Skip to content
Skip to main content
Cloud Services Technical Explainer

What is multi-factor authentication in a cloud service?

Multi-factor authentication (MFA) requires the service to accept evidence from more than one authentication category - for example, a password plus control of a registered authenticator. It can create strong evidence about the access route, but its meaning depends on the method, prompt sequence and resulting session.

Dave's approval is an event in a longer sequence

At 09:07 a sign-in for Dave's Northstar account presents a password from an Edge browser. Microsoft Entra then requires Microsoft Authenticator. The sign-in details record the method sequence and a successful result. At 09:09 OneDrive records an access event through the new session.

That chain is more informative than the phrase “MFA passed”. It identifies the account, methods, timing and service response. The remaining question is who controlled the browser and registered authenticator, and whether the approval was deliberate.

“Something you have” must be made specific

Method Representative evidence Useful next comparison
Authenticator notification or code Method name, challenge result, registered authenticator/device, prompt time App/device records, notification history and possession at that time
Hardware security key Registered key or credential identifier and authentication result Seizure/possession, registration history and device/browser activity
SMS or voice code Delivery destination, challenge/result and time Provider delivery record, handset/SIM evidence and account-recovery history
Device biometric unlocking a credential Authentication method and device-bound credential context Registered device, local unlock evidence and browser/application session
Recovery or helpdesk route Recovery method, reset event, actor and newly registered factor Support ticket, administrator audit and subsequent authentication

Avoid translating every method into “Dave's phone”. A registered method may have moved devices, a household may share a handset, an administrator may have reset it, or a user may have responded to an unexpected prompt. Those are focused alternatives to test, not reasons to discard a successful MFA record.

Check whether the user was prompted at this event

Cloud services can carry earlier authentication claims into later access. A record may show that an MFA requirement was satisfied without a new prompt at the time being examined. Conversely, several failed or timed-out method steps may be grouped within one sign-in record.

Preserve:

  • the root authentication method and every recorded method step;
  • success, failure and reason fields;
  • the policy or requirement applied;
  • correlation, request, session and token identifiers;
  • factor registration, removal and recovery changes; and
  • the resource event produced by the resulting cloud session.
Microsoft Entra MFA reporting - checked 2 September 2026

Microsoft Entra's sign-in Authentication Details can show the authentication policies applied, the sequence of methods and whether each attempt succeeded. Microsoft warns against relying on the authenticationRequirement field alone because an earlier MFA claim may satisfy later access without a fresh prompt.

Microsoft currently describes MFA categories as something known, possessed or inherent to the user, and lists methods including Microsoft Authenticator, OATH codes, FIDO2 security keys and Windows Hello for Business. Available methods and displayed details depend on configuration and product changes.

State what the evidence supports

Microsoft Entra recorded successful password and Microsoft Authenticator steps for Dave's account between 09:07 and 09:08, then created access associated with the 09:09 OneDrive event. This strongly connects the cloud access to those registered authentication routes. Device, prompt and possession evidence will test who controlled them and whether the approval was deliberate.

The next card considers the wider personal-attribution question: does a successful cloud login prove who logged in?

The point to remember

Treat MFA as a sequence of recorded methods and decisions, not a magic “secure” label. Join the factor evidence to the account, device, resulting session and resource event.

Reference: CLD-024Cloud Services