EASYENTRA

Knowledge Base

How to Create a Report: User MFA Configuration and Readiness 

Use case: Use this procedure to create a report that shows users’ registered authentication methods, MFA configuration, and readiness for stronger authentication methods. This helps identify users who are not registered for MFA, rely on weaker methods, or need action before moving to stronger authentication.

About report templates 

A report template defines what the report shows (type) and who it targets (scope). Once a template is created, it can be reused to generate new reports or review results from previous runs. The scope of an existing template can be updated at any time, but the type cannot be changed. 

To create a report that lists user MFA configuration and readiness, do the following: 

  • Go to Entra ID, right-click Reports, and select New Report Template
  • Enter a name for the report, such as MFA
  • Set the Category to Security and the Type to MfaConfiguration, then click Next
  • Configure the Scope to narrow the report to a specific Department or Country, or leave these fields blank to include all users. 
  • Under MFA readiness, select the users you want to include: 
    • Any – Includes users regardless of their MFA readiness. 
    • No strong method – Users who do not have a strong authentication method registered. 
    • Action recommended – Users whose current authentication configuration requires attention. 
    • Not MFA registered – Users who are not registered for MFA. 
    • Ready – Users who are ready to use stronger authentication methods. 
  • Under User type, select AnyMembers only, or Guests only
  • Enable Admins only if you want the report to include only administrator accounts. 
  • Click Create, then click Run to generate the report. 
How to Create a Report: User MFA Configuration and Readiness 

Understanding the MFA report columns 

The MFA configuration report provides more than just the authentication methods registered by each user. It also shows whether users are capable of MFA, passwordless authentication, and self-service password reset (SSPR). 

Some of the key columns include: 

  • MFA Readiness – Indicates whether the user’s current authentication configuration is ready or whether further action is required. 
  • Default MFA Method – The authentication method currently used as the user’s default MFA method, such as sms. 
  • Registered Methods – Lists the authentication methods registered by the user, such as mobilePhone or email. 
  • MFA Registered – Indicates whether the user has registered an authentication method that can be used for MFA. 
  • MFA Capable – Indicates whether the user has an authentication method registered that can satisfy MFA. 
  • Passwordless Capable – Indicates whether the user has registered a method that supports passwordless authentication. 
  • System-Preferred MFA – Shows whether system-preferred MFA is enabled for the user. 
  • SSPR Registered – Indicates whether the user has registered authentication information for self-service password reset. 
  • SSPR Enabled – Indicates whether the user is enabled for self-service password reset. 
  • SSPR Capable – Indicates whether the user’s registered methods can be used for self-service password reset. 

To search and filter the report 

  • Use the Search field to search across all report columns in real time.
  • To filter on a specific column, use [ColumnName]=[search phrase].
  • For column names containing multiple words, omit the spaces. You can shorten a column name as long as you include enough characters to identify it uniquely.
  • For example, use DefaultMFAMethod=sms or the shorter def=sms to find users with SMS as their default MFA method.
  • Combine searches across multiple columns, e.g. admin=true mfaread=act, to identify administrators whose MFA Readiness is Action recommended.

To export the report data 

  • Click Export List… to export all results currently displayed in the window.
  • To copy selected rows instead, press CTRL + A to select all rows, CTRL + C to copy them, and CTRL + V to paste them into Excel, Notepad, or another tool.

Related Articles

How to Configure Authentication Methods and MFA

Other Report Types

How to Create a Report: Disabled Users With Microsoft 365 Subscriptions

How to Create a Report: Identify Core Microsoft 365 Workloads Not Being Used

How to Create a Report: Delegated Access to Mailboxes

How to Create a Report: Inactive Users With Microsoft 365 Subscriptions

How to Create a Report: Mailbox and Archive Sizes