Ensure that privileged identities with access to Microsoft Entra ID-enabled VM instances are configured to use Multi-Factor Authentication (MFA). MFA is a simple, yet efficient method of verifying your user identity by requiring an authentication code generated by a virtual or hardware device, also known as passcode, used in addition to your usual access credentials such as user name and password.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
Microsoft Entra ID credentials can be used to log in to Azure virtual machine (VM) instances. This is useful because it simplifies access management and strengthens security. Instead of managing separate passwords, users can leverage their existing Entra ID credentials, which can be centrally enforced with Multi-Factor Authentication and conditional access policies. This reduces the risk of compromised credentials and streamlines the login process. Multi-Factor Authentication (MFA) for privileged identities that use Microsoft Entra ID credentials adds an extra layer of protection, ensuring only authorized users with the correct credentials and verification code can access VM instances, even if a password is compromised.
Audit
To determine if privileged identities with access to your Microsoft Entra ID-enabled VM instances are using Multi-Factor Authentication, perform the following operations:
Remediation / Resolution
To ensure that privileged identities with access to Microsoft Entra ID-enabled VM instances are configured to use Multi-Factor Authentication (MFA), perform the following operations:
References
- Azure Official Documentation
- Sign in to a Linux virtual machine in Azure by using Microsoft Entra ID and OpenSSH
- How it works: Microsoft Entra multifactor authentication
- Plan a Microsoft Entra multifactor authentication deployment
- Use the sign-ins report to review Microsoft Entra multifactor authentication events
- Enable per-user Microsoft Entra multifactor authentication to secure sign-in events
- Azure Command Line Interface (CLI) Documentation
- az vm list
- az ad user list
- az role assignment list
- Azure PowerShell Documentation
- Azure Active Directory (MSOnline)
- MSOnline
- Get-MsolUser
- Set-MsolUser
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Enable MFA for Privileged Identities with Access to Virtual Machines
Risk Level: Medium