All baseline controls
Identityhigh priority

Privileged roles require MFA

Second-factor coverage for Global Administrators. Part of the standard Alignr Baseline library for proactive technical alignment.

Join Waitlist for Early Access
WHAT THIS CONTROL CHECKS

Second-factor coverage for Global Administrators

Accounts holding Global Administrator must have MFA registered — a privileged account with no second factor is one stolen password away from a full tenant compromise.

Interpret the result in context

This baseline targets the Global Administrator role. Other privileged roles and emergency-access identities need their own explicit standards and exception handling.

YOUR STANDARD

Configure the expectation.

Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.

A fixed baseline expectation

This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.

FROM FINDING TO ACTION

Review. Remediate. Verify.

Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.

  1. 01

    Review the role assignment and confirm that it is still required.

  2. 02

    Register an approved MFA method or remove unnecessary privilege.

  3. 03

    Verify the refreshed role and registration evidence; document any approved exception.

A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.

Make your baseline part of every client review.

Connect checks, findings and remediation to the same client record.

Join Waitlist for Early Access