Azure Multi-Factor Authentication Setup Procedure
Account Lockout
Number of MFA denials to trigger account lockout - 5
Minutes until account lockout counter is reset - 15
Minutes until account is automatically unblocked - 15
Fraud Alert
Allow users to submit fraud alerts - on
Automatically block users who report fraud - off (initially to review cases for false positives)
Code to report fraud alerts - 0
Notifications
Policies
Microsoft Authenticator
Requirements:
Azure AD P1 and/or P2 (example: conditional policies)
References: