MFA has been disabled for group and Tenant however Authenticator is still needed for new users being setup

Raghu Janardhan 0 Reputation points
2025-03-20T20:44:05.17+00:00

I have disabled MFA for All users, disabled system default for group and yet new users keep getting prompted to have authenticator - we do NOT want this since these are IDs shared with external users with local authentication

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,238 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Raghu Janardhan 0 Reputation points
    2025-03-24T14:38:02.61+00:00

    Attached is PDF with images - my apologies for the delay

    0 comments No comments

  2. Raghu Janardhan 0 Reputation points
    2025-03-27T14:40:13.6166667+00:00

    Are there any updates here? - I have provided images on Private Message platform

    0 comments No comments

  3. Venkata Jagadeep 1,080 Reputation points Microsoft External Staff
    2025-03-27T18:17:06.8133333+00:00

    Hello Raghu Janardhan,

    From 2024, Microsoft enforce mandatory MFA for all Azure sign-in attempts. For more background about this requirement, see the below link of our blog post.

    https://azure.microsoft.com/en-us/blog/announcing-mandatory-multi-factor-authentication-for-azure-sign-in/

    The enforcement of MFA rolls out in two phases:

    Phase 1: Starting in October 2024, MFA is required to sign in to the Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center. The enforcement will gradually roll out to all tenants worldwide. Starting in February 2025, MFA enforcement gradually begins for sign in to Microsoft 365 admin center. This phase won't impact other Azure clients such as Azure CLI, Azure PowerShell, Azure mobile app, or IaC tools.

    Phase 2: In the summer of 2025, MFA enforcement will gradually begin for Azure CLI, Azure PowerShell, Azure mobile app, and IaC tools. Some customers may use a user account in Microsoft Entra ID as a service account. It's recommended to migrate these user-based service accounts to secure cloud based service accounts with workload identities.

    Suggest you refer the below documentation. This document covers which applications and accounts are affected, how enforcement gets rolled out to tenants, and other common questions and answers.

    https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication?tabs=dotnet

    Please let us know if you have further questions.

    Thank you.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.