CTD-000045

Microsoft Entra user not registered with MFA

Medium
Entra ID
Credential Access Persistence
v58

Signature Identity

CTD-000045
Threat ID
58
Version
IOE
Indicator Type

Threat Description

An account of a regular user that is not registered with MFA or uses insecure authentication methods doesn't have sufficient protection against modern threats. According to a report by Microsoft, you can block more than 99.9% of account hacking attempts by using multi-factor authentication. Multi-factor authentication is a process in which users are prompted during the sign-in process for an additional form of identification, such as a code on their cellphone or a fingerprint scan. Using only a password to authenticate a user, allows a malicious actor to easily get access if he guesses a weak password or finds it exposed elsewhere. When the second form of authentication is required, security is increased because in most cases a malicious actor can´t pass this additional challenge.

MITRE ATT&CK: Attack Tactics

Credential Access Persistence

D3FEND: Defend Tactics

Multi-factor Authentication

Remediation

  1. To check user’s progress of registering authentication methods using Microsoft Entra admin center:
    1. Open User registration details in Microsoft Entra admin center as a Conditional Access Administrator, Security Administrator, or Global Administrator.
    2. Find user by UPN or Name.
  2. To force users to register MFA authentication method:
    1. Open the Microsoft Entra admin center as a Conditional Access Administrator, Security Administrator, or Global Administrator.
    2. Browse to Protection > Identity Protection > Multifactor authentication registration policy.
    3. Under Assignments click Users.
    4. Choose All users or Select individuals and groups if limiting your rollout.
    5. Optionally you can choose to exclude users or groups from the policy.
    6. Set Policy enforcement – Enabled.
    7. Click Save.
  3. To enforce multifactor authentication for users with Conditional Access policies:
    1. Open the Microsoft Entra admin center.
    2. Browse to Protection > Conditional Access.
    3. Click Create new policy.
    4. Give your policy a name.
    5. Under Assignments select Users.
      1. Under Include select All users or Select users and groups to configure specific users and groups.
      2. Under Exclude select Users and groups or Select users and groups.
      3. Choose your organization’s emergency access or break-glass accounts.
    6. Under Target resources select Cloud apps.
    7. Configure exclusions on the Exclude tab.
    8. Select All cloud apps on the Include tab (and don’t exclude any apps).
    9. Under Access controls > Grant select Grant access > check Require multi-factor authentication and leave all other conditions blank.
    10. In the Enable policy section select On.
    11. Press Create.

Frequently Asked Questions

What does Microsoft Entra user not registered with MFA mean?

A Microsoft Entra user account is considered unsecured if it lacks multi-factor authentication (MFA), making it susceptible to unauthorized access if an attacker obtains or guesses the password. Specifically, this configuration allows attackers to authenticate as the user without needing additional verification.

The absence of MFA in a Microsoft Entra user account does not grant administrative privileges, but it increases the risk of account takeover and unauthorized access if an attacker successfully guesses or obtains the password. This vulnerability can support later attacker activity by providing unsecured access to sensitive resources.

Attackers can exploit a missing MFA by guessing or obtaining a weak password, allowing them to authenticate as the user and potentially escalate privileges or move laterally within the organization. This capability enables attackers to maintain persistence in the environment.

Cayosoft Guardian continuously monitors authentication settings for users in Microsoft Entra, identifying those without MFA and flagging them as security issues to provide administrators with visibility into vulnerabilities. This detection supports investigation by highlighting potential entry points for attackers.

Cayosoft Guardian alerts administrators to enable MFA for affected users, ensuring all accounts have robust protection against unauthorized access and reducing the likelihood of security breaches. This support helps teams respond by providing a clear plan of action to remediate vulnerabilities.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection
Attack Tactics
Credential Access Persistence
Defend Tactics
Multi-factor Authentication
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical