Skip to content

Disable Strong Authentication

Azure

Disable Strong Authentication

service: Azure - Microsoft Entra ID
tactics:
techniques:

Event

This legacy-named audit activity concerns per-user strong-authentication requirements. A disabled per-user MFA state does not disable MFA required by Conditional Access or security defaults. Inspect effective policies and authentication results rather than treating this as a universal MFA-off switch.

Security Context

Unauthorized MFA changes may weaken authentication (T1556.006). Policy migration can legitimately disable per-user MFA while enforcing it elsewhere. This change does not make an old password work after a password reset or prove all future logins need only a password.

Log Source

Microsoft Entra directory audit logs. The sample uses activityDisplayName: Disable Strong Authentication. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.

Key Fields

FieldInvestigation value
targetResources[].modifiedPropertiesRecorded StrongAuthenticationRequirement change.
initiatedBy, additionalDetailsCaller and client hints; user-agent text does not establish a specific legacy API/module.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the change was approved and the caller had appropriate Entra authority.
  3. Check Conditional Access, security defaults, per-user settings, and the user’s actual authentication methods.
  4. Review subsequent sign-in authentication details. Do not infer Entra authority from an Azure elevateAccess event.

Sample Event

Synthetic scenario. The sample removes a per-user requirement. It does not establish the effective MFA outcome or that MSOnline was used.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-001010011100_8E4F2_91187533",
"category": "UserManagement",
"correlationId": "90000000-0000-4000-8000-001010011100",
"result": "success",
"resultReason": "",
"activityDisplayName": "Disable Strong Authentication",
"activityDateTime": "2026-04-15T18:04:51.6037229Z",
"loggedByService": "Core Directory",
"operationType": "Update",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"type": "User",
"userPrincipalName": "draco@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": [
{
"displayName": "StrongAuthenticationRequirement",
"oldValue": "[{\"State\":1,\"RememberDevicesNotIssuedBefore\":\"2026-01-15T00:00:00Z\"}]",
"newValue": "[]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"StrongAuthenticationRequirement\""
}
]
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "Mozilla/5.0 (Windows NT; Microsoft Windows 10.0.22631; en-US) PowerShell/7.4.1"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.