The IRS Just Reminded Tax Firms: MFA Is Required, No Matter Your Size

The IRS says tax firms of every size must protect client information with MFA. Email alone is not enough. Tax software, portals, and cloud storage count too.

On September 4, the IRS and its Security Summit partners issued a reminder to tax professionals: the FTC Safeguards Rule requires multifactor authentication anywhere the firm accesses customer information. The requirement applies to tax preparation firms regardless of size.

The IRS specifically named tax software, cloud storage, email, and other services containing client data. That is broader than the way many small firms have implemented MFA.

It is common to find MFA enabled on Microsoft 365 while an older tax application, client portal, remote-access tool, or shared administrative account still relies on a password. From the firm’s perspective, MFA is “turned on.” From the rule’s perspective, client information remains accessible through an unprotected path.

This is part of the Safeguards Rule

We previously covered the IRS requirement for tax preparers to maintain a Written Information Security Plan. MFA is one of the technical controls that should appear in that plan.

Under the FTC Safeguards Rule, tax preparation firms are considered financial institutions because they handle customer financial information. The rule requires MFA for anyone accessing information systems that contain customer information.

There is a narrow alternative. A firm’s Qualified Individual can approve another access control that is reasonably equivalent or more secure. That approval must be in writing. “The software does not support MFA” or “the partner finds it inconvenient” does not create an automatic exception.

For most small firms, the practical answer is simpler: require MFA everywhere client information can be reached, then document how it is enforced.

Email is only one entry point

Microsoft 365 is often the first system a firm secures because email compromise is common and the risk is easy to understand. But client information moves through more than email.

Tax preparation software contains returns, Social Security numbers, income records, and filing history. A document portal may contain source documents, bank statements, and payroll files. Cloud storage can hold exported returns and working papers. Remote-access software may give someone a path into the workstation where all of those applications are already open.

Each system needs its own answer:

  • Does the application support MFA?
  • Is MFA required for every user or merely available?
  • Are administrators covered by the same requirement?
  • Can anyone bypass MFA through a legacy login, mobile app, or remote-access method?
  • Are shared accounts still in use?

That last question matters. The IRS reminder also says firms should use individual accounts and never share usernames or passwords. Shared credentials make MFA harder to enforce and eliminate accountability. If three people use the same login, the firm cannot reliably show who accessed a client record or approved a change.

“Enabled” and “enforced” are different

Many cloud services describe MFA as enabled when users have the option to enroll. That is not the same as requiring it.

In Microsoft 365, Security Defaults can provide a basic level of protection, but firms that need consistent enforcement and useful evidence should look at Conditional Access. A Conditional Access policy can require MFA for every covered user, block legacy authentication, restrict access by location or device condition, and produce records showing how the policy applied.

The same principle applies outside Microsoft. The firm needs an administrative setting or policy that forces MFA, not an email asking employees to turn it on when they have time.

This distinction matters during an audit, an insurance renewal, or a breach investigation. A screenshot showing that an application offers MFA proves very little. A user report, policy export, or access log showing that every active account is covered is much more useful.

Portals and outside users need attention

CPA firms often focus on employee accounts and overlook clients, contractors, seasonal staff, or outside bookkeepers. Those accounts may still reach customer information.

We have written about why client portals deserve their own security review. A portal can have strong security for internal staff while leaving MFA optional for clients. It can also accumulate old accounts from former clients or temporary users who no longer need access.

The IRS language is about access to customer information, not job titles. If an account can reach protected data, the firm should know who owns it, whether MFA is enforced, and when access was last reviewed.

Seasonal staffing makes this especially important for tax firms. Accounts created in January may still be active in September. A regular access review should confirm that current users still need access and remove anyone who does not.

MFA sits inside a larger defense

MFA blocks many attacks involving stolen passwords. It does not stop every phishing technique.

Device code phishing can send a victim to a legitimate Microsoft page, walk them through MFA, and use that successful authentication to authorize the attacker’s device. Session-token theft can let an attacker reuse an already authenticated session. We covered both problems in our explanation of device code phishing.

MFA remains necessary. The firm also needs monitoring, conditional access, managed devices, and security awareness training that covers current techniques. Compliance establishes a minimum control without guaranteeing that one control will stop every attack.

What to verify before tax season

Start with an inventory of every system that stores or provides access to client information. Include email, tax software, portals, cloud file storage, remote access, payroll platforms, accounting applications, and backup consoles.

For each system, record whether MFA is available, whether it is enforced for every active user, what method is used, and who can approve an exception. If an equivalent control is being used instead, keep the Qualified Individual’s written approval with the firm’s security documentation.

Then test the result. Choose a standard user account and an administrator account in each system. Confirm that a password alone cannot get in. Review dormant and shared accounts while you are there.

The IRS reminder is short, but the instruction is clear: firm size does not change the requirement. A five-person tax practice and a regional accounting firm both need to protect access to customer information with MFA and be able to show that the control is actually in place.


Artech helps CPA firms enforce MFA across Microsoft 365, portals, remote access, and other systems containing client data. If your firm has MFA “somewhere” but cannot show that every access path is covered, we can help you verify it.