$0 Security Sprint

Check what actually enforces MFA

Separate authenticator registration from enforcement, then prepare a request or inspect a scoped work sign-in with permission.

No additional software purchase for the starting steps. Your time, storage and provider support may still have costs.

Entries stay in this tab and clear on reload. Do not enter passwords, secrets or confidential information.

01 / Tailor your starting point

What do you already know?

Choose “Not sure” when you need help. Changing any selection clears your observations and reported outcome.

Which identity service handles your work sign-in?
Can you perform the checks with permission?
How would you like to begin?

02 / Work through your task

Before you begin

Part 1 of 7. Moving through the steps does not mark a check as complete.

  • Identify the work identity provider and the administrator who can inspect enforcement.
  • Choose an ordinary work account, important application and sign-in path to discuss. Do not use an emergency administrator account.

03 / Record what you found

Your observations, kept in this tab

All fields are optional, up to 300 characters each. Use synthetic or non-sensitive summaries. No passwords, tokens, confidential data or personal contact details.

Use a non-sensitive description of the account, app and path.

No tokens, screenshots or identifiers. Summarize what remains uncertain.

A role or team is enough.

What still needs attention?

Optional observations or questions. Keep confidential details out.

What can you report for the stated result?

An observation applies only to the stated account, application and sign-in path. It does not prove coverage for every user, administrator, guest, legacy protocol or application. Preparation results do not verify operational protections.

$0 Security Sprint / Purposeful Security

Check what actually enforces MFA

Ask how MFA is enforced for a work sign-in

Having an authenticator registered does not establish that a sign-in requires a second factor.

No additional software purchase for the starting steps. Your time, storage and provider support may still have costs.

  • Access: Not sure
  • Approach: Prepare first
  • Environment: Not sure

Local outcome: Not checked

Self-reported only. This website has not verified the result.

An observation applies only to the stated account, application and sign-in path. It does not prove coverage for every user, administrator, guest, legacy protocol or application.

Costs and permissions

Use existing records and services. No new software purchase is required to prepare; staff time and provider support may have costs.

Prerequisites

  • Identify the work identity provider and the administrator who can inspect enforcement.
  • Choose an ordinary work account, important application and sign-in path to discuss. Do not use an emergency administrator account.

Actions

  1. Identify the responsible administrator or provider. If you are unsure which identity service you use, ask them before using Microsoft-specific instructions.
  2. Ask which enforcement mechanism applies to the chosen account and application, including relevant scope and exceptions.
  3. Ask for an authorized, coordinated inspection of policy and sign-in evidence. Ask whether existing licenses cover the needed controls and reports.
  4. Record the scope, the evidence the administrator can supply and unanswered questions. Do not change settings or attempt repeated sign-ins.

What to verify

  • A confirmed contact or response is a preparation result, not verification of MFA enforcement.
  • A prompt alone, or the absence of a prompt, is inconclusive. Prior authentication and sessions can affect what you see.

Recovery if something fails

  • If access is denied or the provider is unknown, stop and leave the enforcement check Not checked or Needs follow-up.
  • If a coordinated sign-in fails, use known support. Do not disable protections, revoke sessions or repeatedly retry until an account locks.

Request for the responsible team

Please identify how MFA is enforced for our chosen ordinary work account, application and sign-in path. Please confirm policy scope and exceptions, inspect sign-in evidence in an authorized test, and explain whether a prior session satisfied MFA. Please confirm licensing and reporting limits. Do not change policies for this request.

Optional observations

Scope checked
Not recorded
Evidence summary
Not recorded
Follow-up owner
Not recorded
Next action
Not recorded
Notes
Not recorded

Sources and related guidance

Sources reviewed October 6, 2026. Operational steps have not been lab-tested by Purposeful Security.

Store this card privately if it contains internal details. Review those details before sharing.

Keep your next move

Download, copy or print locally. Review any internal details before sharing the card. The public mission link contains none of your entries.

Sources and testing

Sources reviewed October 6, 2026. These steps have not been lab-tested by Purposeful Security. We have not tested your systems or independently checked your result. How we prepare guidance.