Short answer
Conditional Access can enforce MFA if every applicable cloud authentication path actually receives it. A trusted-location rule that bypasses cloud MFA is insufficient. Supported passkeys with user verification can meet the requirement, and a valid authenticated session does not require a fresh prompt on every request. Check the effective policies, exclusions, legacy paths and session settings with the assessor.
Why this matters
An MFA licence or registration is not proof of enforcement. Check the actual authentication paths: MFA is required where available, and cloud authentication must use MFA.
Assessors need to understand user, administrator and third-party access. Verify effective policies and prevent bypasses of mandatory cloud MFA. Phishing-resistant administrator authentication is strong additional practice; a fresh prompt on every request is not a universal scheme rule.
What to check next
- Check every user account, not just staff with Microsoft 365 licences.
- Disable legacy authentication paths that cannot support MFA.
- Separate day-to-day and administrator accounts and protect both with MFA.
Official sources and related Fig Group guidance
For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.