Okta Ltd.’s UK business unit will enable phishing-resistant multi-factor authentication by default for mid-market accounting tenants on 24 September, according to release notes sent to channel partners and reviewed by InfoHandle. The policy shift follows a cluster of credential-stuffing attempts against Institute of Chartered Accountants in England and Wales member firms that had just processed Xero breach-notification emails for client payroll databases.
What ships in the default bundle
New and renewed Okta orgs in the “accounting vertical” SKU will require FIDO2 WebAuthn or Okta Verify push with number matching on every admin console sign-in, not only on VPN entry. Legacy SMS one-time codes remain available for 90 days as a break-glass method, but security policies will flag any org that keeps SMS as the primary factor after 1 December.
Implementation guides tell managed service providers to stage security keys before month-end VAT filing peaks. Okta’s London solutions engineers scheduled three webinar slots for practices with 50–250 seats, the segment ICAEW said was hardest hit when attackers reused passwords exposed in unrelated retail breaches.
How Xero notices became the trigger
Xero Ltd. posted advisories in early September about suspicious login patterns on a subset of UK payroll orgs. The cloud ledger vendor forced password resets and published Indicators of Compromise for MSPs. Within days, several mid-tier practices told ICAEW’s cyber desk that staff received convincing phishing messages referencing those same breach notices, complete with forged Xero headers.
Attackers appeared to buy lists of accountant email addresses from prior supplier incidents, then timed campaigns for Friday afternoons when teams clear bank feeds. Okta telemetry shared with ICAEW showed a 38 percent jump in failed MFA challenges among customers using SMS as the only second factor.
Why Okta moved now
Okta’s UK general manager told partners the defaults align with Financial Conduct Authority operational resilience questionnaires that ask how firms authenticate privileged users accessing client money data. While accountants are not always FCA-regulated, many run payment services for landlords and small charities that fall under payment institution rules.
The vendor also faces competitive pressure from Microsoft Entra ID bundles sold through Sage and QuickBooks resellers. Making WebAuthn default is a differentiation play as much as a hygiene fix.
What practices must reconfigure
Firms using Okta to front Xero, HMRC Government Gateway, and CCH iFirm will need to enrol partners before the switch flips. ICAEW’s guidance recommends hardware keys for anyone who can export trial balances without a second reviewer. Practices that outsourced IT to regional MSPs should confirm whether the MSP’s master Okta org or the practice’s child tenant controls MFA policy—misunderstandings there have left clients thinking they were protected when only the MSP portal was hardened.
Break-glass accounts for disaster recovery must be vaulted with offline storage; Okta’s notes warn that enabling default MFA without vaulting those accounts can lock firms out during internet outages.
Regulatory context this month
The UK Data Protection and Digital Information Bill’s latest Lords amendments did not weaken MFA expectations for processors handling payroll special-category data. The Information Commissioner’s Office has cited weak authentication in several monetary penalty notices against hospitality and retail breaches; accountants worry they could be next if client ledgers leak.
NCSC’s updated authentication guidance, published in August, explicitly discourages SMS for high-value workflows. Okta’s product marketing cites that document in footers.
What clients will see
End clients logging into practice portals for document upload should notice WebAuthn prompts on mobile devices that support passkeys. Clients on older Android handsets may need helpdesk calls to enrol email magic links as a temporary bridge—a workflow ICAEW asked Okta to document after pilot complaints.
Billing for security keys remains the practice’s problem: Okta is not subsidising YubiKeys, though two distributors offered bundle pricing through October.
Roadmap and risks
Okta plans to extend the accounting vertical defaults to Irish and Channel Island tenants in November if UK error rates stay below 2 percent helpdesk tickets per 100 users. False positives—locked-out partners on audit deadlines—are the metric practices fear most.
For mid-market accountants, the change is blunt but overdue: breach notices from software vendors are now part of the threat model, and SMS second factors no longer match the sensitivity of the ledgers behind them. Whether default MFA sticks depends on partners accepting a few seconds of friction every morning—or on attackers finding the next channel that is not yet switched on.








