MS.AAD.3.4v1 - The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.

Information

To disable the legacy authentication methods screen for the tenant, configure the Manage Migration feature to Migration Complete. The MFA and Self-Service Password Reset (SSPR) authentication methods are both managed from a central admin page, thereby reducing administrative complexity and potential security misconfigurations.

Solution

1. Go through the process of [How to migrate MFA and SSPR policy settings to the Authentication methods policy for Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-methods-manage).
2. Once ready to finish the migration, [set the Manage Migration option to Migration Complete](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-methods-manage#finish-the-migration).

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: microsoft_azure

Control ID: a519c472d55c281a5a2d2d33f5f3eb6bc17c03773a3be8631dad8c8871bc628a