Turn off MFA for one user when Security Defaults are enabled

ARCC Admin 26 Reputation points
2021-09-23T13:30:53.123+00:00

Is it possible to Turn off MFA for one user when Security Defaults are enabled? If so, I have not found it. I already clicked on per user MFA and disabled MFA for that user, but I don't think it's working.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,472 questions
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,306 Reputation points
    2021-09-23T14:48:25.503+00:00

    Hi @ARCC Admin • Thank you for reaching out.

    Unfortunately, it is not possible to turn off MFA for specific user(s) when Security Defaults is enabled. Enabling Security Defaults in a tenant enables MFA for all users in that tenant. As it is a free offering, there is no fine grain control.

    This can be done either via Conditional Access Policy or Per user MFA, which requires assigning required licenses to all the users leveraging Azure MFA.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    3 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Andrej Pirman HM 20 Reputation points
    2023-02-18T20:51:45.9166667+00:00

    Obviously there is a glitch in O365 Admin center interface, because when Security Defaults are ENABLED, this should also ENABLE User MFA settings...but no, if you look under User MFA, they are all DISABLED.

    Also under authentication methods, MS Authenticator is shown DISABLED, but in fact it is preffered for each MFA login, which is forced.

    So I guess MS has quite a lot to do with Admin interface...

    3 people found this answer helpful.