MFA REQUIRED NOTICED

Thiago Mouro de Souza 25 Reputation points
2024-08-28T13:36:20.6933333+00:00

We have an important question, we recently integrated our Identity Provider Okta with Office 365 Admin, for this we need an administrator service account within Office 365 Admin "WITHOUT MFA".

We received the October 2024 change alert from Entra, Azure Ad, and Intune Admin.

Question:

  • Will this also affect the Office 365 admin portal for service accounts without MFA for integration/automations?

From what I saw, no, but I need confirmation because if so, what will the contour be like? It would break the integration of SAML with Office 365 and consequently with Entra, which is linked to the Office groups that come from the IDP.

Office
Office
A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.
1,734 questions
0 comments No comments
{count} votes

Accepted answer
  1. Cesar Lopez 220 Reputation points
    2024-09-11T08:11:07.97+00:00

    Hi,

    Service accounts and service principals, such as the Microsoft Entra Connect Sync Account. Service accounts are non-interactive accounts that aren't tied to any particular user. They're normally used by back-end services allowing programmatic access to applications, but are also used to sign in to systems for administrative purposes. Service accounts like these should be excluded since MFA can't be completed programmatically. Calls made by service principals won't be blocked by Conditional Access policies scoped to users. Use Conditional Access for workload identities to define policies targeting service principals.

    In summary, MFA not affect service account.

    I send you the link about this info:

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-policy-all-users-mfa

    Please, if the answer is validate for you, click in correct answer


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.