Description:
Verifies that the weaker SMS and Voice Call authentication methods are disabled in the Entra ID authentication methods policy.
Why:
Traditional MFA methods such as SMS codes and voice calls are weaker authenticators that are more susceptible to phishing and SIM swapping. This check verifies that those methods are disabled.
Configured: SMS and Voice Call authentication methods are disabled.
Not Configured: SMS or Voice Call authentication methods are enabled.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks:
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.5
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.5
Microsoft documentation:
