Confused about MFA requirement for azure portal for my microsoft live account

BG Boyd 20 Reputation points
2024-10-11T17:48:11.08+00:00

I have security defaults enabled and created a test user in entra and he did get popped for the MFA. The user couldn't do anything, but that's besides the point.

I do not use entra (AD) users for anything. I only login to the azure portal with my microsoft live account to manage my vm (reboot, change size, look at bill, etc...) and when I login with that account I am never prompted for the MFA like my entra users.

It seems to me this really only applies to AD users I create in entra and that my Microsoft live account seems to be fine to continue to login to the azure portal. Is that right?

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
Microsoft Security | Intune | Other
{count} votes

Accepted answer
  1. Sina Salam 22,031 Reputation points Volunteer Moderator
    2024-10-11T22:06:26.94+00:00

    Hello BG Boyd,

    Welcome to the Microsoft Q&A and thank you for posting your questions here.

    I understand that you are confused about MFA requirement for azure portal for my Microsoft live account.

    You do not need to be confused, though I used Microsoft live account for the same purpose as a primary user, but I still have MFA to provide additional security for my Azure Portal and email. Therefore, Microsoft Live account uses its own separate security mechanisms, including the possibility of enabling MFA on your personal account settings, but this is managed outside of Azure AD.

    However, your assumption is correct. Security defaults in Azure AD or Microsoft Entra ID apply to Azure AD users (such as the test user you created) to enforce Multi-Factor Authentication (MFA) and other security measures. So, if you're logging in with your Microsoft Live account a personal Microsoft account, like Outlook or Hotmail), Azure AD security defaults do not directly apply to it.

    So, in your case, Azure AD users are required to use MFA, but your personal Microsoft Live account isn't subject to those specific Azure AD security defaults when accessing the Azure portal. You should be fine to continue logging in with that account without seeing an MFA prompt unless you've set up MFA separately for your Microsoft account.

    I hope this is helpful! Do not hesitate to let me know if you have any other questions.


    Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.