Accounts not capable of MFA

Rizwan Assad 341 Reputation points
2022-10-06T08:11:55.763+00:00

What is the best way to deal with accounts not capable of MFA? is there a way from backend that an administrator can use to enable MFA on stale accounts? for e.g., a sharedmailbox has an identity as well which can be enforced for MFA but still, how to make it capable of MFA without having to login to portal using that account?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Harpreet Singh Matharoo 8,396 Reputation points Microsoft Employee Moderator
    2022-10-06T11:28:52.377+00:00

    Hello @Rizwan Assad

    I would like to confirm that you can as an Admin you can publish Authentication method like mobile/phone number using Azure Portal. Publishing these values would make the account MFA capable and prompt user for MFA using contact number specified if enforced by Per-User MFA or Conditional Access. For more details about the steps, you can follow the steps as listed on following document: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-sspr-authenticationdata.

    You can use following screenshot for reference:
    248029-image.png

    I hope this helps. If there are any further question, please feel to add a comment above.

    ----------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.