MFA registration and usage shall be periodically reviewed
Last updated
Last updated
MFA registration should periodically be reviewed to ensure that there are no gaps or misconfigurations of deployment. MFA can be monitored natively within Azure Active Directory or with 3rd party tools.
MFA registration details and usage shall be monitored on a defined schedule.
Viewing Authentication Activity in Azure AD requires an Azure AD P1 license which can be purchased standalone or through the following common plans:
Microsoft 365 Business Premium
EMS + E3 or EMS + E5
Microsoft 365 E3
Microsoft 365 E5
MFA reports can also be derived from PowerShell which does not require an Azure AD P1 license and can be used with any Microsoft licensing model
To view the Authentication Activity:
There is no end-user impact when looking at log information or reports on MFA.
Using the Azure AD sign-ins report:
Usage Graph API:
The of the Authentication methods section can also be used to investigate potential post-breach activity. Attackers sometimes reset MFA registration methods after accessing a compromised account.
MFA Status Reporting (Multi-tenant):
Find Global Admins without MFA: