> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/new-mfa-method-for-tenant.md).

# New MFA Method for Tenant

Detects users who successfully authenticate with an MFA method that has not been observed in your organization in the previous 90 days. The check suppresses methods used by more than 30 distinct accounts during the recent activity window.

A previously unseen MFA method may indicate a policy change, a new device type being enrolled, or an adversary registering their own authenticator after compromising an account.

**Recommended Actions**

Review the authentication event and confirm the method is expected for this user. If the method is unexpected, investigate recent account activity and authentication policy changes.

**Default Check Settings**

Evaluation Window Days: 7

Lookback Days: 90

Prevalence Window Days: 7

Max Distinct Accounts Using Method: 30

**Compatibility**

[Duo](/integrations/duo-security-integration.md)
