Multi-Factor Authentication and the 2024 Update Every Tax Firm Should Know

Last reviewed 2026-07-04 · 6 min read

Of every control the FTC Safeguards Rule requires, multi-factor authentication is the highest-impact, lowest-cost one you can turn on. It is also the one the IRS singled out for reinforcement. If you do nothing else after reading this, turn on MFA everywhere it belongs.

If you do nothing else this week, turn on MFA for your email and your tax software.

What MFA actually is

Multi-factor authentication means proving who you are with more than just a password. After the password, you provide a second factor: a code from an authenticator app, a prompt on your phone, or a physical security key. Even if an attacker steals or guesses your password, they cannot get in without that second factor.

What changed for tax firms

An August 2024 update to IRS Publication 5708 reinforced MFA as effectively universal for systems that access client data, and revised the associated password standards. Combined with the Safeguards Rule's own MFA requirement, the direction is unambiguous: MFA is expected everywhere client information can be reached, not just on your most sensitive system.

Where to apply it first

Prioritize by risk. These are the doors attackers use most:

Not all second factors are equal

An authenticator app or hardware security key is stronger than a code sent by text message, because SMS codes can be intercepted or redirected through SIM-swap attacks. SMS is far better than nothing, but prefer app-based or hardware MFA for email and tax software.

How to roll it out without chaos

Do it in stages. Start with email and your tax software this week. Enroll staff one system at a time, keep a backup recovery method for each account, and document that MFA is enabled as part of your WISP. Budget is rarely the obstacle: most business email and software platforms include MFA at no extra cost. The real work is enrollment and a short habit change, not spend.

This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.

Frequently asked questions

Is MFA legally required for tax firms?
Effectively yes. The FTC Safeguards Rule requires MFA for accessing systems with customer information, and the 2024 IRS Publication 5708 update reinforced it as universal for systems that touch client data.
Does MFA need to be on my email too?
Yes, and email should be first. It is the most common breach entry point and usually the password-reset path for your other accounts.
Is text-message (SMS) MFA good enough?
It is much better than no MFA, but an authenticator app or a hardware security key is stronger, because SMS codes can be intercepted or redirected via SIM-swap attacks. Prefer app-based or hardware MFA for email and tax software.
How much does MFA cost?
Usually nothing extra. Most business email and tax/accounting platforms include MFA. The effort is enrollment and a small habit change, not spend.
What if a staff member resists using MFA?
MFA is a documented safeguard tied to a legal requirement, so it is a firm policy, not an option. Provide a backup recovery method and a short walkthrough; enrollment friction is brief and one-time.

Check your firm in 3 minutes

← All guides · All FAQs