Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry
Clients/Northwind Traders

Northwind Traders

northwindtraders.onmicrosoft.com

Passwords and sign-in methods

How people sign in and how strong that is: methods by strength, admins without phishing-resistant MFA, the methods policy, and password age and expiry.

All clients
Download PDFXLSX

Strongest method 4

2 to review CSV

Each enabled member counted once, by the strongest method they have.

PeopleAdminsShare of membersWhat it means
6017%Bound to the real Microsoft sign-in page, so a fake page can't relay it.
14140%Strong, but a convincing fake sign-in page can relay a code or push approval.
3 medium09%Weakest second factor: texts and calls can be intercepted or moved to another SIM.
12 medium034%No second factor: the password alone gets in.

Methods registered 5

How many enabled members have each method. People usually have more than one.

MethodStrengthPeopleAdmins
Windows Hello for BusinessPhishing-resistant50
PasskeyPhishing-resistant10
Authenticator appAuthenticator app or token201
Authenticator code (OATH)Authenticator app or token130
Mobile phone (SMS or call) lowPhone (SMS or voice call)30

Enabled members and what they can sign in with, weakest first and admins at the top. Who hasn't set up MFA at all, and whether it's required, is in MFA coverage.

AccountAdminAdmin rolesStrongest methodMethodsAsked for firstPasswordlessSelf-service reset
ann.patel@northwindtraders.example mediumYesGlobal Administrator, Groups Administrator (limited scope)Authenticator app or tokenAuthenticator appAuthenticator appNoYes
What to do: Admin without a phishing-resistant method: register a passkey or security key.
alfie.roberts@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
alfie.scott@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
grace.wilson@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
hannah.robinson@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
leo.morris@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
leo.wright@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
maya.martin@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
olivia.scott@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
owen.taylor@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
rhys.clark@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
sophie.smith@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
thomas.clarke@northwindtraders.example mediumNoNoneNoUnknown
What to do: No second factor. Set up MFA first (see MFA coverage).
arthur.evans@northwindtraders.example mediumNoPhone (SMS or voice call)Mobile phone (SMS or call)NoUnknown
What to do: Only a phone: set up the Authenticator app (or a passkey), then keep the phone as a backup at most.
mia.hughes@northwindtraders.example mediumNoPhone (SMS or voice call)Mobile phone (SMS or call)NoUnknown
What to do: Only a phone: set up the Authenticator app (or a passkey), then keep the phone as a backup at most.
zara.jackson@northwindtraders.example mediumNoPhone (SMS or voice call)Mobile phone (SMS or call)NoUnknown
What to do: Only a phone: set up the Authenticator app (or a passkey), then keep the phone as a backup at most.
aaron.watson@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
amelia.watson@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
ella.baker@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
ethan.green@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
george.roberts@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
george.robinson@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
hannah.patel@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
harry.lee@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
imogen.edwards@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
megan.lee@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
olivia.smith@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
rhys.moore@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
ruby.taylor@northwindtraders.exampleNoAuthenticator app or tokenAuthenticator app, Authenticator code (OATH)NoUnknown
grace.taylor@northwindtraders.exampleNoPhishing-resistantPasskey, Authenticator appNoUnknown
isla.evans@northwindtraders.exampleNoPhishing-resistantWindows Hello for Business, Authenticator appNoUnknown
jacob.hughes@northwindtraders.exampleNoPhishing-resistantWindows Hello for Business, Authenticator appNoUnknown
leo.evans@northwindtraders.exampleNoPhishing-resistantWindows Hello for Business, Authenticator appNoUnknown
owen.white@northwindtraders.exampleNoPhishing-resistantWindows Hello for Business, Authenticator appNoUnknown
ruby.hill@northwindtraders.exampleNoPhishing-resistantWindows Hello for Business, Authenticator appNoUnknown

Which methods people may register and use, from the tenant's authentication methods policy, against what's recommended for a small business.

SettingCurrentRecommendedWhy
Passkeys and security keys (FIDO2)On for Break glassOnNeeded for phishing-resistant sign-in, which admins should use.
Microsoft AuthenticatorOn for All usersOnThe second factor most people should use.
Authenticator shows which app is signing inMicrosoft managedOn (Microsoft managed turns it on)Helps people spot a sign-in that isn't theirs.
Authenticator shows where the sign-in is from lowOffOn (Microsoft managed turns it on)Helps people spot a sign-in that isn't theirs.
Text message (SMS) lowOn for All users except Break glassOff, once people use AuthenticatorTexts can be intercepted or moved to another SIM.
Voice callOffOffCalls can be redirected, and are easy to approve by mistake.
Email one-time passcodeOn for All usersOff, unless guests or password reset need itNot a second factor for members; only for password reset and guests.
Temporary Access PassOffOn, for setting up passkeysA time-limited pass for setting up a new phone or passkey.
Registration campaign (asks people to set up Authenticator at sign-in)Microsoft managed, for All users, can be skipped for 1 dayOn, or Microsoft managedMoves people off text messages and calls.
System-preferred MFA (asks for the strongest method a person has) lowOffOn, or Microsoft managedOtherwise people are asked for their own default, often a text message.
People can report an MFA prompt they didn't expectMicrosoft managedOnA reported prompt blocks the account's risky sign-ins and alerts admins.
Methods managed in this policy (not the old MFA and SSPR settings)YesYesMicrosoft has retired the old per-user MFA and SSPR method settings.

Authentication strengths in Conditional Access 0

No Conditional Access policy requires an authentication strength. Start with one requiring Phishing-resistant MFA for admin roles, once admins have a passkey.

When each enabled member's password was last set. An old password matters most without MFA; an account that has never signed in may still have the password it was created with. Problems first, then oldest first.

AccountPassword last changedNever expiresSynced from on-premisesLast sign-inMFA set up
thomas.clarke@northwindtraders.exampleUnknownNoNo2 Jun 2026No
hannah.robinson@northwindtraders.exampleUnknownNoNo7 Apr 2026No
sophie.smith@northwindtraders.exampleUnknownNoNo21 Jan 2026No
megan.lee@northwindtraders.exampleUnknownNoNo9 Oct 2026Yes
grace.taylor@northwindtraders.exampleUnknownNoNo11 Oct 2026Yes
owen.white@northwindtraders.exampleUnknownNoNo9 Oct 2026Yes
ruby.taylor@northwindtraders.exampleUnknownNoNo29 Sep 2026Yes
olivia.smith@northwindtraders.exampleUnknownNoNo8 Oct 2026Yes
grace.wilson@northwindtraders.exampleUnknownNoNo11 Oct 2026No
zara.jackson@northwindtraders.exampleUnknownNoNo10 Oct 2026Yes
leo.evans@northwindtraders.exampleUnknownNoNo11 Oct 2026Yes
amelia.watson@northwindtraders.exampleUnknownNoNo10 Oct 2026Yes
george.robinson@northwindtraders.exampleUnknownNoNo10 Oct 2026Yes
hannah.patel@northwindtraders.exampleUnknownNoNo5 Oct 2026Yes
ethan.green@northwindtraders.exampleUnknownNoNo11 Oct 2026Yes
ruby.hill@northwindtraders.exampleUnknownNoNo5 Oct 2026Yes
mia.hughes@northwindtraders.exampleUnknownNoNo10 Oct 2026Yes
rhys.moore@northwindtraders.exampleUnknownNoNo10 Oct 2026Yes
leo.wright@northwindtraders.exampleUnknownNoNo29 Sep 2026No
leo.morris@northwindtraders.exampleUnknownNoNo10 Oct 2026No
isla.evans@northwindtraders.exampleUnknownNoNo5 Oct 2026Yes
owen.taylor@northwindtraders.exampleUnknownNoNo11 Oct 2026No
maya.martin@northwindtraders.exampleUnknownNoNo11 Oct 2026No
arthur.evans@northwindtraders.exampleUnknownNoNo5 Oct 2026Yes
harry.lee@northwindtraders.exampleUnknownNoNo11 Oct 2026Yes
alfie.scott@northwindtraders.exampleUnknownNoNo5 Oct 2026No
rhys.clark@northwindtraders.exampleUnknownNoNo11 Oct 2026No
ella.baker@northwindtraders.exampleUnknownNoNo11 Oct 2026Yes
alfie.roberts@northwindtraders.exampleUnknownNoNo29 Sep 2026No
olivia.scott@northwindtraders.exampleUnknownNoNo9 Oct 2026No
jacob.hughes@northwindtraders.exampleUnknownNoNo11 Oct 2026Yes
george.roberts@northwindtraders.exampleUnknownNoNo29 Sep 2026Yes
aaron.watson@northwindtraders.exampleUnknownNoNo10 Oct 2026Yes
imogen.edwards@northwindtraders.exampleUnknownNoNo9 Oct 2026Yes
ann.patel@northwindtraders.exampleUnknownNoNo30 Sep 2026Yes

Password expiry policy 3

CSV

How often cloud-only accounts on each domain must change their password. Microsoft and the NCSC now advise against regular expiry when everyone has MFA: forced changes lead to weaker, predictable passwords. Accounts synced from on-premises AD follow AD's policy instead.

DomainSigns in withPasswords expire afterReminder before expiryRecommended
northwindtraders.exampleMicrosoft Entra IDNeverNever, with MFA required for everyone
northwindtraders.onmicrosoft.comMicrosoft Entra IDNeverNever, with MFA required for everyone
parked.example lowMicrosoft Entra ID90 days14 daysNever, with MFA required for everyone

Data from MFA registration (), Sign-in methods policy (), Users (), Admin roles (), Conditional Access (), Directory sync ().