Microsoft Entra ID

Customer intent: As an identity administrator, I want to plan for mandatory MFA for users who sign in to Azure portal so that my organization is prep…

In brief

Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.

Documentation change

Conditional Access requires a Microsoft Entra ID P1 or P2 license. If you can't use Conditional Access, enable security defaults.

You can self-enforce MFA by using built-in definitions in Azure Policy. To learn more and follow a step-by-step overview to apply these policy assignments in your environment, see Tutorial: Apply MFA self-enforcement through Azure Policy.

You can self-enforce MFA by using built-in definitions in Azure Policy. To learn more and follow a step-by-step overview to apply these policy assignments in your environment, see Tutorial: Apply MFA self-enforcement through Azure Policy. Azure Policy supports both the Audit effect (which reports noncompliance in policy compliance results) and the Deny effect, which blocks noncompliant requests.

For the best compatibility experience, ensure users in your tenant are using Azure CLI version 2.76 and Azure PowerShell version 14.3 or later. Otherwise, you can expect to see error messages as explained in these topics: