Description:

This check verifies that MFA Number Matching is enabled. This requires the Microsoft Authenticator app to be enabled/used.

Why:

Number matching prevents users from approving MFA to a malicious user due to MFA fatigue. The user will be presented with a number to enter in the Authenticator app when receiving MFA push notifications, ensuring that the MFA request is valid.

Status detail shown in Augmentt: You have N out of M settings applied.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • NIST CSF 2.0 — PR.AA-02

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.1

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.1

  • HIPAA Security Rule — 164.312(d), 164.308(a)(5)(ii)(D)

  • CMMC Level 1 — IA.L1-b.1.vi

  • CMMC Level 2 — IA.L2-3.5.3, IA.L2-3.5.4

Microsoft documentation:


_KB status: already published as "MFA Number Matching" — update the existing step in place._

_Source: Augmentt native check. Check ID mfanumbermatching (module 28)._

Sourced for this page:

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Identity · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · NIST CSF 2.0 · HIPAA · CMMC Level 1 · CMMC Level 2