Skip to main content

MFA Context in Overe Scan Results

How Overe scan results identify the specific MFA enforcement method in use, distinguishing between Security Defaults, Conditional Access policies and per-user MFA enforcement.

D
Written by David McCandless

What it is

When Overe runs a Deep Scan, tells you not just whether MFA is in place for a tenant, but how it is being enforced. Scan results identify whether MFA protection comes from Security Defaults, from a Conditional Access policy or from Per-user MFA enforcement. giving you a clearer picture of each tenant's security posture.
​

What each enforcement method means

Security Defaults
Microsoft's baseline protection. When Security Defaults are enabled, all users are required to use MFA, but the settings cannot be customised. Security Defaults and Conditional Access cannot both be active at the same time.
​

Conditional Access policy
A configurable, policy-based approach that lets you define who must authenticate, under what conditions, and with what methods. This is the recommended approach for tenants on Microsoft 365 Business Premium, M365 E3/E5, or with an Entra ID P1 licence.
​
​Per user MFA enforcement
This is a legacy method that doesn't allow authentication method visibility or the ability to define which methods are sufficient. Read more
​

How to use it

When reviewing scan results in Overe, check the MFA context shown for each tenant. If a tenant shows Security Defaults rather than Conditional Access, this is a signal to review whether that tenant has the licensing and readiness to move to policy-based enforcement. Conditional Access gives you more control, allows exclusions, and is a prerequisite for several Overe policy controls.
​

Did this answer your question?