Subscription Owners still satisfy MFA with SMS, and a contractor replayed a text. How should the security engineer raise MFA quality for users who manage Azure without turning the item into an authenticator how-to?
Select an answer to reveal the explanation.
Short Explanation
SMS is a postcard—anyone who intercepts it can walk into Azure. For people who manage subscriptions, demand a stronger method or an authentication-strength grant on the Azure management Conditional Access policy, not another text message.
Full Explanation
Conditional Access can require specific authentication strengths or stronger methods for Azure management apps, reducing reliance on phishable SMS OTP for privileged operators. Disabling MFA or depending on passwords alone weakens the control; SMS plus voice is not phishing-resistant.