MFA for Azure Portal Login, but NOT for Office 365 Login

Shaun Wilkinson 0 Reputation points
2024-08-19T00:18:33.81+00:00

MS are implementing mandatory MFA login for their Entra and Azure Admin Portals. This makes sense.

Can someone tell me how I enable the MFA access for the Azure and other Admin portals BUT decline to enable it for Office 365 applications.

There should be an option that allows for the selection of which apps require MFA and which do not.

Can someone point me towards where they may be done.

Thanks in advance

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,587 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Navya 10,375 Reputation points Microsoft Vendor
    2024-08-20T03:33:05.4266667+00:00

    Hi @Shaun Wilkinson

    Thank you for posting this in Microsoft Q&A.

    I understand that you are looking for a way to configure Multi factor authentication (MFA) for Azure Portal Login, but NOT for Office 365 Login.

    To set this up, you'll need to create a conditional access policy that targets the Azure and Admin portals, and then exclude the Office 365 applications from the policy. Here's a step-by-step guide to help you achieve this:

    1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
    2. Browse to Protection > Conditional Access > Policies.
    3. Select New policy.
    4. Give the policy a name, such as "MFA for Azure and Admin Portals".
    5. Under Assignments, select Users or workload identities you want to apply the policy to.
    6. Under Target resources > Cloud apps > Include, select apps >select Microsoft Admin Portals it includes Microsoft 365 admin center, Exchange admin center, Azure portal, Microsoft Entra admin center, and others.
    7. Under Access controls > Grant, select Grant access, require multifactor authentication, and select.
    8. Confirm your settings and set Enable policy to On.
    9. Select Create to create to enable your policy. For your reference: Conditional Access: Target resources

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.

    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.