Verifies all admin accounts MFA requirement, including Security Defaults, Conditional Access Policies or Per-User MFA & DUO in its logic.

How it works:

Security Defaults

If enabled for a tenant, the configuration status will appear as Security Defaults and all users will be considered as Protected. Typically used by tenants that don't have Entra ID P1 licensing, we are unable to read the MFA registration status of these tenants, as the API is behind the Entra ID P1 paywall. Due to this, we indicate all users as Protected so you, the MSP, can show that your part of the work has been completed by having Security Defaults and hence, MFA enabled.

Legacy (Per User) MFA

This MFA type is being deprecated by Microsoft. Augmentt recommends moving your clients to Security Defaults or Conditional Access before Microsoft fully deprecates this feature.

Conditional Access

Augmentt will read all conditional access policies and identify which ones are applying a grant type of "Require MFA" or "Authentication Strength". The users/groups/roles will be extrapolated from these policies and the related users will be verified for their registration status. Users having MFA enforcement via Conditional Access and completed successful registration will be considered as protected.

Conditional Access & DUO

Following similar logic to Conditional Access, we will extrapolate policies that have a grant type of "RequireDUOMFA". If the related users have a successful DUO registration and are not in bypassed mode, they will be considered protected.

DUO for Microsoft Entra ID (formerly Azure AD) requires a Conditional Access Policy actively enforcing DUO MFA — make sure you have this in place before proceeding, as it can cause inconsistent reporting. See Duo Two-Factor Authentication for Microsoft Entra ID.

Non-registered and bypassed users will be Not protected.

Why:

Requiring multi-factor authentication (MFA) for all Azure Active Directory accounts with privileged roles makes it harder for attackers to access accounts. If any of those accounts are compromised, critical devices and data will be open to attacks.

Status detail shown in Augmentt: You have N of M privileged accounts that don't use MFA.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: YES — Microsoft Secure Score control AdminMFAV2.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • CISA SCuBA — MS.AAD.3.2

  • Essential Eight (Maturity Level 1) — 1504, 1679, 1680, 1401

  • Essential Eight (Maturity Level 2) — 1504, 1679, 1680, 1401, 1173, 1682, 1872

  • Essential Eight (Maturity Level 3) — 1504, 1679, 1680, 1401, 1173, 1682, 1872

  • NIST CSF 2.0 — PR.AA-02

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.2.1

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.2.1

  • HIPAA Security Rule — 164.312(d), 164.312(a)(1)

  • CMMC Level 1 — AC.L1-b.1.i, IA.L1-b.1.vi

  • CMMC Level 2 — AC.L2-3.1.1, IA.L2-3.5.3

Microsoft documentation: