This objective requires your organization to identify all system accounts that must use multifactor authentication (MFA) to access systems, especially those that store, process, or transmit Controlled Unclassified Information (CUI). The goal is to ensure MFA is applied to accounts where it is necessary for risk-based or role-based access.