This is a coverage drill, not a setup walkthrough.
If MFA (multi-factor authentication) is already on — or you think it is — spend 20 minutes confirming the rule is in place, people are enrolled, and it works on real apps. Then write it down. If it is not on yet, use the Microsoft 365 MFA setup guide first.
CISA lists requiring MFA in Four Cybersecurity Essentials for Businesses and the Cybersecurity Performance Goals. This is how a 5–50 person team proves the control is real.
What “MFA coverage” means in plain language
Coverage is not a checkbox that says “MFA is on.”
It means three things at once:
- Policy — Microsoft 365 requires a second step at sign-in.
- Enrolled — each person has registered a method (app, security key, or — last resort — phone).
- Works on real apps — Outlook, Teams, SharePoint, and bookkeeping tools still complete that second step.
Microsoft’s Multifactor authentication for Microsoft 365 guidance: use Security Defaults or Conditional Access — never both. They do not mix. Zero Trust guidance for small businesses calls this “verify explicitly.”
How do I check MFA coverage? Confirm one enforcement path, check enrollment for admins then everyone, spot-check three real sign-ins, and save a dated log.
Before you start (3 minutes)
Set the 20-minute timer after you have the items below. Look; don’t change settings.
Grab these three things
- Admin access. Sign in at admin.microsoft.com or entra.microsoft.com as a Global Administrator (or sit with the person who is).
- A user list. Microsoft 365 admin center → Users → Active users. Mark the owner, office manager, bookkeeper, and admin roles.
- A blank coverage log. New note or spreadsheet. Copy the Minute 17–20 table. Date it today.
The 20-minute drill
Stay in look-only mode. If policy is missing, finish the log, then open the setup guide.
Minute 0–5: Confirm MFA is required
Pick one path. Write it at the top of the log: Security Defaults or Conditional Access. Never both.
Security Defaults (common on Business Basic and Business Standard): open the Microsoft Entra admin center → Identity → Overview → Properties → Manage security defaults. Note Enabled or Disabled.
Conditional Access (typical on Business Premium, E3, or E5): Entra → Protection → Conditional Access → Policies. Find a policy that requires multifactor authentication. Note On, Report-only, or Off. Report-only does not count as required.
Microsoft: you can use Security Defaults or Conditional Access, not both at the same time. If Security Defaults is on, you cannot turn CA policies on. If any Conditional Access policy exists (On, Off, or Report-only), you cannot turn Security Defaults on.
If both look attempted, or you cannot tell which path is live, write unclear. Do not flip switches during the drill.
- One path recorded: Security Defaults or Conditional Access
- Not both in use
- If Conditional Access: the MFA policy is On, not Report-only
Minute 5–12: Check enrollment admins then everyone
Policy without registration is not coverage.
Admins first. In Entra, open Users → All users (or Microsoft 365 Users → Active users). Scan for Global Administrator and other admin roles (Exchange, SharePoint, Billing, Security). Then open Protection → Authentication methods → User registration details. If that blade is missing, use Users → Active users → Multi-factor authentication in the Microsoft 365 admin center.
Check in this order: every admin role; owner, office manager, bookkeeper; everyone else. Mark enrolled, not enrolled, or unknown. Note the method if shown (Authenticator, security key, SMS).
Watch for shared mailboxes used as sign-in accounts, a former consultant still listed as admin, and “office@” or “admin@” accounts with full access.
- Every admin role is enrolled
- Owner, office manager, and bookkeeper are enrolled
- Remaining active users enrolled or listed as a gap
Minute 12–17: Spot-check real sign-ins
A green registration row is not a working sign-in. Spot-check three people: owner, office manager, bookkeeper. If one person wears two hats, pick the next person who handles money, clients, or email.
Option A — live sign-in. Sign out of Outlook or Teams and back in. Confirm the second-step prompt. Note the app.
Option B — sign-in log. Entra → Monitoring → Sign-in logs. Filter to that user and a recent success. Look for MFA required and satisfied. Write the app and pass/fail.
If a sign-in succeeds with password only, coverage failed for that account.
- Owner, office manager, and bookkeeper: real app showed MFA
- Failures written in the log (app + what happened)
Minute 17–20: Write the coverage log
Leave blanks as unknown. Do not guess.
Drill date: YYYY-MM-DD · Tester: · Policy path (one): Security Defaults / Conditional Access · Both in use? No / Yes (gap)
| Person / account | Role | Policy applies? | Enrolled? | Method | Spot-check app | Result | Notes |
|---|---|---|---|---|---|---|---|
| Owner / Global Admin | Y / N | Y / N | Outlook / Teams | Pass / Fail | |||
| Office manager | Y / N | Y / N | Email / SharePoint | Pass / Fail | |||
| Bookkeeper | Y / N | Y / N | Email / accounting | Pass / Fail |
Next drill date: 90 days from today, or insurance renewal if sooner.
Save as MFA-coverage-YYYY-MM-DD in a shared folder the owner can find. Done when the log is saved — not when every gap is fixed.
Which MFA methods to prefer (CISA order)
Coverage includes what people enrolled, not only that they enrolled.
CISA Cybersecurity Performance Goals 2.0 (3.F, Implement Multi-factor Authentication) ranks methods strongest to weakest:
- Phishing-resistant / FIDO — a FIDO2 security key or similar WebAuthn / PKI method. First choice for admins and the emergency account.
- Authenticator app with number matching — Microsoft Authenticator (or another app) that shows a number you match. Practical default for most staff.
- SMS or voice — only if no other option. Still a second step; weakest on CISA’s list.
Four Cybersecurity Essentials for Businesses uses the same order. So does NIST SP 800-63B-4 (Authentication and Authenticator Management).
If someone is on SMS only, mark enrolled and “upgrade method.”
Which MFA method should we use? Prefer a FIDO2 security key for admins; Microsoft Authenticator with number matching for everyone else; SMS only when no other method is possible.
Lockout prevention without weakening MFA
Prevention does not mean turning MFA off.
- Second Global Administrator. If only one person can change tenant settings, a lost phone becomes an outage. Add a second trusted Global Admin and enroll that account too.
- Second method on each admin. Authenticator plus a FIDO2 key (or another backup the owner controls).
- Break-glass still uses MFA. Keep a dedicated emergency Global Admin with a long random password and recovery materials in a safe or password manager. That account must use MFA. Prefer a FIDO2 security key stored with those materials.
Never leave break-glass without MFA. “Emergency” is not a reason to skip the second step. Store the key and password so two trusted people know where they are.
CISA’s #StopRansomware Guide calls for phishing-resistant MFA on email and critical systems.
Does a break-glass admin account need MFA? Yes. Prefer a FIDO2 security key. Do not create a no-MFA exception.
If the drill finds gaps
Gaps are normal. The log is the point.
| Gap | What to do next |
|---|---|
| No policy, or path is unclear | Use the MFA setup guide. Security Defaults or Conditional Access — never both. |
| Both paths attempted | Pick one path in the setup guide. Do not leave them mixed. |
| Conditional Access is Report-only | Not enforcement. Enroll, then set the policy to On. |
| Admins or staff not enrolled | Enroll this week. Do not skip admins. |
| Enrolled but spot-check failed | Re-test that person and app (mobile Outlook is a frequent miss). |
| SMS-only on an admin | Keep MFA on. Add Authenticator or a FIDO2 key. |
| Only one Global Admin | Add a second admin with MFA before you change policy. |
| Break-glass has no MFA | Add a FIDO2 key. Do not remove MFA to “make recovery easier.” |
If the gap is “we never turned it on,” the setup guide is next. After a fix, re-run Minutes 5–20 on the people you changed.
Save evidence for insurance (optional)
Some insurers ask whether MFA is required and whether you can show it. This is not legal or coverage advice — it is a folder habit.
Keep it simple: Security Defaults Enabled or Conditional Access On; the admin enrollment list; and this dated log. Name files with the date. Store them next to your backup test log. Update at renewal or quarterly.
Related guides
- MFA setup for Microsoft 365 — enable policy if this drill found none
- Test your backup in 15 minutes — the matching restore drill
- 5 security mistakes Houston SMBs make
- Resources — CISA and NIST references
Educational content only — not legal, insurance, or compliance advice.