← Back to all posts

How to Check MFA Coverage in Google Workspace and Microsoft 365

To check MFA coverage, review three things separately: who has a suitable method, which access requires it, and what the relevant sign-in records show. A registration percentage answers only the first.

Blue Lantern Security helps make registration review repeatable with its daily identity posture scan. Use those findings to identify accounts needing attention, then verify enforcement and usage in Google Workspace or Microsoft Entra, the identity service used with Microsoft 365.

For a plain-language explanation of the terms, see what MFA means in cybersecurity.

Which accounts and access are you reviewing?

Start with a roster and a named owner. Include administrators, ordinary employees, contractors, and other accounts relevant to the review. Record approved exceptions separately so they are visible in the result.

Then define the applications and access requirements you care about. A policy that covers administrators or one application may not cover other users and services. Avoid calling a result "company-wide MFA coverage" unless you have checked the scope behind it.

Keep the review in three columns:

Evidence Question Follow-up
Registration or enrollment Does this account have a usable method? Resolve missing or unsuitable registration
Applicable policy Does this access require the intended authentication? Review included users, applications, methods, and exceptions
Sign-in evidence What requirement applied and how was it satisfied? Investigate unexpected results or gaps in the available records

How do you check MFA coverage in Google Workspace?

In the Google Admin console, open Reporting, then User Reports, then Security. A role with the Reports privilege is required. Review the separate 2-Step Verification enrollment, enforcement, and protection columns; each answers a different question.

Google notes that enrollment data can be delayed by up to 48 hours and points to a user's security settings for a current individual check. Its user security report documentation explains the fields and edition-dependent availability.

Next, inspect the applicable policy under Security, Authentication, and 2-step verification. Check the relevant organizational units or groups, allowed methods, and enrollment periods. Google's deployment guide explains those controls and the recovery considerations to address before changing enforcement.

For each exception or apparent gap, record the account, the policy that applies, and the owner's next action. If an account's status is unexpected, examine its current settings and relevant sign-in evidence instead of resolving the discrepancy from a summary percentage alone.

How do you check MFA coverage in Microsoft 365?

In the Microsoft Entra admin center, open Entra ID, Authentication methods, then Activity. Use an account with appropriate reporting permissions. Microsoft's native Usage and insights reporting requires Entra ID P1 or P2.

Review Registration and Usage separately. "MFA capable" combines registration of a strong method with policy eligibility to use it; it does not mean every sign-in is required to use MFA. Check the report's scope and exclusions before comparing it with another roster. The data is not real-time: Microsoft's authentication-method activity guide notes a reporting latency of up to 36 hours.

Then inspect the actual enforcement arrangement, such as applicable Conditional Access policies or security defaults. Check the intended users and resources, exclusions, and required methods. Where Conditional Access applies, inspect an appropriate sign-in record's Conditional Access details to see the policy result. Microsoft's guide to applied policies explains that view and its prerequisites.

A user having registered an authenticator does not make an admin-only policy apply to them. Conversely, not seeing a fresh prompt is not itself proof of a bypass: existing sessions or another supported authentication arrangement may explain the experience. Use the records to establish what happened.

Add Blue Lantern Security's daily registration check

In Blue Lantern Security, open the settings for your Gmail or Outlook organization integration, enable the daily identity posture scan, and complete any required permission steps. The identity monitoring setup guide provides the integration details.

Integration Requirements to check What the identity result supplies
Gmail organization The existing directory scope covers the optional identity checks Directory 2-Step Verification status and dormant-account findings
Outlook organization The optional identity checks require AuditLog.Read.All with admin consent; dormancy additionally requires Entra ID P1 or P2 Directory MFA registration and available dormancy findings

These optional-check requirements sit alongside the integration's existing permissions, and Microsoft's own licensing for its native reports still applies.

Review the latest successful run in the Monitoring Hub under Identity. Use the MFA or administrator filter to focus the view, inspect the underlying checks, and use Export CSV if you need a review roster. The export includes the report's checks, so filter the downloaded data for the task at hand.

The scan includes the connected directory, including users whose mailboxes are not monitored, so its denominator may differ from a native report that applies different exclusions. Record each source's scope before reconciling the numbers.

Turn the findings into a short action list

Consider an illustrative review with three findings:

Finding Action
An administrator has no registered method Verify the status, arrange enrollment and recovery, and confirm the policy for admin access
A registered employee falls outside the intended policy Correct the policy scope through the change process, then verify the effect
A recently enrolled user still appears unregistered in an older report Check the individual record, source timestamp, and a later successful report before concluding enrollment failed

Do not disable users or change policies simply to make two percentages agree. Resolve the scope, timing, or policy difference behind the numbers.

After remediation, retain the registration result, applicable policy evidence, and any sign-in evidence used to verify the outcome. Record exceptions with an owner and review date. Include the follow-up in the monthly security review, while addressing urgent admin gaps promptly.

Blue Lantern Security can help you keep finding missing registration. Your directory administrator completes the work by checking that the intended protection is actually required for the access the business relies on.