MFA Is the Headline of Cybersecurity Awareness Month. Your Active Directory Is the Fine Print.
Every October, the advice arrives in a familiar order. Use strong passwords, turn on multi-factor authentication, learn to spot phishing, and keep software updated. This year the National Cybersecurity Alliance has wrapped that guidance in a new theme, “Don’t Make It Easy for Them,” and the message is a sound one: security comes from good habits repeated consistently, not from a single perfect decision.
For an individual with a handful of personal accounts, turning on MFA really is one of the most effective habits available. For a university with tens of thousands of students, faculty, staff, and alumni, or a state agency serving an entire population, MFA is not a switch. It is a system, and like every system it depends on the information underneath it. That information lives in the directory, and the Active Directory is the fine print of cCybersecurity Awareness Month.
Identity is where attackers start
The threat research published this year leaves little doubt about where attackers focus their effort. Expel found that identity was the primary attack surface in 68.6 percent of the incidents it handled during 2025. Sophos reported that 67 percent of the incidents its response teams investigated were rooted in identity-related attacks, and that MFA was missing in 59 percent of those cases. Unit 42 at Palo Alto Networks found that identity weaknesses played a material role in almost 90 percent of its investigations.
The same research also shows why MFA deserves its place at the top of every awareness checklist. In the Expel data, more than half of the identity-based attacks that used legitimate credentials failed immediately because of controls such as MFA. When MFA is present and applied correctly, it works. The real question for IT and security leaders is whether it is applied correctly everywhere it needs to be, and the answer depends on the quality of the identity data behind it.
Every MFA decision begins with a directory lookup
Before an MFA prompt ever appears, the access platform has to answer several questions. Who is this user, and are they still active? Which groups and roles do they belong to? Which applications are they entitled to use, and how sensitive are those applications? Adaptive and step-up authentication add further questions about location, device, and risk, yet each of those decisions still rests on attributes pulled from a directory.
In higher education and government, those attributes rarely live in one place. A typical environment includes Active Directory, one or more legacy LDAP directories, a student information system, an HR database, and specialized systems inherited from departmental projects or reorganizations. Many organizations tie these sources together with synchronization jobs that copy data on a schedule. Every interval between those jobs is a window in which the data the access platform reads may not match reality, whether that involves a contractor whose engagement ended yesterday, a student whose status changed, or an employee who moved into a role with access to sensitive financial or research systems.
That gap is the fine print. An organization can enable MFA everywhere and still have its access decisions rest on information that is hours or days out of date. Attackers who rely on stolen credentials, the pattern that dominates this year’s breach research, are looking for exactly those inconsistencies.
How a virtual directory closes the gap
The Optimal IdM Virtual Identity Server (VIS) addresses this problem directly. VIS is a virtual directory that unifies multiple identity sources into a single, real-time view without copying or altering the data in the systems behind it. It works with Microsoft Active Directory, any LDAPv3 compliant directory, and SQL databases, and its API can incorporate other sources such as flat files, proprietary systems, and bespoke directories. Because VIS presents data from the authoritative sources rather than relying on synchronization, the access platform sees identity information as it stands now.
VIS is embedded in the OptimalCloud, which means the platform’s authentication and authorization decisions can draw on attributes from any connected source. Adaptive authentication rules in the OptimalCloud can use any custom attribute an administrator defines, alongside signals such as geo-fencing, geo-velocity detection, and device context. When risk rises, policies can require step-up authentication, route the user to a specific identity provider, or deny access entirely. When the attributes behind those rules come from a unified and current view, the policies do what they were designed to do.
The benefits extend beyond MFA. When a password change comes through VIS, it can be set in connected systems automatically, which helps keep credentials consistent across the environment. One Optimal IdM customer saved more than $1 million by using this capability rather than purchasing a separate password synchronization tool.
Making the right habit the easy habit
Cybersecurity Awareness Month rightly emphasizes that good habits only protect people when they are easy to keep, and the same principle applies to the people who use MFA every day. The OptimalCloud is currently the only IAM platform that delivers MFA prompts natively inside Microsoft Teams on both desktop and mobile, so users can approve a sign-in within an application they already have open rather than reaching for a separate authenticator app. The OptimalCloud also includes MFA in its base pricing rather than treating it as a premium add-on, which removes a common reason organizations leave some user populations uncovered.
Questions worth asking this October
For CISOs and IT directors who want to look past the headline this month, a few questions can reveal how much fine print sits beneath their MFA deployment. How many identity stores feed access decisions today, and how often are they synchronized? When a person leaves the organization or changes roles, how long does it take for every system to reflect that change? Are adaptive and step-up policies reading attributes that are current, or attributes that are only as fresh as the last sync job? Are there user populations, such as adjunct faculty, contractors, or affiliates, that fall outside MFA coverage because their identities live in a system the access platform cannot see?
The answers will not appear on any awareness poster, but they determine whether MFA delivers the protection the poster promises. Attackers are counting on the fine print. A unified, real-time directory is one of the most effective ways to make sure it does not work in their favor.
To learn how the Virtual Identity Server and the OptimalCloud can unify your identity data and strengthen MFA across your organization, contact Optimal IdM to schedule a conversation with our team.
Contact us for more information.
Frequently Asked Questions
What is the theme of Cybersecurity Awareness Month 2026?
The National Cybersecurity Alliance theme for Cybersecurity Awareness Month 2026 is “Don’t Make It Easy for Them,” while CISA is running “Securing the Next 250.” Both campaigns focus on everyday habits such as strong passwords, multi-factor authentication, recognizing phishing, and keeping software updated, with the goal of making cybercriminals work harder to succeed.
Can multi-factor authentication fail even when it is turned on?
Yes. MFA can be enabled across an organization and still make decisions based on outdated identity data. If a directory has not yet reflected that a user left, changed roles, or lost eligibility, access policies may treat that account as valid. MFA is most effective when the identity information behind each authentication decision is accurate and current.
What is a virtual directory?
A virtual directory is an identity layer that presents data from multiple directories and databases as one unified view without copying or moving that data. The Optimal IdM Virtual Identity Server (VIS) is a virtual directory that connects Active Directory, LDAPv3 directories, SQL databases, and other sources, giving access platforms a single, real-time view of identity information.
Do organizations need to replace their existing directories to use a virtual directory?
No. A virtual directory works with the identity stores an organization already has. The Optimal IdM Virtual Identity Server creates an abstract view of back-end data without altering it and does not require synchronization, which makes it well suited to universities and government agencies with legacy LDAP directories and multiple systems of record.
Can MFA prompts be delivered through Microsoft Teams?
Yes. The OptimalCloud is currently the only IAM platform that delivers MFA prompts natively inside Microsoft Teams on both desktop and mobile. Users approve sign-ins within an application they already use every day, with no separate authenticator app required, and MFA is included in the OptimalCloud base pricing.


