Azure Active Security Defaults

Josh R 1 Reputation point
2020-07-07T17:11:23.593+00:00

Hello!

We want to enable 2FA for our whole organization, but when we want to test it out on one person to make sure it works, Multi Factor Authentication is grayed out.

Ive been reading and it says the way to enable 2FA w/o buying the Azure license is to enable security defaults, which will turn it on for the whole organization, which I don't want to do just yet.

Now when I go into the Azure Licensed feature, I see 'Multi-Factor Authentication (phone and sms)' feature available.

Confused if its included or not...

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,120 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. neray-MSFT 26 Reputation points
    2020-07-07T18:04:04.183+00:00

    @JoshR-3829
    You can enable each user MFA individually. The licensing of per user MFA is entitled here.

    When users are enabled individually, they perform multi-factor authentication each time they sign in (with some exceptions, such as when they sign in from trusted IP addresses or when the remembered devices feature is turned on).<br />By default, all users are set out as Disabled. When you enroll users in Azure Multi-Factor Authentication, their state changes to Enabled. When enabled users sign in and complete the registration process, their state changes to Enforced.

    You can follow the steps detailed in this document for enabling MFA per user basis. - https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates#change-the-status-for-a-user

    Do let us know if this helps and if there are any more queries around this, please do let us know so that we can help you further. Also, please do not forget to accept the response as Answer; if the above response helped in answering your query.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.