MFA shows disable

%3CLINGO-SUB%20id%3D%22lingo-sub-2188944%22%20slang%3D%22en-US%22%3EMFA%20shows%20disable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2188944%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20guys%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMFA%20is%20enabled%20through%20Azure%20AD%2C%20but%20when%20i%20want%20to%20check%20to%20see%20who%20still%20not%20using%20MFA%2C%20it%20shows%20that%20it%20is%20disable%20for%20all%20users.%20i%20have%20been%20looking%20around%20to%20see%20what%20is%20the%20issues%20and%20found%20some%20in%20Microsoft%20community%20and%20they%20says%20that%20we%20should%20turn%20security%20default%20off%20but%20we%20never%20used%20security%20default%20and%20it%20is%20already%20off.%3C%2FP%3E%3CP%3EI%20tried%20another%20ways%20using%20PowerShell%20scripts%20but%20it%20gives%20wrong%20result%20like%20users%20are%20using%20MFA%20but%20the%20result%20was%20they%20don't.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2188944%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Active%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMulti-Factor%20Authentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2189083%22%20slang%3D%22en-US%22%3ERe%3A%20MFA%20shows%20disable%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2189083%22%20slang%3D%22en-US%22%3EHello%2C%20if%20enabling%20AAD%20MFA%20through%20conditional%20access%20it%20doesn't%20change%20the%20state%20of%20the%20user.%20So%20in%20other%20words%2C%20if%20you're%20using%20CA%20for%20MFA%20you're%20all%20set.%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi guys, 

 

MFA is enabled through Azure AD, but when i want to check to see who still not using MFA, it shows that it is disable for all users. i have been looking around to see what is the issues and found some in Microsoft community and they says that we should turn security default off but we never used security default and it is already off.

I tried another ways using PowerShell scripts but it gives wrong result like users are using MFA but the result was they don't. 

 

 

4 Replies
Hello, if enabling AAD MFA through conditional access it doesn't change the state of the user. So in other words, if you're using CA for MFA you're all set.
If you are using Conditional Access, check the sign-in logs to verify users are being prompted, cfr https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/troubleshoot-conditional-...
Thanks for the response,
Is there any way to see who uses MFA and who does not,
I tried a PowerShell script but it gives wrong results, in the report generated by the PowerShell script shows that users did not register for MFA so I went back to AAD to look up the account and found that user is using MFA while the report shows they don't.

@Mohalkhateeb 
good tool could be: 
Azure active directory > security > authentication methods > registration and reset events

Here you can see which user has completed his mfa registration.