Weak MFA Was Used To Successfully Sign In

Detects users that have successfully logged in with a weak form of Multi-Factor Authentication (MFA).

The National Institute of Standards and Technology (NIST) recommends using one-time password solutions or cryptographical solutions such as Google Authenticator, Okta Verify, or Microsoft Authenticator as the second factor of authentication, as SMS and voice calls are susceptible to attacks.

Recommended Actions

Encourage users to use stronger authentication on a more regular basis. If that is not possible, we recommend tagging users with administrative privileges in critical services like Okta and Workday, and providing them with physical authentication solutions like Yubikey.


Microsoft Entra ID



Last updated