Description:
Verifies that authenticator login context information is enabled.
Why:
This stopgap security policy helps protect the tenant when phishing-resistant MFA has not been enforced and Microsoft Authenticator is used. This policy helps improve the security of Microsoft Authenticator by showing user context information, which helps reduce MFA phishing compromises.
Configured: Authenticator login context information is enabled.
Not Configured: Authenticator login context information is disabled.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
CISA SCuBA — MS.AAD.3.3
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.1
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.1
Microsoft documentation:
