Attached is PDF with images - my apologies for the delay
MFA has been disabled for group and Tenant however Authenticator is still needed for new users being setup
I have disabled MFA for All users, disabled system default for group and yet new users keep getting prompted to have authenticator - we do NOT want this since these are IDs shared with external users with local authentication
3 answers
Sort by: Most helpful
-
-
Raghu Janardhan 0 Reputation points
2025-03-27T14:40:13.6166667+00:00 Are there any updates here? - I have provided images on Private Message platform
-
Venkata Jagadeep 1,080 Reputation points Microsoft External Staff
2025-03-27T18:17:06.8133333+00:00 Hello Raghu Janardhan,
From 2024, Microsoft enforce mandatory MFA for all Azure sign-in attempts. For more background about this requirement, see the below link of our blog post.
The enforcement of MFA rolls out in two phases:
Phase 1: Starting in October 2024, MFA is required to sign in to the Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center. The enforcement will gradually roll out to all tenants worldwide. Starting in February 2025, MFA enforcement gradually begins for sign in to Microsoft 365 admin center. This phase won't impact other Azure clients such as Azure CLI, Azure PowerShell, Azure mobile app, or IaC tools.
Phase 2: In the summer of 2025, MFA enforcement will gradually begin for Azure CLI, Azure PowerShell, Azure mobile app, and IaC tools. Some customers may use a user account in Microsoft Entra ID as a service account. It's recommended to migrate these user-based service accounts to secure cloud based service accounts with workload identities.
Suggest you refer the below documentation. This document covers which applications and accounts are affected, how enforcement gets rolled out to tenants, and other common questions and answers.
Please let us know if you have further questions.
Thank you.