Rule
Office 365 Multi-Factor Authentication Disabled
Purpose
Detects when Multi-Factor Authentication is disabled to a user account.
Objective
Detect when Multi-Factor Authentication (MFA) is disabled for an account.
How to test
Log in to the Azure Active Directory or Office 365 admin portal using an administrator account.
Disable MFA for the test user account.
Navigate to Users > Multi-Factor Authentication settings.
Find the test user and disable MFA for their account.
Verify MFA is disabled by attempting to log in to the test user’s account without MFA