Description:

Verifies that system-preferred multifactor authentication is enabled in the Entra ID authentication methods policy and applied to all users, so Entra ID can dynamically select the strongest method a user has registered.

Why:

CIS M365 Foundations Benchmark v6 §5.2.3.6 requires system-preferred multifactor authentication to be enabled in the Entra ID authentication methods policy and applied to all users. This lets Entra ID dynamically select the strongest registered MFA method available to each user at sign-in.

Configured: System-preferred multifactor authentication is enabled and applied to all users.

Not Configured: System-preferred multifactor authentication is disabled or not applied to all users.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)

Compliance Frameworks:

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.6

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.6

  • CIS Controls v8 — 6.3

  • CIS Controls v8.1 — 6.3

Microsoft documentation:


_KB status: new — this check is not yet documented in the knowledge base._

_Source: Augmentt native check, aligned to the CIS Microsoft 365 Foundations Benchmark. Check ID AUG.CIS.M365.5.2.3.6 (module 1083)._

Sourced for this page:

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Identity · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · CIS v8 · CIS v8.1