CyFun Tracker
PR.AC-3(b)Key Measure

Remote access is secured with multi-factor authentication (MFA)

Protect · Access Control

Fully Automated

Compliance Score

82%

Partially Compliant

Documentation Maturity

4/ 5
x

Target: 2.5

Implementation Maturity

4/ 5
x

Target: 2.5

Control Description

All remote access to organizational resources requires multi-factor authentication. This includes VPN connections, remote desktop, cloud applications, and email access from outside the corporate network.

Microsoft Graph API Endpoints Used

GET /identity/conditionalAccess/policiesGET /reports/authenticationMethods/userRegistrationDetailsGET /users/{id}/authentication/methods

Required Permissions

Policy.Read.AllUserAuthenticationMethod.Read.AllAuditLog.Read.All
Findings (1)
16/20 items compliant
SeverityFinding
medium

Improvement needed: Remote access is secured with multi-factor authentication (MFA)

Current implementation does not fully meet the requirements of PR.AC-3(b).

Remediation Guidance

Create a Conditional Access policy requiring MFA for all users, all cloud apps, from any location. Use Microsoft Authenticator app (not SMS). Ensure all users have registered MFA methods. Block legacy authentication protocols.