特権ロールで MFA が要求されない

HIGH

バージョン 202608241311

Aug 24, 2026, 1:11 PM

  • Detection (Ignore the "Directory Synchronization Accounts" and "On Premises Directory Sync Account" roles, whose assignees are the Microsoft Entra Connect and Cloud Sync service accounts, which cannot require MFA without breaking the synchronization)
  • Metadata (Explain that the Microsoft Entra Connect and Cloud Sync service accounts must be excluded from the recommended Conditional Access policy, since they cannot comply with an MFA requirement, and exclude the two directory synchronization roles from the policy created or edited by the remediation script)

Release: 202608241311