EIDAUTH-004: Users with Only SMS/Voice MFA Methods

Plataforma
Entra ID / M365
Categoría
Entra ID Authentication Methods & MFA
Severidad
High
Pilar de Zero Trust
Identity (peso 2)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

Users relying solely on SMS or voice-based MFA are vulnerable to SIM swap attacks, where attackers social-engineer mobile carriers to transfer a victim's phone number, and SS7 signaling protocol attacks that intercept SMS messages in transit. These methods provide significantly weaker protection than app-based or hardware token authentication. Organizations should identify and migrate these users to phishing-resistant methods.

Valor recomendado

No users relying exclusively on SMS or voice as their only MFA method

Remediación

Identify users with only SMS/voice MFA via Entra ID > Protection > Authentication methods > User registration details. Create a migration plan to move these users to Microsoft Authenticator or FIDO2 security keys. Consider disabling SMS/voice as allowed methods in the authentication methods policy after migration is complete.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de EIDAUTH-004
EscenarioVeredicto esperado
cleanPASS
known-badWARN
no-dataNot Assessed

Mapeos a marcos de referencia

CISA SCuBA
MS.AAD.3.5v2
NIST SP 800-53
IA-2(1)
CIS M365 Benchmark
5.2.2.4
MITRE ATT&CK
T1111, T1078