Description:
This check verifies that MFA Number Matching is enabled. This requires the Microsoft Authenticator app to be enabled/used.
Why:
Number matching prevents users from approving MFA to a malicious user due to MFA fatigue. The user will be presented with a number to enter in the Authenticator app when receiving MFA push notifications, ensuring that the MFA request is valid.
Status detail shown in Augmentt: You have N out of M settings applied.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.
Category: Identity
Microsoft Licensing: Works with Basic licensing
Remediation in Augmentt: Configure directly in Augmentt (Configure tab)
Compliance Frameworks:
NIST CSF 2.0 — PR.AA-02
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.1
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.1
HIPAA Security Rule — 164.312(d), 164.308(a)(5)(ii)(D)
CMMC Level 1 — IA.L1-b.1.vi
CMMC Level 2 — IA.L2-3.5.3, IA.L2-3.5.4
Microsoft documentation:
