> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/no-strong-mfa-configured.md).

# No Strong MFA Configured

Detects accounts where every active multi-factor authentication method is a weak form of verification, such as SMS codes, email one-time passwords, or voice calls, leaving them more vulnerable to interception and SIM-swapping attacks than accounts protected by stronger authentication methods. Accounts where the identity source is managed through a federated provider or Okta accounts where all weak factors are designated as recovery methods only, are excluded from this check.

The National Institute of Standards and Technology (NIST) recommends using authenticator apps or cryptographic solutions such as Duo Verified Push or Passwordless, Google Authenticator, Okta Verify, or Microsoft Authenticator, as well as hardware security keys, as strong second factors.

**Recommended Actions**

Encourage users to replace weak authentication methods with a stronger alternative such as an authenticator app or hardware security key, prioritizing accounts with access to critical systems and administrative privileges. Where a user has a legitimate reason to remain on a weaker method, document the exception and consider providing a physical hardware security key as a more secure fallback option.

**Compatibility**

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)

[Okta](/integrations/okta-data-integration.md)

[Duo](/integrations/duo-security-integration.md)
