Example, read only. A sample account that shows what finished CMMC looks like.

← Back to the 15 safeguards
IA · Identification and AuthenticationMET

Safeguard 6 of 15 · IA.L1-b.1.vi

IA.L1-3.5.2 · FAR 52.204-21 (b)(1)(vi) · NIST SP 800-171 3.5.2

Authentication

Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems

What it means

Before letting anyone into your systems, verify they are who they say they are, typically a password plus a second factor (MFA).

Why it matters

This is the control primes scrutinize most. Password-only access is a near-automatic rejection in 2026. MFA on all admin accounts is the floor.

How to do it, Microsoft 365

  1. 1Go to admin.microsoft.com → Security & compliance (or entra.microsoft.com → Protection → Conditional Access)
  2. 2Open the policy that enforces MFA (often 'Require MFA for all users' or Security Defaults)
  3. 3Screenshot the policy showing it is enabled and applies to all users
  4. 4Also capture Users → Active users → filter 'MFA status: Enforced' to show coverage

Capture: Two screenshots: (1) the Conditional Access policy or Security Defaults page showing MFA is on, (2) the user list showing MFA enforced per account.

The proof on file

  • entra-mfa-conditional-access.pngReviewed, sufficient

Every file is checked by Charlie the moment it is uploaded, so a gap is caught on the spot, not at the assessment.

The narrative on file

All accounts require a password meeting the company policy plus multi factor authentication through Microsoft Authenticator. MFA is enforced by a Conditional Access policy for every user in the tenant, verified in the admin center screenshot on file.

You answer in plain English; Charlie writes the official narrative for your System Security Plan.

What makes it pass

  • Tenant-level MFA / 2-Step policy is visible and shows status = Enabled / Enforced
  • Per-user enrollment report shows MFA status for every account (no users left at 'Disabled')
  • Any MFA-exempt accounts (break-glass, service) are documented with a reason
  • Date of capture visible

Assessment objectives, NIST SP 800-171A

[a] Each user's identity is authenticated before system access
MET
[b] Each process acting on behalf of a user is authenticated before access
MET
[c] Each device accessing the system is authenticated before access
MET

This is one of 15

Answer in plain English, drop the proof, confirm it MET.

Cedar Ridge Machine Works, LLC walked all 15 the same way. The platform explains each one in plain English, tells you exactly what to grab, checks it, and writes the paperwork, and you confirm each one MET. The self assessment stays your act. Start free, or book a call.