Description:

Verifies that the weaker SMS and Voice Call authentication methods are disabled in the Entra ID authentication methods policy.

Why:

Traditional MFA methods such as SMS codes and voice calls are weaker authenticators that are more susceptible to phishing and SIM swapping. This check verifies that those methods are disabled.

Configured: SMS and Voice Call authentication methods are disabled.

Not Configured: SMS or Voice Call authentication methods are enabled.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Requires Premium (P1) licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)

Compliance Frameworks:

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.5

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.5

Microsoft documentation:


_KB status: new — this check is not yet documented in the knowledge base._

_Source: Augmentt native check, aligned to the CIS Microsoft 365 Foundations Benchmark. Check ID CIS.M365.5.2.3.5 (module 1082)._

Sourced for this page:

  • Category — Microsoft service targeted by the check

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Entra ID P1 · CIS M365 v6 L1 · CIS M365 v7 L1