Confused about MFA requirement for azure portal for my microsoft live account

BG Boyd 20 Reputation points
2024-10-11T17:48:11.08+00:00

I have security defaults enabled and created a test user in entra and he did get popped for the MFA. The user couldn't do anything, but that's besides the point.

I do not use entra (AD) users for anything. I only login to the azure portal with my microsoft live account to manage my vm (reboot, change size, look at bill, etc...) and when I login with that account I am never prompted for the MFA like my entra users.

It seems to me this really only applies to AD users I create in entra and that my Microsoft live account seems to be fine to continue to login to the azure portal. Is that right?

Thank you.

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
7,192 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,225 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,199 questions
{count} votes

Accepted answer
  1. Sina Salam 12,166 Reputation points
    2024-10-11T22:06:26.94+00:00

    Hello BG Boyd,

    Welcome to the Microsoft Q&A and thank you for posting your questions here.

    I understand that you are confused about MFA requirement for azure portal for my Microsoft live account.

    You do not need to be confused, though I used Microsoft live account for the same purpose as a primary user, but I still have MFA to provide additional security for my Azure Portal and email. Therefore, Microsoft Live account uses its own separate security mechanisms, including the possibility of enabling MFA on your personal account settings, but this is managed outside of Azure AD.

    However, your assumption is correct. Security defaults in Azure AD or Microsoft Entra ID apply to Azure AD users (such as the test user you created) to enforce Multi-Factor Authentication (MFA) and other security measures. So, if you're logging in with your Microsoft Live account a personal Microsoft account, like Outlook or Hotmail), Azure AD security defaults do not directly apply to it.

    So, in your case, Azure AD users are required to use MFA, but your personal Microsoft Live account isn't subject to those specific Azure AD security defaults when accessing the Azure portal. You should be fine to continue logging in with that account without seeing an MFA prompt unless you've set up MFA separately for your Microsoft account.

    I hope this is helpful! Do not hesitate to let me know if you have any other questions.


    Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.