Skillplan M365 Checklist
2026-07-20 19:26
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 5 of 17
Multi-Factor & Phishing-Resistant Auth
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Enable phishing-resistant authentication methods (FIDO2 keys, Windows Hello for Business, certificate-based auth) tenant-wide.
Not Fulfilled
Fulfilled
Accepted
Enforce phishing-resistant MFA for all administrative roles via Conditional Access Authentication Strengths.
Not Fulfilled
Fulfilled
Accepted
Disable SMS and voice-call MFA methods for any account holding an administrative role.
Not Fulfilled
Fulfilled
Accepted
Enable Microsoft Authenticator number matching for all users to defeat MFA-fatigue attacks.
Not Fulfilled
Fulfilled
Accepted
Enable additional context (app name, location) in Authenticator push notifications.
Not Fulfilled
Fulfilled
Accepted
Run an authentication methods registration campaign to nudge users to Authenticator and away from SMS.
Not Fulfilled
Fulfilled
Accepted
Audit and remove unused legacy MFA methods (security questions, voice OTP) from all user profiles.
Not Fulfilled
Fulfilled
Accepted
Run an authentication-strength audit quarterly to confirm no admin role has a weak factor configured.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →