Free tool

MFA readiness check for Microsoft 365

Nine questions, two minutes. Find out whether multi-factor authentication actually protects every account in your tenant, and what to fix first. Your answers never leave this page.

  1. 01Is MFA required for every user, through security defaults or Conditional Access?

    Registered is not the same as required. Check Entra admin centre → Protection → Conditional Access, or Properties → Security defaults.

  2. 02Has every user registered an MFA method?

    Entra admin centre → Protection → Authentication methods → User registration details shows who has not.

  3. 03Is legacy authentication (POP, IMAP, SMTP AUTH, older Office clients) blocked?

    Legacy protocols cannot do MFA, so they let attackers skip it entirely.

  4. 04Do all administrators use phishing-resistant MFA (passkeys, FIDO2 keys or Windows Hello for Business)?

    Codes and push approvals can be phished in real time. Admin accounts are the ones attackers want most.

  5. 05Are SMS and voice calls switched off as MFA methods?

    Text messages can be intercepted or redirected by SIM swapping.

  6. 06Are guest users also required to use MFA?

    Guests with access to Teams and SharePoint are an easy way in if their own accounts are weak.

  7. 07Is MFA required even from the office, with no “trusted location” exceptions?

    Skipping MFA on the office network helps an attacker who is already inside it.

  8. 08Do you have two emergency access (break-glass) accounts, excluded from Conditional Access and monitored?

    Without them, a mistaken policy or an MFA outage can lock every administrator out.

  9. 09Is sign-in blocked on shared mailboxes and room accounts?

    Shared mailboxes have passwords too, and rarely have MFA.

0 of 9 answered. Unanswered questions count as not in place.