ID-04: Require Phishing-Resistant MFA for All Users

Frequently asked questions about implementing and managing the ID-04 security control in Microsoft 365 and Entra ID.

Q
What is ID-04 (Require Phishing-Resistant MFA for All Users)?
A

ID-04 is a security control that phishing attacks can bypass traditional mfa. at level 3, the entire organization uses authentication methods that cryptographically prove user presence, eliminating mfa bypass attacks entirely. It requires that all users must use phishing-resistant mfa (fido2, windows hello, passkeys) and sms and voice call authentication methods are disabled tenant-wide, push notification mfa is disabled or only allowed with number matching.

Related controls:ID-04
Q
Why is Require Phishing-Resistant MFA for All Users important for Microsoft 365 security?
A

Phishing attacks can bypass traditional MFA. At Level 3, the entire organization uses authentication methods that cryptographically prove user presence, eliminating MFA bypass attacks entirely.

Related controls:ID-04
Q
How do I implement ID-04 in my tenant?
A

TrueConfig provides one-click remediation for ID-04. Enables FIDO2 and passkey authentication methods. Users still need to register their own security keys.

Related controls:ID-04
Q
What license do I need for ID-04?
A

This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.

Related controls:ID-04
Q
Which security baseline includes ID-04?
A

ID-04 is included in the Maximum Security baseline (Level 3). This level is designed for high-security environments and regulated industries.

Related controls:ID-04
Q
Why is ID-04 marked as critical severity?
A

ID-04 is rated critical because failure to implement this control significantly increases the risk of security incidents. Phishing attacks can bypass traditional MFA. At Level 3, the entire organization uses authentication methods that cryptographically prove user presence, eliminating MFA bypass attacks entirely.

Related controls:ID-04

6

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial