Multi-Factor Authentication and the 2024 Update Every Tax Firm Should Know
Last reviewed 2026-07-04 · 6 min read
Of every control the FTC Safeguards Rule requires, multi-factor authentication is the highest-impact, lowest-cost one you can turn on. It is also the one the IRS singled out for reinforcement. If you do nothing else after reading this, turn on MFA everywhere it belongs.
If you do nothing else this week, turn on MFA for your email and your tax software.
What MFA actually is
Multi-factor authentication means proving who you are with more than just a password. After the password, you provide a second factor: a code from an authenticator app, a prompt on your phone, or a physical security key. Even if an attacker steals or guesses your password, they cannot get in without that second factor.
What changed for tax firms
An August 2024 update to IRS Publication 5708 reinforced MFA as effectively universal for systems that access client data, and revised the associated password standards. Combined with the Safeguards Rule's own MFA requirement, the direction is unambiguous: MFA is expected everywhere client information can be reached, not just on your most sensitive system.
Where to apply it first
Prioritize by risk. These are the doors attackers use most:
- Email accounts. Email is the single most common entry point for a breach and often the reset path for every other account.
- Tax and accounting software, where the client data actually lives.
- File storage and client document portals.
- Any remote access to your systems or network.
An authenticator app or hardware security key is stronger than a code sent by text message, because SMS codes can be intercepted or redirected through SIM-swap attacks. SMS is far better than nothing, but prefer app-based or hardware MFA for email and tax software.
How to roll it out without chaos
Do it in stages. Start with email and your tax software this week. Enroll staff one system at a time, keep a backup recovery method for each account, and document that MFA is enabled as part of your WISP. Budget is rarely the obstacle: most business email and software platforms include MFA at no extra cost. The real work is enrollment and a short habit change, not spend.
This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.
Frequently asked questions
- Is MFA legally required for tax firms?
- Effectively yes. The FTC Safeguards Rule requires MFA for accessing systems with customer information, and the 2024 IRS Publication 5708 update reinforced it as universal for systems that touch client data.
- Does MFA need to be on my email too?
- Yes, and email should be first. It is the most common breach entry point and usually the password-reset path for your other accounts.
- Is text-message (SMS) MFA good enough?
- It is much better than no MFA, but an authenticator app or a hardware security key is stronger, because SMS codes can be intercepted or redirected via SIM-swap attacks. Prefer app-based or hardware MFA for email and tax software.
- How much does MFA cost?
- Usually nothing extra. Most business email and tax/accounting platforms include MFA. The effort is enrollment and a small habit change, not spend.
- What if a staff member resists using MFA?
- MFA is a documented safeguard tied to a legal requirement, so it is a firm policy, not an option. Provide a backup recovery method and a short walkthrough; enrollment friction is brief and one-time.