Configuring MFA registration policies
We have already discussed MFA in Chapter 2, Authentication and Security, and Chapter 3, Implementing Conditional Access Policies, and illustrated how MFA can be enabled and enforced for your Microsoft 365 users via both the Office 365 Admin Center and by using Conditional Access policies. It is also possible to configure an Azure MFA policy for your cloud-based users from within the Azure AD Identity Protection pane.
In the context of Identity Protection, it is always preferable to require Azure MFA for your user sign-ins as it does the following:
- Provides strong authentication with a choice of verification methods
- Provides your users with the option to effectively take responsibility for their own risk detections and use self-remediation
In order to configure the MFA registration policy within Azure Identity Protection, we need to complete the following steps:
- From the Azure AD Identity Protection pane, navigate to...