Assess device availability before mandating MFA
Aliases: mandatory 2FA · MFA rollout · users without smartphones
What it is
A mandate makes a second factor a condition of continued use. Assessing device availability means, before the switch flips, knowing whether the target population actually has the kind of device or channel required: a smartphone, a number that can receive SMS, a security key, an authenticator on a work PC. Without that assessment, a mandate permanently locks out people with no device, or drives them into the only weak channel still allowed. This entry is population and device before a mandate. It is not about how strength tiers are arranged after MFA is on, and not about how backup factors are enrolled.
Why it happens
Second factors are physical. Students sharing a computer, older people with feature phones, frontline staff forbidden to bring phones into a warehouse, regions with poor SMS delivery—none of that shows up in an office trial. A mandate designed around developers’ own devices excludes structurally. Assessment must follow the required factor, not a coarse “do you have a phone”: having a phone is not being allowed to install an authenticator, not receiving international SMS, not permitting a USB key. When available devices cannot be found, delay the mandate or offer a factor that population actually has—do not ship on the calendar and whitelist via support.
Studying it
Survey owned factors in a representative sample, and run an optional trial to see who sticks at enrollment.
Independent variables: required factor kinds, population strata (age, region, role, phone-in-workplace rules), whether an alternate factor is offered. Dependent variables: share who finish enrollment, share stuck on “no device,” churn or tickets after the mandate.
Convenience samples overstate availability. Field work must include roles that cannot bring phones and dual-SIM / virtual-number users. Do not defend a mandate with “security incidents fell” alone unless lockouts are reported with it. The trial must last long enough to include people who cannot buy a key the same day.
Where it stops holding
High-assurance roles (bank staff, cloud admins) may mandate keys; the assessment may conclude “no key, no account,” which is hiring and issuance—still get the key into their hand rather than assume they have one. Consumer products facing an unspecified public cannot mandate a single hardware kind without selecting their users. When law requires MFA, assessment becomes “which compliant factor covers people without smartphones,” such as hardware OTP cards, not cancelling the mandate. People already using passkeys should not be forced to enroll SMS as well; existing factors count in the assessment.
Applying it
- Before a mandate, sample target users on whether they can finish enrollment of the required factor; write the coverage gap; do not flip the switch until the gap is closed.
- Offer an available alternate for people without smartphones (hardware OTP, authenticator on a work PC), and say who it is for.
- Mandate in waves: optional, then high-risk accounts, then everyone; watch “no device” tickets per wave, not enablement rate alone.
- Verify: the pilot roster includes people who declare no smartphone or no SMS; record whether they can keep working without an MFA exception. The gate for a full mandate is that path already running. After launch, count accounts lost because MFA could not be enrolled, and report that beside security gains.
Related
- Within the group: H6.12.1 MFA should offer strength options between convenience and security · H6.12.2 A failed second factor needs a pre-enrolled backup method · H6.12.4 Recovery-code custody must be explained to the person who holds them
- Adjacent: H6.05 Biometrics · H6.01 Registration friction
- Search terms:
MFA mandate·authenticator availability·inclusive 2FA