Pumpkin
    Access Control

    Multi-Factor Authentication Is the Boring Fix That Works

    A second factor on every login means a stolen password stops being a master key to your client files. Rolled out across the firm, documented, and configured so nobody spends their March trying to get around it.

    The Highest-Return Hour You'll Spend

    Stolen credentials are how firms get opened up. MFA has no demo value and nothing interesting to say for itself, and it prevents more damage per dollar than anything else on this page.

    A Stolen Password Stops Short

    With a second factor required, a password lifted by phishing or bought on a forum gets an attacker as far as a prompt they can't answer.

    Whatever Fits the Person

    Authenticator apps, push approval, hardware keys, biometrics. Partners who travel get keys. Seasonal hires get something simpler.

    Documented for Auditors

    IRS Publication 4557 and SOC 2 both want strong access control written down. Policies, enrollment records, and reports come with the rollout.

    Admin Panel

    Centralized MFA Management

    Enrollment status, policies by role, and authentication events in one place. The row worth checking is always the seasonal staff, because temporary accounts are how a firm ends up with permanent exceptions nobody remembers granting.

    • Per-user enrollment tracking
    • Role-based policy enforcement
    • Compliance reporting dashboard
    security.pumpkin.cloud/mfa-admin

    Total Users

    48

    MFA Enrolled

    46

    Pending

    2

    Partners

    Hardware Key

    8/8

    Senior Staff

    Authenticator App

    14/14

    Staff Accountants

    Authenticator App

    18/18

    Admin Staff

    Push Notification

    4/4

    Seasonal Temps

    SMS Code

    2/4

    What the Rollout Includes

    Methods that match the risk, policies that match the role, and the paperwork that proves both to whoever asks.

    Biometric Options

    Fingerprint and face recognition on devices that support it, fast enough that nobody starts hunting for a way around it.

    Single Sign-On

    One identity across practice management, tax prep, and Microsoft 365, with MFA enforced once at the front door.

    Policy by Role

    Partners and admins get stricter rules than the front desk. Everybody gets something.

    Conditional Access

    A known laptop in the office gets prompted less. A new device signing in from a new country gets prompted more, or doesn't get in.

    Hardware Keys

    FIDO2 and YubiKey support for the accounts that would hurt most, which is usually the partner who has access to everything.

    Joiners and Leavers

    MFA on from day one, access off the day somebody leaves. The second half is the one firms forget until the client list walks out with them.

    Who It's For

    Firms where one password opens more than anyone is comfortable admitting.

    CPA Firms

    MFA on tax software, client portals, and email, which is where the taxpayer data actually lives.

    Multi-Partner Practices

    One standard for partners, staff, and the seasonal hires who arrive in January and are gone by May.

    Remote & Hybrid Teams

    Logins from home, from a client's conference room, from an airport, without handing anyone a permanent exception.

    security.pumpkin.cloud/mfa-setup

    Set Up Your Authentication

    Choose your preferred verification method

    Authenticator App

    Microsoft or Google Authenticator

    Recommended

    Hardware Security Key

    YubiKey or FIDO2 device

    Push Notification

    Approve on your mobile device

    Biometric

    Fingerprint or face recognition

    User Experience

    Setup People Actually Finish

    Guided enrollment gets each person set up in a few minutes. They pick a method, the system walks them through it, and nobody has to open a ticket. We steer people toward apps and keys, and away from SMS wherever it matters.

    • Self-service enrollment in under 3 minutes
    • Trusted device policies reduce prompts
    • Works across all firm applications

    Frequently Asked Questions

    Why does MFA matter this much for accounting firms?

    Because credential theft is the common way in, and your logins open onto Social Security numbers and bank details for hundreds of households. MFA doesn't fix everything. It removes the single most reliable attack in the catalogue, which is using a password somebody typed into a convincing fake page at 9pm.

    Which methods do you support?

    Authenticator apps, push approval, hardware security keys (YubiKey and other FIDO2 devices), and device biometrics. SMS codes work and we'd rather you didn't lean on them, since SIM swapping is a real and documented technique. Apps or keys for anything sensitive.

    How does it fit the software we already run?

    We connect MFA to practice management, tax prep, Microsoft 365, Google Workspace, and most everything else through single sign-on. Staff sign in once at the start of the day instead of fighting a separate prompt in every application.

    Will it slow us down in March?

    It shouldn't. Push approval takes a couple of seconds, and trusted-device policies stop the prompting on known machines. If MFA is interrupting people twenty times a day, the policy is configured badly, and that's a fixable problem rather than a reason to turn it off.

    Does MFA satisfy IRS requirements?

    Publication 4557 points at multi-factor authentication as a safeguard for taxpayer data, and tax software vendors have been requiring it on their own products for a while now. Rolled out with written policies and enrollment records, it also answers the access control expectations in SOC 2 and GLBA.

    Turn It On Before You Need It

    Roll MFA out across the firm, document it for your WISP, and close off the easiest attack against your practice. We handle the enrollment, including the person who hates this sort of thing.