Check provider logo

Ensure all users are MFA capable

entra_users_mfa_capable

Severitycritical
Serviceentra
by Prowler

Ensure all users are being registered and enabled for multifactor authentication.

Risk

Users who are not MFA capable are more vulnerable to account compromise, as they may rely solely on single-factor authentication (typically a password), which can be easily phished or cracked.

Run this check with Prowler CLI

prowler m365 --checks entra_users_mfa_capable

Run in Prowler Cloud

Remediation

Other

Remediation steps will depend on the status of the personnel in question or configuration of Conditional Access policies. Administrators should review each user identified on a case-by-case basis.

WUI

Ensure all member users are MFA capable by registering and enabling a strong authentication method that complies with the organization's authentication policy. Regularly review user status to detect gaps in MFA deployment and correct misconfigurations.

References:

Source Code

References

Resource Type

Conditional Access Policy

Related URL