Northwind Traders
Each enabled member counted once, by the strongest method they have.
| Strength | People | Admins | Share of members | What it means |
|---|---|---|---|---|
| Phishing-resistant | 6 | 0 | 17% | Bound to the real Microsoft sign-in page, so a fake page can't relay it. |
| Authenticator app or token | 14 | 1 | 40% | Strong, but a convincing fake sign-in page can relay a code or push approval. |
| Phone (SMS or voice call) medium | 3 | 0 | 9% | Weakest second factor: texts and calls can be intercepted or moved to another SIM. |
| None medium | 12 | 0 | 34% | No second factor: the password alone gets in. |
How many enabled members have each method. People usually have more than one.
Enabled members and what they can sign in with, weakest first and admins at the top. Who hasn't set up MFA at all, and whether it's required, is in MFA coverage.
| Account | Admin | Admin roles | Strongest method | Methods | Asked for first | Passwordless | Self-service reset |
|---|---|---|---|---|---|---|---|
| grace.taylor@northwindtraders.example | No | Phishing-resistant | Passkey, Authenticator app | No | Unknown |
Which methods people may register and use, from the tenant's authentication methods policy, against what's recommended for a small business.
| Setting | Current | Recommended | Why |
|---|---|---|---|
| Passkeys and security keys (FIDO2) | On for Break glass | On | Needed for phishing-resistant sign-in, which admins should use. |
| Microsoft Authenticator | On for All users | On | The second factor most people should use. |
| Authenticator shows which app is signing in | Microsoft managed | On (Microsoft managed turns it on) | Helps people spot a sign-in that isn't theirs. |
| Authenticator shows where the sign-in is from low | Off | On (Microsoft managed turns it on) | Helps people spot a sign-in that isn't theirs. |
| Text message (SMS) low | On for All users except Break glass | Off, once people use Authenticator | Texts can be intercepted or moved to another SIM. |
| Voice call | Off | Off | Calls can be redirected, and are easy to approve by mistake. |
| Email one-time passcode | On for All users | Off, unless guests or password reset need it | Not a second factor for members; only for password reset and guests. |
| Temporary Access Pass | Off | On, for setting up passkeys | A time-limited pass for setting up a new phone or passkey. |
| Registration campaign (asks people to set up Authenticator at sign-in) | Microsoft managed, for All users, can be skipped for 1 day | On, or Microsoft managed | Moves people off text messages and calls. |
| System-preferred MFA (asks for the strongest method a person has) low | Off | On, or Microsoft managed | Otherwise people are asked for their own default, often a text message. |
| People can report an MFA prompt they didn't expect | Microsoft managed | On | A reported prompt blocks the account's risky sign-ins and alerts admins. |
| Methods managed in this policy (not the old MFA and SSPR settings) | Yes | Yes | Microsoft has retired the old per-user MFA and SSPR method settings. |
Authentication strengths in Conditional Access 0
No Conditional Access policy requires an authentication strength. Start with one requiring Phishing-resistant MFA for admin roles, once admins have a passkey.
When each enabled member's password was last set. An old password matters most without MFA; an account that has never signed in may still have the password it was created with. Problems first, then oldest first.
How often cloud-only accounts on each domain must change their password. Microsoft and the NCSC now advise against regular expiry when everyone has MFA: forced changes lead to weaker, predictable passwords. Accounts synced from on-premises AD follow AD's policy instead.
| Domain | Signs in with | Passwords expire after | Reminder before expiry | Recommended |
|---|---|---|---|---|
| northwindtraders.example | Microsoft Entra ID | Never | Never, with MFA required for everyone | |
| northwindtraders.onmicrosoft.com | Microsoft Entra ID | Never | Never, with MFA required for everyone | |
| parked.example low | Microsoft Entra ID | 90 days | 14 days | Never, with MFA required for everyone |
Data from MFA registration (), Sign-in methods policy (), Users (), Admin roles (), Conditional Access (), Directory sync ().