[THEME] Multi-Factor Authentication
The Multi-Factor Authentication theme ensures that MFA is properly configured and enforced across your Microsoft 365 environment. MFA is the single most important security measure for protecting user accounts.
What does Attic do?
Attic verifies MFA configuration at multiple levels and monitors for changes that could weaken your MFA posture.
The checks in this theme cover:
- Security Defaults status and configuration
- MFA enforcement for all administrators and users
- Detection of admins without MFA enabled
- MFA policy exclusion monitoring (detecting when users are removed from MFA requirements)
- Microsoft Authenticator configuration: push notifications, number matching, additional context, and location display
- Fraud reporting capabilities are enabled
- SMS sign-in is disabled (weaker authentication method)
- FIDO2 security key support is enabled
- Conditional Access policies use authentication strength requirements for admins
- Device code flow restrictions via Conditional Access
- Monitoring of Conditional Access policy changes
- Report-only policies are identified for review
Why is this important?
MFA blocks over 99% of credential-based attacks. Without MFA, a stolen password is all an attacker needs to access your environment. Attic ensures MFA is not only enabled, but configured with the strongest available methods and continuously monitored for gaps or weakening changes.
Checks in this theme
| ID | Check |
|---|---|
| CHK-1127 | Security Defaults enabled |
| CHK-1328 | MFA enforced for admins |
| CHK-1327 | MFA for all users |
| CHK-1154 | MFA exclusion added |
| CHK-1137 | Admin without MFA |
| CHK-1140 | Pushnotifications Microsoft Authenticator enabled |
| CHK-1141 | MFA Number Matching |
| CHK-1142 | Appname in MS Authenticator |
| CHK-1153 | Location in MS Authenticator |
| CHK-1144 | MFA Fraud Alerts enabled |
| CHK-1161 | MFA Block OTP |
| CHK-1164 | Block SMS sign-in |
| CHK-1168 | Monitor Conditional Access |
| CHK-1170 | FIDO2 Authentication |
| CHK-1171 | Phishing-resistant MFA for Admins |
| CHK-1172 | Block Device Code Flow Authentication |
| CHK-1173 | CA Report-only policies present |