Disable Strong Authentication
Disable Strong Authentication
Event
This legacy-named audit activity concerns per-user strong-authentication requirements. A disabled per-user MFA state does not disable MFA required by Conditional Access or security defaults. Inspect effective policies and authentication results rather than treating this as a universal MFA-off switch.
Security Context
Unauthorized MFA changes may weaken authentication (T1556.006). Policy migration can legitimately disable per-user MFA while enforcing it elsewhere. This change does not make an old password work after a password reset or prove all future logins need only a password.
Log Source
Microsoft Entra directory audit logs. The sample uses activityDisplayName: Disable Strong Authentication. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.
Key Fields
| Field | Investigation value |
|---|---|
targetResources[].modifiedProperties | Recorded StrongAuthenticationRequirement change. |
initiatedBy, additionalDetails | Caller and client hints; user-agent text does not establish a specific legacy API/module. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the change was approved and the caller had appropriate Entra authority.
- Check Conditional Access, security defaults, per-user settings, and the user’s actual authentication methods.
- Review subsequent sign-in authentication details. Do not infer Entra authority from an Azure elevateAccess event.
Sample Event
Synthetic scenario. The sample removes a per-user requirement. It does not establish the effective MFA outcome or that MSOnline was used.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-001010011100_8E4F2_91187533", "category": "UserManagement", "correlationId": "90000000-0000-4000-8000-001010011100", "result": "success", "resultReason": "", "activityDisplayName": "Disable Strong Authentication", "activityDateTime": "2026-04-15T18:04:51.6037229Z", "loggedByService": "Core Directory", "operationType": "Update", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "type": "User", "userPrincipalName": "draco@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [ { "displayName": "StrongAuthenticationRequirement", "oldValue": "[{\"State\":1,\"RememberDevicesNotIssuedBefore\":\"2026-01-15T00:00:00Z\"}]", "newValue": "[]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"StrongAuthenticationRequirement\"" } ] } ], "additionalDetails": [ { "key": "User-Agent", "value": "Mozilla/5.0 (Windows NT; Microsoft Windows 10.0.22631; en-US) PowerShell/7.4.1" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.