{"id":12816,"date":"2026-04-21T09:21:17","date_gmt":"2026-04-21T09:21:17","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/23\/adaptive-mfa-in-entra-okta-and-duo-how-security-teams-hook\/"},"modified":"2026-07-09T17:00:19","modified_gmt":"2026-07-09T17:00:19","slug":"adaptive-mfa-in-entra-okta-and-duo-how-security-teams-hook","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/04\/21\/adaptive-mfa-in-entra-okta-and-duo-how-security-teams-hook\/","title":{"rendered":"Adaptive MFA in Entra, Okta, Duo: Hook 2026 Rollout to NIS2"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min. read<\/p>\n<p><strong>In 2026, adaptive MFA is less a question of technology than a question of evidence. Since Germany&#8217;s NIS2 Implementation Act took effect without a transition period, security teams must not only demonstrate that they have multi-factor authentication in place \u2013 they must show they understand which risks they are mitigating with it. That means the thresholds used to drive decisions need to be documented. Entra Conditional Access, Okta Adaptive MFA, Duo Risk-Based, and Ping Identity all offer the capabilities. Yet rollouts still fail at the same gap: the space between feature and evidence.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">NIS2 mandates MFA but specifies no parameters.<\/strong> Article 21 requires multi-factor authentication yet leaves thresholds and exceptions to each organisation. The documentation obligation is concrete; the technical framework is deliberately broad.<\/li>\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">The choice between Entra, Okta, Duo and Ping comes down to your stack.<\/strong> Organisations running deep on Microsoft 365 typically land on Entra Conditional Access. For multi-IdP environments, Okta remains the most flexible platform; Duo is the default in Cisco contexts; Ping Identity delivers in the enterprise segment.<\/li>\n<li><strong style=\"color:#69d8ed;\">MFA fatigue is the core operational problem.<\/strong> Push bombing and number-matching attacks are on the rise. Without threshold calibration and user training, adaptive MFA loses exactly the effect it is supposed to deliver.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/11\/infostealer-2026-how-stolen-session-cookies-bypass-mfa\/\" style=\"color:#333;text-decoration:underline;\">Infostealer 2026: How Session Cookies Bypass MFA<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/13\/mid-market-identity-sprawl-what-three-common-ad-plus-cloud\/\" style=\"color:#333;text-decoration:underline;\">Identity Sprawl in Mid-Sized Businesses: AD-Plus-Cloud Setups<\/a><\/p>\n<h2>NIS2 Article 21 as the Framework for Adaptive MFA<\/h2>\n<p>Germany&#8217;s NIS2 Implementation Act has been in force since December 6, 2025, with no transition period. Registration with the BSI (Federal Office for Information Security) was mandatory by March 6, 2026. Article 21 of the directive lists ten areas in which organisations must demonstrate measures \u2013 among them access policies, supply chain security, and, explicitly, multi-factor authentication. The directive&#8217;s wording is deliberately open: MFA must be implemented &#8220;appropriately,&#8221; without the EU or BSI prescribing any specific minimum thresholds.<\/p>\n<p>That openness becomes a liability in audits when companies report MFA as active but have no documentation of their threshold logic. An auditor does not simply ask whether MFA is switched on. They ask under what conditions a second factor is enforced, what exceptions are configured, how emergency access is secured, and which logs make the decision behind a conditional access policy traceable. Security teams that have treated MFA as a checkbox item are now firmly on the back foot.<\/p>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#003340;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#fff;letter-spacing:-0.03em;\">March 6, 2026<\/div>\n<div style=\"font-size:15px;color:#fff;margin-top:8px;max-width:480px;margin-left:auto;margin-right:auto;line-height:1.5;\">Deadline for BSI registration under NIS2. Organisations that missed it are now operating under penalty risk and have forfeited room to manoeuvre in any evidence discussion.<\/div>\n<div style=\"font-size:12px;color:#69d8ed;margin-top:12px;\">Source: BSI, NIS2 Implementation Act, in force since December 6, 2025.<\/div>\n<\/div>\n<h2>The Four Major IAM Platforms Compared: Adaptive MFA Head-to-Head<\/h2>\n<p>Microsoft Entra Conditional Access is the obvious choice for organisations running Microsoft 365, because the policy engine integrates directly into the identity stack and draws on signals such as sign-in risk, user risk, and device compliance from Microsoft Defender for Identity. Thresholds can be set at a granular level per group and application. The real effort lies in cleanly mapping policies to user groups and documenting the decision logic. Without proper policy hygiene, you end up two years down the road with a zoo of a hundred overlapping rules that nobody can untangle.<\/p>\n<p>Okta Adaptive MFA positions itself as a multi-IdP platform and excels when multiple identity sources converge \u2013 Active Directory, G Suite, HR systems, and more. Its risk-scoring engine relies on device fingerprinting, network reputation, and behavioural patterns. For organisations that aren&#8217;t deeply embedded in Microsoft, Okta is often the first choice. It costs more than Entra, but the flexibility is correspondingly greater.<\/p>\n<p>Duo Security, now part of Cisco, is widely deployed in the mid-market and among companies running Cisco infrastructure. Its risk-based features are mature, and integration with Cisco ISE and Umbrella saves money and time for those who have already invested in that stack. Ping Identity plays a stronger role in enterprise environments with complex B2B integrations, Customer Identity Access Management (CIAM), and federated identities than it does in the classic mid-market. The four platforms overlap in core functionality but differ considerably in how deeply they integrate with existing stacks.<\/p>\n<p>In practice, legacy application support often matters more than any feature matrix. Many German mid-sized companies run applications that understand neither SAML nor OpenID Connect. Header-based authentication, RADIUS proxies, and certificate-based SSH access are standard in that context. Duo and Ping have more depth in this area, while Entra has caught up significantly over the past 18 months through Entra Application Proxy and Entra ID Governance. Okta covers the gap via its Access Gateway. Evaluating these edge cases should be part of the selection phase \u2013 otherwise the rollout stalls the moment a core ERP system or a specialist application can&#8217;t be onboarded.<\/p>\n<p>Licensing is the second variable that shifts significantly in any comparison. Microsoft Entra Conditional Access is included in Entra ID P1 and P2, with P2 unlocking risk-based policies through Identity Protection. Okta licenses per user across multiple packages covering MFA, Adaptive MFA, and Lifecycle Management. Duo offers a clear tiered model with Duo Essentials, Advantage, and Premier. Ping tends to sit higher in enterprise pricing, but provides deeper customisation options in return. Anyone looking for a benchmark price should always compare the specific configuration being deployed, not headline per-user list prices.<\/p>\n<h2>Why MFA Fatigue Is the Number One Rollout Risk<\/h2>\n<p>A successful Adaptive MFA rollout hinges not on the policy engine, but on user experience. Push bombing attacks \u2013 where attackers repeatedly trigger MFA prompts until a user confirms out of habit \u2013 became standard playbook material in 2025. The industry&#8217;s answer is number matching, which requires users to enter a displayed code into the authenticator app. Microsoft has enabled this by default; Duo and Okta have their own variants. Any organization not enforcing number matching is leaving the door wide open.<\/p>\n<div style=\"display:grid;grid-template-columns:repeat(auto-fit,minmax(280px,1fr));gap:16px;margin:28px 0;\">\n<div style=\"background:#fafafa;border-top:3px solid #c0392b;padding:18px 20px;border-radius:4px;\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#c0392b;\">What Triggers MFA Fatigue<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Push prompts without context (no app name, no geolocation)<\/li>\n<li style=\"margin-bottom:6px;\">Thresholds set too low, triggering on every login<\/li>\n<li style=\"margin-bottom:6px;\">Lack of user education about phishing attempts<\/li>\n<li>No reporting tooling for suspicious prompts<\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#fafafa;border-top:3px solid #2d7a3e;padding:18px 20px;border-radius:4px;\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#2d7a3e;\">What Reduces Fatigue Attacks<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Number matching enabled by default for all users<\/li>\n<li style=\"margin-bottom:6px;\">Risk-based policies that ease friction for trusted devices<\/li>\n<li style=\"margin-bottom:6px;\">Self-service report button built into the authenticator<\/li>\n<li>SIEM integration for push bombing pattern detection<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>Threshold calibration is the second challenge. When an Adaptive MFA system demands a second factor on every other login, prompt fatigue sets in and workarounds emerge. When it challenges too rarely, the security benefit evaporates. The pragmatic approach is to launch with conservative policies in the first three months and use telemetry to learn which login patterns are genuinely anomalous. Entra, Okta, and Duo all offer dashboards that make prompt frequency visible per user and risk level.<\/p>\n<p>One frequently overlooked area is the handling of service accounts and API access. Adaptive MFA is optimized for interactive user logins. Automated processes require certificate-based authentication or short-lived tokens with rotation. Organizations leaving service accounts protected only by long-lived passwords \u2013 with no MFA \u2013 are maintaining an attack vector that adversaries will actively target in 2026. Documenting the service account policy is part of NIS2 evidence requirements, not just user-facing MFA.<\/p>\n<p>A third component scrutinized during audits is the handling of external users. Suppliers, contractors, and partners regularly gain access to internal systems without going through the standard IAM process. Entra B2B Collaboration, Okta External Identities, and Ping DaVinci provide dedicated functions that give external parties a clean MFA path. Organizations forcing external users into internal accounts face not just an evidence gap, but an attack surface that was actively exploited in multiple supply chain incidents throughout 2025.<\/p>\n<h2>How Security Teams Can Execute a Clean Rollout<\/h2>\n<p>A realistic rollout runs in four phases spanning ten to twenty weeks depending on organizational size. The first phase is inventory; the last is audit readiness.<\/p>\n<div style=\"margin:28px 0;border:1px solid rgba(230,227,218,0.12);border-radius:6px;overflow:hidden;\">\n<div style=\"background:#003340;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">Adaptive MFA Rollout in Four Phases<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">Phase 1 (Wks 1-4)<\/div>\n<div style=\"color:#333;line-height:1.55;\">Inventory: Catalog all IAM sources, segment user groups by risk class, list service accounts separately. Without a clean inventory, policies become arbitrary.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">Phase 2 (Wks 4-10)<\/div>\n<div style=\"color:#333;line-height:1.55;\">Policy design: Define Conditional Access or risk-based rules per user group and application. Set number matching as the default. Document the emergency path for break-glass accounts.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">Phase 3 (Wks 10-16)<\/div>\n<div style=\"color:#333;line-height:1.55;\">Pilot: Run one user group as a pilot, observe for two weeks, evaluate telemetry, tune thresholds. Write a support playbook for MFA lockouts and device registration issues.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">Phase 4 (Wk 16+)<\/div>\n<div style=\"color:#333;line-height:1.55;\">Audit readiness: File policy documentation in the IT governance system, maintain records of threshold decisions, schedule quarterly reviews with the CISO and data protection officer.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>The most common weakness in any rollout is the missing link to incident response. When the SIEM spots suspicious login patterns but the IAM team doesn&#8217;t know how to quarantine accounts quickly, Adaptive MFA develops a blind spot. The integration between Entra or Okta and the SOC pipeline belongs in phase one, not bolted on at the end. In practice, that means Splunk, Sentinel, or Elastic need sign-in logs, risk events, and policy-change events in a central store, with alerts on patterns like ten failed logins in five minutes or a prompt originating from an unusual country. Log formats differ between Entra and Okta, and normalization is a workstream that cannot be delegated to the SIEM vendor.<\/p>\n<p>Finally, the most important point: Adaptive MFA is not a project with a finish line \u2013 it is an ongoing operation. Thresholds shift as attackers adopt new techniques. New applications get onboarded, user groups evolve. Organizations that treat the rollout as a one-time project will find themselves, eighteen months later, with an IAM stack that no longer reflects the current threat landscape. A dedicated IAM operations role and quarterly policy reviews are what turn Adaptive MFA into productive, auditable evidence.<\/p>\n<p>A concrete real-world reference: a mechanical engineering firm in the Sauerland region launched its rollout on Entra Conditional Access in late 2025. The pilot ran for two weeks with an IT user group and deliberately conservative policies. In the first three days, 140 MFA prompts per user per day were recorded because a policy trigger fired on every switch between VPN and the office LAN. After calibrating with compliant-device status as a signal, the prompt count dropped to 12 to 18 per day \u2013 a level users accepted. The lesson: telemetry during the pilot phase is not an optional feature; it is the instrument that determines whether people will actually embrace the system.<\/p>\n<p>Another issue that surfaces regularly in audit discussions is the distinction between authentication and authorization. MFA decides whether someone is allowed to log in securely. What they can do afterward is governed by authorization \u2013 through Role-Based Access Control (RBAC), Privileged Access Management (PAM), or just-in-time access. Many organizations conflate the two, leading to the mistaken belief that strong MFA compensates for weak role configuration. It does not. NIS2 explicitly requires access policies under Article 21. Those policies must rest on a sound role architecture, not on the MFA prompt alone.