All baseline controls
Identityhigh priority

No MFA bypass in effect

Temporary MFA exceptions that remain active. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

Temporary MFA exceptions that remain active

No account should carry an active MFA bypass. A bypass is sometimes granted for a genuine device-loss emergency, but one left switched on is a standing hole in the MFA policy it was meant to be a temporary exception to.

Interpret the result in context

An exception should have an owner, a reason and an expiry. Review active bypasses in their operational context rather than assuming every exception is unauthorised.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

A fixed baseline expectation

This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Identify the account and the reason for its bypass.

  2. 02

    Restore the approved authentication method and remove the bypass when no longer needed.

  3. 03

    Refresh the bypass evidence and record the closure or approved exception.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access