Description:
Verifies all user (non-admin) accounts MFA requirement, including Security Defaults, Conditional Access Policies or Per-User MFA in its logic.
How it works:
Security Defaults
If enabled for a tenant, the configuration status will appear as Security Defaults and all users will be considered as Protected. Typically used by tenants that don't have Entra ID P1 licensing, we are unable to read the MFA registration status of these tenants, as the API is behind the Entra ID P1 paywall. Due to this, we indicate all users as Protected so you, the MSP, can show that your part of the work has been completed by having Security Defaults and hence, MFA enabled.
Legacy (Per User) MFA
This MFA type is being deprecated by Microsoft. Augmentt recommends moving your clients to Security Defaults or Conditional Access before Microsoft fully deprecates this feature.
Conditional Access
Augmentt will read all conditional access policies and identify which ones are applying a grant type of "Require MFA" or "Authentication Strength". The users/groups/roles will be extrapolated from these policies and the related users will be verified for their registration status. Users having MFA enforcement via Conditional Access and completed successful registration will be considered as protected.
Conditional Access & DUO
Following similar logic to Conditional Access, we will extrapolate policies that have a grant type of "RequireDUOMFA". If the related users have a successful DUO registration and are not in bypassed mode, they will be considered protected.
DUO for Microsoft Entra ID (formerly Azure AD) requires a Conditional Access Policy actively enforcing DUO MFA — make sure you have this in place before proceeding, as it can cause inconsistent reporting. See Duo Two-Factor Authentication for Microsoft Entra ID.
Non-registered and bypassed users will be Not protected.
Why:
Requiring multi-factor authentication (MFA) for all user accounts helps protect devices and data that are accessible to these users. Adding more authentication methods, such as a phone token or a badge, increases the level of protection in the the event that one factor is compromised.
Status detail shown in Augmentt: You have N of M user accounts that don't use MFA.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.
Category: Identity
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: YES — Microsoft Secure Score control MFARegistrationV2.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab)
Compliance Frameworks:
CISA SCuBA — MS.AAD.3.2
Essential Eight (Maturity Level 1) — 1504, 1679, 1680, 1401
Essential Eight (Maturity Level 2) — 1504, 1679, 1680, 1401, 0974, 1872
Essential Eight (Maturity Level 3) — 1504, 1679, 1680, 1401, 0974, 1872
NIST CSF 2.0 — PR.AA-02
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.2.2
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.2.2
HIPAA Security Rule — 164.312(d), 164.312(a)(1)
CMMC Level 1 — AC.L1-b.1.i, IA.L1-b.1.vi
CMMC Level 2 — AC.L2-3.1.1, IA.L2-3.5.2, IA.L2-3.5.3
Microsoft documentation:
Deployment considerations for Microsoft Entra multifactor authentication - Microsoft Entra ID
Require MFA for all users with Conditional Access - Microsoft Entra ID
