Cannot disable MFA on one user after migrating to Azure authentication

AndrewD84 41 Reputation points
2023-08-22T18:35:45.28+00:00

I’ve been looking into migrating away from legacy MFA and SSPR as described here: https://learn.microsoft.com/en-us/azure/active-directory/authentication/how-to-authentication-methods-manage

We are currently using legacy MFA to enable 2 factor auth on user accounts. I cannot enable Security Defaults in Azure AD to enable MFA company wide - there are a few accounts that cannot have MFA enabled as users work in a secure location w/o phone access. We also have a few service accounts that send out emails automatically and can’t have MFA requirements on those automated emails. So we manually went into legacy MFA and enabled it on each account that required it.

Looking into the migration to Azure authentication methods, I can’t find any ability to disable MFA for individual users after migrating to the new Azure authentication methods policy. Seems like on the Azure AD free license, we will be allowed to turn on Security Defaults to enable MFA company wide, or not have MFA at all.

The only means I can find to disable MFA on a few accounts after migrating to the Azure authentication methods policy is through conditional access policies, which require an Azure AD P1 license.

So my question is: After migrating to Azure authentication methods, is there any way to disable MFA on a few accounts, other than using conditional access policies? We’d like to stay on the Azure AD free license, but still have the ability to disable MFA on a few accounts.

Thanks.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,771 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,256 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 155.3K Reputation points MVP
    2023-08-22T19:08:09.29+00:00

    I havent seen anything to indicate per user MFA is going away, just the methods are being migrated:

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.