Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
Also called multifactor authentication.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500AZ-900DP-750SC-900AB-900SC-200SC-300AZ-802DP-600SC-401MD-102DP-800ALZ
Each book explains MFA in context, with comparison tables and the common traps.
Terms in this definition
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
Related terms
- App passwords
When per-user MFA is enforced, older apps that cannot show a browser prompt can sign in with these generated passwords instead, so MFA is skipped. An administrator has to permit their use, and they survive a reset of the user's own password unless removed separately.
- Block access (Conditional Access)
When a Conditional Access policy with this grant applies, the sign-in is refused outright; because block wins over all other controls, meeting MFA or compliance requirements in a different policy cannot override it.
- Bulk enrolment
A provisioning package from Windows Configuration Designer is applied to Windows devices so they join Microsoft Entra ID and enrol in Intune in one go. Its token is valid for 180 days, and MFA can't be used on the account inside the package.
- Certificate-based authentication
Lets people authenticate to Microsoft Entra by presenting an X.509 certificate from your organisation's PKI. Scoped to a group, it becomes an extra option, can count as passwordless MFA and doesn't stop anyone using other methods.
- Eligible assignment
A role assignment in PIM that has no effect until the user activates it, satisfying whatever MFA, justification or approval is required.
- EWS
A legacy Exchange client protocol that falls into the legacy authentication category. Such clients can't perform MFA, so Conditional Access usually blocks them.
- federatedIdpMfaBehavior
Controls, per federated domain, how Microsoft Entra ID treats MFA carried out by the federation provider: accept it, enforce it there, or reject it. Choosing rejectMfaByFederatedIdp means Microsoft Entra MFA always happens. It takes over from SupportsMfa.
- Grant controls
The part of a Conditional Access policy that either blocks access or demands conditions such as MFA, a compliant device or an approved client app. Several can be combined, requiring all of them or just one.