Registered is not
enforced or used.
Review one redacted list of critical services and roles. Record three different facts—method registered, policy enforced and use observed—plus a dated evidence reference. The tool exposes unknowns; it never connects to an identity provider or claims an account is protected.
MFA evidence-state register
| Service / role | Criticality / method | Registered | Policy | Observed use | Verified / next review / evidence |
|---|
A typed row is not proof. Registration does not prove enforcement; an enforced policy does not prove every sign-in was challenged; observed use does not prove future protection. Verify in each authoritative identity or service report.
Identity and security boundary: raw CSV stays in this browser; the paid pack receives only redacted service aliases, roles, states, dates and evidence references. Do not enter names, email addresses, tenant IDs, passwords, security answers, recovery codes, tokens, QR seeds, session data or confidential policy exports. The tool does not connect to Entra, Google, Okta or any service; inspect accounts, validate evidence, change policy, enroll users, recover access or certify compliance. An authorized human must verify every state in the source system.
$9 MFA evidence review pack
Unlock an editable Markdown pack with the three-state register, critical gaps, method-strength questions, evidence index and human signoff. It documents a review; it does not prove control effectiveness or make security changes.
- registration / enforcement / observed-use separation
- critical service-role gap register
- method-strength and exception questions
- dated evidence-reference index
- authorized owner and next-review signoff
Authoritative guidance and strong native reporting substitutes
PMF pre-judgment 74/100 · security need is clear, but identity platforms already provide authoritative registration and sign-in reports