{"id":"T1556.006","name":"Multi-Factor Authentication","url":"https://attack.mitre.org/techniques/T1556/006","tactics":["defense-impairment","persistence","credential-access"],"platforms":["IaaS","Identity Provider","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0190","stix_id":"x-mitre-detection-strategy--eccad822-4f5b-4337-8c8b-825cf617f853","name":"Detect MFA Modification or Disabling Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0190","analytics":[{"id":"AN0543","stix_id":"x-mitre-analytic--97cb8df9-f100-4a64-802a-1aa2f45c26eb","name":"Analytic 0543","description":"Detects registry and Group Policy modifications that disable or weaken MFA, suspicious PowerShell usage modifying MFA-related attributes, and anomalous login sessions succeeding without expected MFA challenge.","url":"https://attack.mitre.org/detectionstrategies/DET0190#AN0543","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4739","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:PowerShell","channel":"Set-ADUser or Set-ADAuthenticationPolicy with MFA attributes disabled","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"WatchedAttributes","description":"List of AD attributes or policy fields tied to MFA enforcement that may vary by organization."},{"field":"TimeWindow","description":"Correlation window between MFA policy changes and anomalous login behavior."}],"live":true,"detection_strategies":["DET0190"],"techniques":["T1556.006"]},{"id":"AN0544","stix_id":"x-mitre-analytic--33b7f7b2-b79c-4893-bd5c-2d5638bf5786","name":"Analytic 0544","description":"Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users.","url":"https://attack.mitre.org/detectionstrategies/DET0190#AN0544","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Modify Conditional Access Policy","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"azure-signinlogs"},{"name":"m365:unified","channel":"User excluded from MFA or MFA method registered","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"PrivilegedRoles","description":"Roles permitted to modify MFA settings in IdP; helps tune detection of unauthorized changes."}],"live":true,"detection_strategies":["DET0190"],"techniques":["T1556.006"]},{"id":"AN0545","stix_id":"x-mitre-analytic--3090db89-83c0-44bc-a17d-7cb2a6aecb87","name":"Analytic 0545","description":"Detects API calls to cloud secrets/MFA configurations where MFA enforcement policies are disabled or bypassed.","url":"https://attack.mitre.org/detectionstrategies/DET0190#AN0545","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"UpdateIdentityPolicy or DisableMFA","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"MonitoredServices","description":"Specific cloud services or IAM policies relevant to MFA enforcement."}],"live":true,"detection_strategies":["DET0190"],"techniques":["T1556.006"]},{"id":"AN0546","stix_id":"x-mitre-analytic--d0a9cbc4-d190-44fb-b067-27153e35dc49","name":"Analytic 0546","description":"Detects PAM module modifications or removal of MFA hooks in /etc/pam.d/ configurations, correlated with successful authentications lacking MFA prompts.","url":"https://attack.mitre.org/detectionstrategies/DET0190#AN0546","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/write to /etc/pam.d/*","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"NSM:Connections","channel":"Successful login without expected MFA challenge","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"MFAHooks","description":"Paths to organization-specific PAM modules enforcing MFA."}],"live":true,"detection_strategies":["DET0190"],"techniques":["T1556.006"]},{"id":"AN0547","stix_id":"x-mitre-analytic--3a19d0ff-833f-47ae-81a0-2516e91c7b25","name":"Analytic 0547","description":"Detects modifications to authorization plugins responsible for MFA enforcement and correlates with suspicious login sessions missing MFA prompts.","url":"https://attack.mitre.org/detectionstrategies/DET0190#AN0547","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Modification of /Library/Security/SecurityAgentPlugins","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Login success without MFA step","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WatchedPluginPaths","description":"Paths to organization-deployed MFA authorization plugins."}],"live":true,"detection_strategies":["DET0190"],"techniques":["T1556.006"]},{"id":"AN0548","stix_id":"x-mitre-analytic--81c940cd-633b-4f88-9f8f-f6837a7026bc","name":"Analytic 0548","description":"Detects suspicious MFA method changes, such as registration of weaker factors (e.g., SMS), or removal of MFA requirements for specific accounts or groups.","url":"https://attack.mitre.org/detectionstrategies/DET0190#AN0548","platforms":["SaaS"],"log_source_references":[{"name":"saas:zoom","channel":"DisableMFA or RegisterNewFactor","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"saas-zoom"}],"mutable_elements":[{"field":"AcceptedFactors","description":"Configured MFA factors allowed in SaaS environment; tuned to organizational policies."}],"live":true,"detection_strategies":["DET0190"],"techniques":["T1556.006"]},{"id":"AN0549","stix_id":"x-mitre-analytic--1193139d-0032-4d0b-88f1-c140abe2c964","name":"Analytic 0549","description":"Detects MFA bypass attempts by modifying tenant-wide authentication policies or excluding high-value accounts from MFA enforcement.","url":"https://attack.mitre.org/detectionstrategies/DET0190#AN0549","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Set-CsOnlineUser or UpdateAuthPolicy","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"MonitoredPolicies","description":"Specific tenant or suite policies tied to MFA enforcement."}],"live":true,"detection_strategies":["DET0190"],"techniques":["T1556.006"]}],"live":true,"version":"1.0","techniques":["T1556.006"]}],"sigma_rules":[{"id":"28eea407-28d7-4e42-b0be-575d5ba60b2c","title":"Azure AD Only Single Factor Authentication Required","author":"MikeDuddington, '@dudders1'","status":"test","level":"low","date":"2022-07-27","modified":null,"description":"Detect when users are authenticating without MFA being required.","references":["https://learn.microsoft.com/en-gb/entra/architecture/security-operations-user-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.defense-impairment","attack.t1078.004","attack.t1556.006"],"path":"rules/cloud/azure/signin_logs/azure_ad_only_single_factor_auth_required.yml","techniques":["T1078.004","T1556.006"],"cves":[]},{"id":"50e068d7-1e6b-4054-87e5-0a592c40c7e0","title":"Okta MFA Reset or Deactivated","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-09-21","modified":"2026-04-27","description":"Detects when an attempt at deactivating  or resetting MFA.","references":["https://developer.okta.com/docs/reference/api/system-log/","https://developer.okta.com/docs/reference/api/event-types/"],"logsource":{"product":"okta","service":"okta"},"tags":["attack.persistence","attack.credential-access","attack.defense-impairment","attack.t1556.006"],"path":"rules/identity/okta/okta_mfa_reset_or_deactivated.yml","techniques":["T1556.006"],"cves":[]},{"id":"60de9b57-dc4d-48b9-a6a0-b39e0469f876","title":"Disabling Multi Factor Authentication","author":"Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule)","status":"test","level":"high","date":"2023-09-18","modified":null,"description":"Detects disabling of Multi Factor Authentication.","references":["https://research.splunk.com/cloud/c783dd98-c703-4252-9e8a-f19d9f5c949e/"],"logsource":{"product":"m365","service":"audit"},"tags":["attack.persistence","attack.credential-access","attack.defense-impairment","attack.t1556.006"],"path":"rules/cloud/m365/audit/microsoft365_disabling_mfa.yml","techniques":["T1556.006"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}