Hi @Rahat Anowar,
Thank you for posting your question in the Microsoft Q&A forum.
- Regarding Question 1 and 2: Based on what I have research currently, there is no official Microsoft article stating that MFA cannot be disabled per user or that MFA is completely mandatory for all users under an A1 subscription. What is documented is that mandatory MFA applies when accessing certain admin portals (Azure Portal, Microsoft Entra Admin Center, Intune, Microsoft 365 Admin Center). This is explained in the following article: Plan for mandatory Microsoft Entra multifactor authentication (MFA) - Microsoft Entra ID | Microsof…
- Security Defaults: Based on Microsoft’s guidance, Global Administrators should be able to disable Security Defaults if they have the appropriate admin role. There is no official article confirm that you can't disable the "Security default" feature, this is an expected behavior for A1 tenant. Reference: Configure Security Defaults for Microsoft Entra ID - Microsoft Entra | Microsoft Learn
Therefore, I strongly recommend raise a support ticket with Azure/Microsoft so they reconfirm this information, and inspect further if this is a unexpected behavior.
Thank you again for your time and understanding. While my initial response may not resolve the issue immediately, I’d like to gather more details about your situation so I can assist you more effectively.
I really appreciate your patience, and I’m here to help. Looking forward to your response!
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread