The original Digital Friction report told you what was causing friction and what your users were probably doing instead. Useful — but it didn't tell you how bad it was. "Some of your CA policies might be causing re-authentication fatigue" is a different conversation to "22 of your 24 active CA policies have no session controls configured."
The latest update adds quantified impact to every friction finding — specific numbers from your tenant's actual data, not estimates.
The scenario that prompted this: a user logs into their laptop in the morning, opens Outlook, gets an MFA prompt. Opens Teams, another prompt. Switches to their phone at lunch, two more prompts. By end of day they've authenticated six times and they're furious about it.
This isn't a security gap — it's a configuration gap. Specifically, it's what happens when Conditional Access policies enforce MFA but don't configure session controls telling Entra how long a session should persist.
M365Clarity now reads sessionControls from every active CA policy during a scan. It extracts three signals:
frequencyInterval=everyTime — MFA required on every new session, every device, every browser. Maximum friction.The Digital Friction report now surfaces this as a friction point with a cyan "Quantified impact" panel showing the exact counts. If you have any policies set to everyTime re-auth, it's flagged as high severity with the specific policy name.
The other major re-authentication driver is device state. When a CA policy requires a compliant device and a user's device isn't enrolled in Intune, they can't satisfy the grant control — so they fall back to MFA on every session instead of receiving a persistent token tied to their managed device.
M365Clarity now cross-references your Intune enrolled device count against your total licensed user count and surfaces the gap directly in the friction report.
This is the number that makes the conversation with leadership concrete. "We have a device enrolment problem" is abstract. "69% of our users are being re-prompted for MFA every time they open an app because their devices aren't managed" is actionable.
A separate but related friction signal: users who have licences for Microsoft 365 desktop apps but have never actually installed and activated them. They're working in browser-only versions of Word and Excel, which have reduced functionality and no offline access — which often drives adoption of personal alternatives.
What the data shows: M365Clarity reads Microsoft 365 app activation reports during a scan. If more than 20% of licensed users have never activated any desktop or mobile app, it flags this as a friction point: "N% of your users are restricted to browser-only access. This often drives adoption of Google Docs or other personal alternatives."
When a high proportion of licensed users have zero email send and receive activity in the last 30 days — and Exchange Online Protection policies aren't configured — the most likely explanation is over-aggressive spam filtering quarantining legitimate mail. Users experiencing this often start forwarding work email to personal Gmail accounts, creating an ungoverned copy of company data outside Microsoft 365.
The friction report now correlates these two signals and surfaces it as a specific finding rather than two separate unrelated amber tiles.
Each friction point now has four components instead of three:
What's happening — the specific configuration gap, with numbers: "22 of 24 active CA policies have no session controls configured."
📊 Quantified impact — the adoption consequence in numbers: "Users on these policies are subject to Entra's default 60-minute access token lifetime — they may be re-prompted multiple times per working day across different devices and apps."
💡 Likely workaround — what users are probably doing instead: "Users are likely staying logged into personal devices using saved passwords in browsers, bypassing MFA entirely on unmanaged endpoints."
How to fix — the specific remediation: "Configure sign-in frequency on CA policies to 8 hours or use token protection with continuous access evaluation."
The quantified friction report is particularly valuable in client conversations. When you can show a client that 22 of their 24 CA policies are misconfigured in a way that's causing their users to re-authenticate multiple times a day, and that 69% of their devices aren't managed which compounds the problem, the conversation shifts from "here's a security recommendation" to "here's why your staff keeps complaining about logging in."
The friction score and grade give you an executive summary. The friction points give you the specifics. The quantified impact gives you the numbers to make the business case for fixing it.
See your Digital Friction score
Open the Digital Friction tab in M365Clarity to see your quantified friction report.
Run a scan →Related articles