Description:

This check verifies that MFA Number Matching is enabled. This requires the Microsoft Authenticator app to be enabled/used.

Why:

Number matching prevents users from approving MFA to a malicious user due to MFA fatigue. The user will be presented with a number to enter in the Authenticator app when receiving MFA push notifications, ensuring that the MFA request is valid.

Status detail shown in Augmentt: You have N out of M settings applied.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • NIST CSF 2.0 — PR.AA-02

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.3.1

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.3.1

  • HIPAA Security Rule — 164.312(d), 164.308(a)(5)(ii)(D)

  • CMMC Level 1 — IA.L1-b.1.vi

  • CMMC Level 2 — IA.L2-3.5.3, IA.L2-3.5.4

Microsoft documentation: