ID-06: Complete Authentication Methods Policy Migration

Frequently asked questions about implementing and managing the ID-06 security control in Microsoft 365 and Entra ID.

Q
What is ID-06 (Complete Authentication Methods Policy Migration)?
A

ID-06 is a security control that the legacy per-user mfa system cannot be centrally managed or monitored. migrating to the unified authentication methods policy enables centralized control over passkeys, fido2, and all mfa methods. It requires that authentication methods policy migration state is "migrationcomplete" and legacy per-user mfa settings are no longer active, all authentication methods are managed via unified policy.

Related controls:ID-06
Q
Why is Complete Authentication Methods Policy Migration important for Microsoft 365 security?
A

The legacy per-user MFA system cannot be centrally managed or monitored. Migrating to the unified Authentication Methods policy enables centralized control over passkeys, FIDO2, and all MFA methods.

Related controls:ID-06
Q
How do I implement ID-06 in my tenant?
A

ID-06 requires manual implementation. Migration requires Entra Admin Center: Protection > Authentication methods > Policies

Related controls:ID-06
Q
What license do I need for ID-06?
A

This control can be implemented with any Microsoft 365 subscription, including free Azure AD.

Related controls:ID-06
Q
Which security baseline includes ID-06?
A

ID-06 is included in the TrueConfig Recommended Secure baseline (Level 1). This is the foundation level suitable for most organizations.

Related controls:ID-06

5

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial