PA-05: Require Phishing-Resistant MFA for Admins
Frequently asked questions about implementing and managing the PA-05 security control in Microsoft 365 and Entra ID.
QWhat is PA-05 (Require Phishing-Resistant MFA for Admins)?▼
PA-05 is a security control that traditional mfa (push notifications, sms) can be bypassed through social engineering and mfa fatigue attacks. phishing-resistant methods like fido2 keys cannot be phished because they require physical presence and cryptographic proof. It requires that all users with privileged roles have registered phishing-resistant mfa and fido2 security keys, windows hello for business, or device-bound passkeys required, sms and voice call mfa methods are blocked for admin accounts.
QWhy is Require Phishing-Resistant MFA for Admins important for Microsoft 365 security?▼
Traditional MFA (push notifications, SMS) can be bypassed through social engineering and MFA fatigue attacks. Phishing-resistant methods like FIDO2 keys cannot be phished because they require physical presence and cryptographic proof.
QHow do I implement PA-05 in my tenant?▼
Creates Conditional Access policy requiring FIDO2/Windows Hello for privileged roles
QWhat license do I need for PA-05?▼
This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.
QWhich security baseline includes PA-05?▼
PA-05 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.
QWhy is PA-05 marked as critical severity?▼
PA-05 is rated critical because failure to implement this control significantly increases the risk of security incidents. Traditional MFA (push notifications, SMS) can be bypassed through social engineering and MFA fatigue attacks. Phishing-resistant methods like FIDO2 keys cannot be phished because they require physical presence and cryptographic proof.
6
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial