Microsoft Azure MFA is a service that requires an additional authentication factor during sign-in to verify user identity. It protects access to both cloud and on-premises resources by enforcing conditional access policies based on context-aware conditions such as user, device state, location, and sign-in risk. The service supports multiple verification methods, including mobile app push notifications, phone calls, SMS text messages, and time-based one-time passcodes from hardware or software OATH tokens. It allows for per-user and per-app MFA enforcement, self-service registration of authentication methods, and the ability to bypass MFA from trusted IP locations. For legacy applications, app passwords can be generated, and users can report fraudulent sign-in attempts. The service provides administrators with reporting and logging of all authentication activity.