No Strong MFA Configured
Detects accounts where every active multi-factor authentication method is a weak form of verification, such as SMS codes, email one-time passwords, or voice calls, leaving them more vulnerable to interception and SIM-swapping attacks than accounts protected by stronger authentication methods. Accounts where the identity source is managed through a federated provider or Okta accounts where all weak factors are designated as recovery methods only, are excluded from this check.
The National Institute of Standards and Technology (NIST) recommends using authenticator apps or cryptographic solutions such as Duo Verified Push or Passwordless, Google Authenticator, Okta Verify, or Microsoft Authenticator, as well as hardware security keys, as strong second factors.
Recommended Actions
Encourage users to replace weak authentication methods with a stronger alternative such as an authenticator app or hardware security key, prioritizing accounts with access to critical systems and administrative privileges. Where a user has a legitimate reason to remain on a weaker method, document the exception and consider providing a physical hardware security key as a more secure fallback option.
Compatibility
Last updated