Microsoft 365 security guide

Microsoft 365 MFA: how to check who is protected

An MFA audit should distinguish users who have registered an authentication method from users whose access is actually protected by MFA. Review administrator and standard-user coverage, the policies applying to them, and any exclusions.

Published · Last reviewed · By CyberProva

Run your free Microsoft 365 security assessment

No card required · Optional read-only Microsoft 365 connection

What is the difference between registration and enforcement?

Registration reports tell you which methods users have set up. They do not, by themselves, prove that MFA is required for every relevant sign-in.

  • Review registration and usage reports alongside the applicable policies.
  • Check whether the policy is enforced rather than only being evaluated.
  • Record exclusions, affected users and the reason for each exception.

How to check MFA in Microsoft 365

Ask your administrator to review Entra ID authentication methods activity, the relevant access policies and representative sign-in records. Report access depends on permissions and licensing. Registration and enforcement need to be reviewed together.

  • Export the dated registration population and identify accounts without suitable methods.
  • Check which policies require MFA for standard users and administrators.
  • Review enforcement state, scope and exclusions.
  • Use sign-in records to investigate whether expected requirements apply.

Which accounts need attention first?

Prioritise privileged access and accounts that expose sensitive business information. Include external IT-provider identities in the review.

  • Review Global Administrators and other privileged roles.
  • Check accounts without usable MFA methods.
  • Review emergency-access arrangements separately with your administrator.
  • Identify access paths that do not support your intended authentication controls.

What makes good MFA evidence?

Ask for enough context to show who is covered and what the policy does. A cropped screenshot of a single enabled setting can leave important exclusions invisible.

  • Record the report date and account population.
  • Include policy targeting, enforcement state and exclusions.
  • Review representative sign-in evidence where available.
  • Assign an owner and review date to unresolved exceptions.

Make the answer provable

Evidence to request

  • A dated MFA registration report.
  • Policy configuration showing targets, enforcement and exclusions.
  • An administrator-reviewed exception list and remediation plan.

How CyberProva helps

CyberProva includes evidence-based MFA controls and, where the required access and data are available, additional read-only identity checks. Missing consent, licensing or evidence remains a gap; registration alone is not presented as proof of universal MFA enforcement.

See what a Microsoft 365 security assessment should cover →

See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions

Common questions

Does MFA registration mean everyone is protected?

No. It shows that methods have been registered. You also need to review the policies and access paths that determine when MFA is required.

Will CyberProva enable MFA for us?

No. The connection is read-only. Agree and implement any policy changes with an authorised administrator.

Official guidance

Use these sources with your IT provider when reviewing the controls described above.

From assumptions to evidence

See what needs attention in your organisation

Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.

Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.

Run your free assessment →