Skip to content
English
  • There are no suggestions because the search field is empty.

Enforce Multi-Factor Authentication for Administrators [CHK-1328]

This check ensures that multi-factor authentication (MFA) is enforced for all administrators in your Microsoft 365 Tenant.

Rationale

Enforcing MFA for administrators enhances security by adding an extra layer of protection. It can help prevent unauthorized access, even if passwords are compromised.

Fix

An automated fix is available through Attic.

Manual steps:

  1. Navigate to the Entra ID portal at https://entra.microsoft.com.
  2. Go to Conditional Access > Policies.
  3. Click "New policy".
  4. Name the policy "Attic - Admin MFA Policy".
  5. Under "Assignments > Users", select "Directory roles" and choose all administrator roles.
  6. Under "Assignments > Cloud apps", select "All cloud apps".
  7. Under "Access controls > Grant", select "Grant access" and check "Require multifactor authentication".
  8. Set "Enable policy" to "On".
  9. Click "Create".

Impact

Once this fix is implemented, all administrators will be required to use MFA, thereby enhancing the security of your Microsoft 365 Tenant.

More Information

For more information about MFA and its benefits, visit the Microsoft MFA Guide.