# MFA: track exceptions as carefully as adoption

https://thiago.limaesilvatecnologia.com.br/en/artigos/mfa-exceptions/

Published: 2026-09-12

High coverage can conceal important alternative paths.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: May 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

A count of users with MFA enabled does not reveal every access route. Special accounts, recovery and integrations may follow different rules.

## Practical application

Editorial proposal: map coverage to access journeys, not just people. In a hypothetical organization, compare everyday, administrative and emergency access. Record reason, duration and owner for each exception.

## How to verify

In a tabletop exercise, remove one factor from a test user and trace recovery. Check whether the alternative preserves required trust. Track paths lacking intended protection to prioritize fixes by impact and actual use.

## Sources

- [OWASP — Multifactor Authentication Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Multifactor_Authentication_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
