ForumsIdentity & access

What actually happened to your MFA coverage numbers after the 2024 Snowflake incidents?

Question 6 May 2026 759 views
Karthik Subramanian Sample Sysadmin turned security lead at a university. · member since Mar 2026

In mid-2024 a series of intrusions into organisations' Snowflake tenants were attributed to stolen credentials being reused where multi-factor authentication was not enforced. The platform was not itself breached, which made it a very clear shared-responsibility case study.

Did that change anything measurable for you on data platform MFA, or did it get discussed and forgotten?

4 replies

Arjun Mehra Sample CISO at a private bank. Buys for 4,000 endpoints and argues about renewals. · 4 months ago

It changed one specific thing for us: we stopped accepting 'the platform supports MFA' as an answer and started requiring evidence of enforcement, per platform, with a number. Support and enforcement are not the same word and the gap between them is where that whole episode lived.

Isabelle Moreau Sample Consultant Independent consultant. Runs vendor bake-offs for a living. · 3 months ago

We audited and found 11 percent of data platform accounts without enforced MFA, almost all service or contractor accounts created before the policy existed. That number is now on a monthly report and it is at 0.4 percent, which is the contractor onboarding lag rather than anything structural.

Ben Carter Sample Blue team of one and a half. Automation is survival. · 3 months ago

Same finding, different flavour: ours were mostly accounts belonging to people who had left, which was an offboarding problem wearing an MFA costume. Worth checking whether your gap is really an identity lifecycle gap.

Karthik Subramanian Sample Sysadmin turned security lead at a university. · 3 months ago

That is a useful reframe and I suspect it applies to us too. Running the same check this week.

Sign in or join to reply.