$0 Security Sprint / Purposeful Security
Check what actually enforces MFA
Ask how MFA is enforced for a work sign-in
Having an authenticator registered does not establish that a sign-in requires a second factor.
No additional software purchase for the starting steps. Your time, storage and provider support may still have costs.
- Access: Not sure
- Approach: Prepare first
- Environment: Not sure
Local outcome: Not checked
Self-reported only. This website has not verified the result.
An observation applies only to the stated account, application and sign-in path. It does not prove coverage for every user, administrator, guest, legacy protocol or application.
Costs and permissions
Use existing records and services. No new software purchase is required to prepare; staff time and provider support may have costs.
Prerequisites
- Identify the work identity provider and the administrator who can inspect enforcement.
- Choose an ordinary work account, important application and sign-in path to discuss. Do not use an emergency administrator account.
Actions
- Identify the responsible administrator or provider. If you are unsure which identity service you use, ask them before using Microsoft-specific instructions.
- Ask which enforcement mechanism applies to the chosen account and application, including relevant scope and exceptions.
- Ask for an authorized, coordinated inspection of policy and sign-in evidence. Ask whether existing licenses cover the needed controls and reports.
- Record the scope, the evidence the administrator can supply and unanswered questions. Do not change settings or attempt repeated sign-ins.
What to verify
- A confirmed contact or response is a preparation result, not verification of MFA enforcement.
- A prompt alone, or the absence of a prompt, is inconclusive. Prior authentication and sessions can affect what you see.
Recovery if something fails
- If access is denied or the provider is unknown, stop and leave the enforcement check Not checked or Needs follow-up.
- If a coordinated sign-in fails, use known support. Do not disable protections, revoke sessions or repeatedly retry until an account locks.
Request for the responsible team
Please identify how MFA is enforced for our chosen ordinary work account, application and sign-in path. Please confirm policy scope and exceptions, inspect sign-in evidence in an authorized test, and explain whether a prior session satisfied MFA. Please confirm licensing and reporting limits. Do not change policies for this request.
Optional observations
- Scope checked
- Not recorded
- Evidence summary
- Not recorded
- Follow-up owner
- Not recorded
- Next action
- Not recorded
- Notes
- Not recorded
Sources and related guidance
Sources reviewed October 6, 2026. Operational steps have not been lab-tested by Purposeful Security.
Store this card privately if it contains internal details. Review those details before sharing.