This objective ensures that MFA is not only identified as a requirement (from IA.L2-3.5.2[a]), but also actively enforced for the applicable accounts. It confirms that users must present two or more authentication factors before being granted access to systems, especially those that process or store Controlled Unclassified Information (CUI).