For the complete documentation index, see llms.txt. This page is also available as Markdown.

New MFA Method for Tenant

Detects users who successfully authenticate with an MFA method that has not been observed in your organization in the previous 90 days. The check suppresses methods used by more than 30 distinct accounts during the recent activity window.

A previously unseen MFA method may indicate a policy change, a new device type being enrolled, or an adversary registering their own authenticator after compromising an account.

Recommended Actions

Review the authentication event and confirm the method is expected for this user. If the method is unexpected, investigate recent account activity and authentication policy changes.

Default Check Settings

Evaluation Window Days: 7

Lookback Days: 90

Prevalence Window Days: 7

Max Distinct Accounts Using Method: 30

Compatibility

Duo

Last updated