Description:
Verifies that authenticator login context information is enabled.
Why:
This stopgap security policy helps protect the tenant when phishing-resistant MFA has not been enforced and Microsoft Authenticator is used. This policy helps improve the security of Microsoft Authenticator by showing user context information, which helps reduce MFA phishing compromises.
Configured: Authenticator login context information is enabled.
Not Configured: Authenticator login context information is disabled.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
CISA SCuBA — MS.AAD.3.3
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.1
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.1
Microsoft documentation:
