CTD-000044

Privileged Microsoft Entra account not registered for MFA

Critical
Entra ID
Credential Access Persistence
v72

Signature Identity

CTD-000044
Threat ID
72
Version
IOE
Indicator Type

Threat Description

Accounts that do not use multi-factor authentication (MFA) are vulnerable to modern identity-based attacks. Password-only authentication provides insufficient protection against threats such as phishing, password spraying, and credential reuse.

Administrative accounts without MFA pose a high risk. If compromised, attackers can establish persistence, access sensitive data, escalate privileges, and cause significant damage within the environment.

Microsoft reports that MFA blocks more than 99.9% of account compromise attempts. MFA enhances security by requiring an additional verification step during sign-in, such as a one-time passcode, push notification, or biometric factor. Even if a password is exposed, MFA significantly reduces the likelihood of unauthorized access.

Where supported and enabled, remediation for this threat may be automated to help ensure MFA enforcement. For more information, view the automated remediation section in the Remediation advice tab. Otherwise, this threat provides visibility and guidance for manual remediation.

NOTE: This threat definition supports only Microsoft’s native MFA. Accounts protected by third-party MFA providers—such as Okta, Duo Security, Ping Identity, RSA SecurID, OneLogin, or CyberArk Identity—may be flagged as lacking MFA.

If your organization uses third-party MFA, consider disabling this threat or configuring exceptions to prevent false positives.

MITRE ATT&CK: Attack Tactics

Credential Access Persistence

D3FEND: Defend Tactics

Multi-factor Authentication

Remediation

Manual remediation
  1. To check user’s progress of registering authentication methods using Microsoft Entra admin center:
    1. Open User registration details in Microsoft Entra admin center as a Conditional Access Administrator, Security Administrator, or Global Administrator.
    2. Find user by UPN or Name.
  2. To force users to register MFA authentication method:
    1. Navigate to the Microsoft Entra admin center as a Conditional Access Administrator, Security Administrator, or Global Administrator.
    2. Browse to Protection > Identity Protection > Multifactor authentication registration policy.
    3. Under Assignments > Users click on All users.
    4. Under Include choose All users or Select individuals and groups.
    5. Optionally, you can decide to exclude users or groups from the policy.
    6. Set Policy enforcement – Enabled.
    7. Press Save.
  3. To enforce multifactor authentication for users with Conditional Access policies:
    1. Open the Microsoft Entra admin center as a Conditional Access Administrator, Security Administrator, or Global Administrator.
    2. Browse to ID Protection > Risk-based Conditional Access > Policies.
    3. Click Create new policy.
    4. Give your policy a name.
    5. Under Assignments select Users:
      1. Under Include select All users or Select users and groups to configure specific users and groups.
      2. Under Exclude, select Users and groups.
      3. Choose your organization’s emergency access or break-glass accounts.
    6. Go to Target resources > All resources (formerly ‘All cloud apps’) > Include.
    7. Configure exclusions on the Exclude tab.
    8. Select All cloud apps (and don’t exclude any apps).
    9. Under Access controls > Grant > select Grant access > check Require multifactor authentication.
    10. Leave all other conditions blank.
    11. Make sure the policy is enabled.
    12. Press Create.
Automated remediation (if enabled and supported)

Where supported and enabled, remediation for this threat may be automated. In this case, the system creates and enables a Conditional Access policy to enforce MFA for the affected privileged account while excluding predefined customer emergency access accounts.

If automated remediation is not available or not enabled, the steps above can be used to manually remediate the issue

Frequently Asked Questions

What does Privileged Microsoft Entra account not registered for MFA mean?

A Privileged Microsoft Entra account lacks multi-factor authentication (MFA), allowing access via only a password. This reduces the protection against phishing and credential reuse attacks.

Privileged accounts without MFA are rated critical because they increase the likelihood of unauthorized access, privilege escalation, and data compromise due to password-only authentication. Specifically, an attacker can gain access to sensitive resources using a compromised password, then use that access to escalate privileges and establish persistence in the environment.

Attackers can exploit a Privileged Microsoft Entra account without MFA by using phishing or credential reuse attacks to gain unauthorized access, then escalate privileges and establish persistence in the environment. This allows them to move laterally within the network, compromising sensitive data and disrupting business operations.

Cayosoft Guardian continuously monitors multi-factor authentication coverage across your Entra ID environment to identify accounts lacking MFA, alerting administrators to take corrective action and provide visibility into the affected accounts.

Cayosoft Guardian alerts administrators to enforce or disable MFA on affected accounts, reducing the attack surface and limiting unauthorized access opportunities. This helps support investigation and response efforts by providing a clear audit trail of changes made to MFA settings.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Privileged Access Management
Attack Tactics
Credential Access Persistence
Defend Tactics
Multi-factor Authentication
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical