Critical

No CA policy enforces MFA for all users

No enabled Conditional Access policy requires MFA (or an authentication strength) for the "All users" scope, and Security Defaults is not enabled.

Category
Authentication
Default severity
Critical
Rule key
CHECK_CA_MFA_COVERAGE
Last updated

How to fix it

Create a Conditional Access policy that requires MFA for all users (or for all admins at minimum). Alternatively, enable Security Defaults for small tenants without CA licensing.

Required Microsoft Graph permissions

EntraAnalyzer needs the following read-only Graph permissions to evaluate this rule:

  • Policy.Read.All
  • Directory.Read.All

Further reading

Microsoft documentation →

Run this check on your tenant

EntraAnalyzer evaluates this rule automatically on every scan and emails you the results.

Get started — free first scan →