A cloud-based identity and access management service for securing user authentication and resource access
If a user is still marked as Enabled in the old portal, it can still force MFA unexpectedly, cause inconsistent sign-in behavior, block some legacy clients, and make troubleshooting harder because it overrides what CA policies indicate should happen.
The recommended action is to disable per-user MFA for all remaining users. Doing so does not remove MFA if you are enforcing it through Conditional Access - it only removes the legacy enforcement layer. You can disable these users directly in the old MFA portal or by clearing their StrongAuthenticationRequirements via PowerShell. This leaves MFA fully controlled by your modern Entra ID policies and avoids conflicts.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin