> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/no-mfa-configured.md).

# No MFA Configured

Detects users who do not have Multi-Factor Authentication (MFA) enabled for at least one of their identity sources.

These users are more vulnerable to data breaches and system compromises, making it critical to address these gaps. All users should be using MFA to gain access to the system.

Users will not fail this check if they fall within the grace period of 14 days (configurable), or if they have a federated account.

If needed, adjust the new account grace period in Custom Detection Settings to align with your organization's procedures. This could increase the accuracy and actionability of check results.

#### **Recommended Actions**

Enforce and enable MFA on all identity sources, even if they are not the primary IdP or MFA provider. This ensures that misconfigurations don't allow users to bypass MFA by signing in through alternate identity sources.

Identify accounts with valid reasons to be exempt from MFA or those with mitigating controls in place. Document these accounts in an external system for easier tracking and detection.

For exempt accounts, apply temporary exclusions to resolve failures, then periodically review those accounts to assess and update their status, as needed.

#### **Default Check Settings:**

Grace period for new accounts (days): 14

#### **Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Google Workspace](/integrations/google-workspace-integration.md)

[Duo](/integrations/duo-security-integration.md)

[GitHub](/integrations/github.md)

<figure><img src="/files/judP73OQ1or5Re85k6K0" alt=""><figcaption></figcaption></figure>
