
Multi-Factor Authentication Methods Acceptable Under CMMC
CMMC Level 2 expects MFA for specific access types; this post explains acceptable factor types, Microsoft methods that fit, and the evidence assessors request.

CMMC Level 2 expects MFA for specific access types; this post explains acceptable factor types, Microsoft methods that fit, and the evidence assessors request.

Contractors should verify Cyber AB authorization, independence, ISO/IEC 17020 status, and alignment to the CAP and NIST SP 800-171 when choosing a C3PAO for future CMMC Level 2 assessments, while using Microsoft resources as implementation references, not as assessment criteria.

Sensitivity label inheritance in Microsoft Purview can help files and emails keep CUI-equivalent markings, but contractors need clear NARA-aligned marking policy, targeted configuration, and testing to make the behavior hold across Office, Exchange, SharePoint, and OneDrive.

Assessors accept boundary diagrams that show the true system boundary, key internal boundaries, and CUI flows, supported by evidence that matches the SSP and CMMC scoping.

ITAR 120.54 permits end-to-end encrypted, unclassified technical data in the cloud when you control keys and avoid proscribed routing, but the deemed export rule keeps identity and access at the center of any Microsoft 365 strategy.

Inherited controls help only when you define the CUI boundary, assign ownership for each assessment objective, and point to evidence in the SSP and CRM that applies to in-scope assets.