All baseline controls
Identityhigh priority

MFA required for active accounts

MFA registration for enabled identities. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

MFA registration for enabled identities

Every enabled directory account must have multi-factor authentication registered. An active account with no MFA is the single highest-leverage gap in an identity estate — it turns one leaked password into full access.

Interpret the result in context

Registration shows that a method exists; it does not prove that every sign-in is challenged or that the method is phishing-resistant. Pair this check with conditional access review.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

A fixed baseline expectation

This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Confirm the account is in scope and identify its owner.

  2. 02

    Arrange MFA registration through the organisation’s approved enrolment process.

  3. 03

    Refresh directory evidence and review the applicable sign-in policy.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access