Skip to main content

Test 86: MFA on Identity Provider

Drata uses its synchronized account delegation with your Identity Provider to request a list of all users and determine if MFA is enabled.

ASSOCIATED DRATA CONTROL

This test is part of the MFA on Accounts control that ensures Multi-Factor Authentication (MFA) is being required for access to any sensitive systems or applications. Drata will verify that in order to log in a user needs to provide their ID, a password, and then either a One-Time Password (OTP) or certificate.

WHAT TO DO IF A TEST FAILS

If Drata finds an identity within your Identity Provider (IdP) that does not have MFA enabled for all users of the application the test will fail. With a failed test you will receive a list of users that do not have MFA enabled on their account.

To remediate a failed test you will have the ability to send email reminders within Drata to each user, reminding them that they need to enable MFA on their account. The emails sent from Drata will direct your employees back to their onboarding tasks in Drata.

STEPS FOR PASSING

  1. Identify failing identities and providers.

    • Navigate to the Monitoring page, search for and open Test 86, and review the Findings tab.

    • Identify which users are failing and note the specific Identity Provider (IdP) associated with their accounts.

    • Check if a failing user has more than one active IdP connected to Drata. Users with multiple identities must have MFA enabled on every active account to pass. A single non-compliant identity will cause the entire user record to fail Test 86.

  2. Enforce MFA in your Identity Provider

    • Log into the relevant IdP and enable MFA for the failing users.

    • We recommend enforcing MFA via Group Policy or Organizational Unit (OU) settings to ensure all current and future users are automatically compliant.

  3. Sync your data. After updating settings in your IdP, Drata needs to verify the changes. You can either:

    • Wait: Drata performs a nightly sync automatically.

    • Manual Sync: To pass the test immediately, navigate to the test and select "Test Now."

Manage Legitimate Exclusions: If an account cannot use MFA (e.g., service accounts or "break-glass" admin accounts), create an exclusion for that account.

HELPFUL RESOURCES

Drata can identify users without MFA enabled, but MFA settings must be updated directly in your identity provider.

For instructions, refer to your provider’s documentation:

Mandatory Microsoft MFA: As of early 2026, Microsoft has enforced mandatory MFA for all admin portals. If your admin accounts are failing Test 86, ensure you haven't bypassed these new defaults with legacy Conditional Access policies.

Did this answer your question?