Access Control · AP-AC-001
Every user with access to PHI or production systems must authenticate with a second factor (TOTP, push, or hardware token).
Enable Conditional Access in Microsoft Entra to require MFA for all users. AuditPilot can pre-fill the policy template — your IT admin just needs to approve it.
Microsoft Graph: /users + /policies/conditionalAccessPolicies
Person or Entity Authentication
Logical Access — User Authentication
User Authentication for External Connections
Microsoft 365 MFA enforcement export
Microsoft Entra · uploaded 2 days ago by Jordan Reyes