New MFA Method for Tenant
Last updated
Detects users who successfully authenticate with an MFA method that has not been observed in your organization in the previous 90 days. The check suppresses methods used by more than 30 distinct accounts during the recent activity window.
A previously unseen MFA method may indicate a policy change, a new device type being enrolled, or an adversary registering their own authenticator after compromising an account.
Recommended Actions
Review the authentication event and confirm the method is expected for this user. If the method is unexpected, investigate recent account activity and authentication policy changes.
Default Check Settings
Evaluation Window Days: 7
Lookback Days: 90
Prevalence Window Days: 7
Max Distinct Accounts Using Method: 30
Compatibility
Last updated