Query Regarding Additional MFA in Microsoft Account Security

Venkata V.reddy 25 Reputation points
2024-01-09T02:44:12.7533333+00:00

Hi Microsoft Community,

I have a concern regarding the security features in Microsoft accounts, particularly related to Multi-Factor Authentication (MFA).

As I understand, when adding a new MFA method to our Microsoft accounts, it's possible to do so without being prompted to re-verify the existing MFA. This raises a security question in my mind.

In the scenario where a user account is compromised, and the attacker has already established access using MFA, there seems to be a potential risk. In case an attacker gains access through methods like AITM attacks, they could add an additional MFA method, thereby maintaining persistence.

I would like to inquire if there is an option or setting that can be enabled to ensure that when users add an additional MFA, they are prompted to reconfirm with any of the existing MFA methods. This additional layer of security would be valuable in preventing maintaining persistence.

Your insights and guidance on this matter would be greatly appreciated. Thank you for your time and assistance.

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 120K Reputation points MVP Volunteer Moderator
    2024-01-09T08:39:08.4733333+00:00

    Changing any authentication method does require additional verification, and if we're talking about Entra ID/Microsoft 365 accounts, you can also configure restrictions as to the initial MFA registration, or configure additional controls such as require a TAP. See for example this article: https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-policy-registration

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.