Ross ROSS = Recommend OSS · open-source software intelligence for agents

dafthack/MFASweep

A tool for checking if MFA is enabled on multiple Microsoft Services observed · 2026-08-28

github.com/dafthack/MFASweep · PowerShell · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

67/100

  • Activity 77
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2171
  • days_rel: n/a
  • days_push: 142
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1692 stars · 229 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

MFASweep is a PowerShell script that attempts to log in to multiple Microsoft services with provided credentials to detect whether MFA is enforced on each. It covers Graph API, Azure Resource Manager, Exchange Web Services, the M365 web portal with various user agents, Active Sync, and on-prem ADFS.

Use cases

  • check if MFA is enabled across Microsoft services for an account
  • find Microsoft services left single-factor due to conditional access gaps
  • audit MFA inconsistencies in a Microsoft 365 tenant
  • test whether ADFS allows single-factor login
  • pentest Azure AD accounts for MFA bypasses
  • verify conditional access policy coverage per protocol

When to choose

  • you have authorized credentials and need to audit MFA enforcement across Microsoft services
  • you are doing a security assessment of an Azure AD/M365 tenant
  • you want to detect protocols bypassing conditional access policies

When to avoid

  • you lack authorization to test the target account (account lockout and legal risk)
  • you need a continuous MFA monitoring solution rather than a point-in-time check
  • you need non-Microsoft identity provider coverage

Facets

cli-tool · maturity active

security penetration-testing auth cli security penetration-testing cloud-computing windows cli cross-platform mfa microsoft-365 azure adfs conditional-access red-team powershell

1 source

Member repositories

RepositoryRoleHealth v2
dafthack/MFASweepmain67

For agents

markdown · JSON · MCP: product_card(name="dafthack/MFASweep")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem