Short answer
Use an implementation that provides the required independent authentication factors. FIDO2 passkeys with user verification can satisfy MFA. Authenticator codes, appropriately secured push flows and SMS-based combinations can also be relevant; SMS is not universally banned by the scheme. Prefer phishing-resistant methods for higher-risk access and verify the actual configuration.
Why this matters
An MFA licence or registration is not proof of enforcement. Check the actual authentication paths: MFA is required where available, and cloud authentication must use MFA.
Assessors need to understand user, administrator and third-party access. Verify effective policies and prevent bypasses of mandatory cloud MFA. Phishing-resistant administrator authentication is strong additional practice; a fresh prompt on every request is not a universal scheme rule.
What to check next
- Check every user account, not just staff with Microsoft 365 licences.
- Disable legacy authentication paths that cannot support MFA.
- Separate day-to-day and administrator accounts and protect both with MFA.
Official sources and related Fig Group guidance
For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.