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Does NIS2 explicitly require Adaptive MFA, or is classic MFA sufficient?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The directive calls for &#8220;appropriate&#8221; MFA without specifying exact parameters. Organisations using classic MFA with a strong second factor meet the requirement \u2013 provided the documentation is clean. Adaptive MFA is not mandatory, but for risk-exposed organisations it has become the de facto standard in practice, because it makes thresholds and exceptions auditable and transparent.<\/p>\n<\/details>\n<details>\n<summary><strong>How does a migration from Duo to Entra Conditional Access work in Microsoft 365 environments?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Typically in parallel, not as a big bang. Conditional Access kicks in first for Microsoft applications, while Duo remains in place for Cisco systems and legacy applications. After six to nine months it usually becomes clear whether a full switch is worthwhile or whether a hybrid setup makes more sense long term.<\/p>\n<\/details>\n<details>\n<summary><strong>What thresholds are a good starting point for Adaptive MFA?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">A typical starting point: trigger an MFA prompt on login from a new device, an unknown network IP, outside working hours, or when accessing sensitive applications. After three months, thresholds are adjusted based on telemetry \u2013 often resulting in some conditions being tightened and others relaxed.<\/p>\n<\/details>\n<details>\n<summary><strong>How do I handle service accounts that can&#8217;t support interactive MFA?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Service accounts use certificate-based authentication or Managed Identities, combined with short-lived tokens and secrets rotation in the vault. The protection level is not MFA, but it is equivalent. Documenting this decision is important so that auditors understand the policy rationale.<\/p>\n<\/details>\n<details>\n<summary><strong>What does the BSI say about Number Matching as a default?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The BSI recommends Number Matching or equivalent methods in its current guidance documents, without framing it as an explicit obligation. Microsoft has configured Number Matching as the default for Entra Authenticator; Duo and Okta strongly recommend it and feature it prominently in the admin consoles of current releases. Anyone using push confirmations without matching must justify that decision in their risk analysis and record it in their NIS2 documentation.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/21\/opus-4-7-vs-gpt5-4-why-european-cloud-providers-are-now\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-opus-4-7-gpt-5-4-eu-cloud-inference-2026-8513156.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Opus 4.7 vs GPT-5.4: Why European cloud providers back local AI<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/predictive-analytics-in-erp-how-mid-market-tech-teams\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-predictive-analytics-erp-mittelstand-kun-29254584-250x173.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Predictive Analytics in ERP: Boosting Customer Retention<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/between-nvidia-dominance-and-alternatives-how-cios-are\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-nvidia-dominanz-alternativen-ki-stack-ci-88736577-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Between NVIDIA Dominance and Alternatives: How CIOs Are Sorting Their AI Stack in 2026<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"NIS2 mandates MFA but specifies no thresholds. How security teams set up rollout in Entra, Okta, and Duo with audit-proof evidence.","protected":false},"author":10,"featured_media":12540,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"","_yoast_wpseo_title":"Adaptive MFA in Entra, Okta and Duo: How Security Teams Hook the 2026 Rollout to","_yoast_wpseo_metadesc":"Deploy Adaptive MFA in Entra Conditional Access, Okta & Duo with NIS2 evidence: thresholds, service accounts, and MFA fatigue defense.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255,259],"tags":[],"class_list":["post-12816","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en","category-strategie-governance-en"],"evm_reading_time_minutes":13,"wpml_language":"en","wpml_translation_of":12541,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12816","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=12816"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12816\/revisions"}],"predecessor-version":[{"id":21557,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12816\/revisions\/21557"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/12540"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=12816"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=12816"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=12816"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}