accessing more features like azure and accounts.microsoft.com.security-info, keep prompting me for a 2FA code yet i neither set nor id MFA enabled on the admin side....

Edwin Kambale 0 Reputation points
2026-06-12T06:05:31.98+00:00

been trying to explore the 365 ecosystem and there are features i can't try due to the MFA code requested on specific page visits.

MFA is disabled from the admin side but regardless i keep getting these 2FA prompts.

User's image

2

User's image

User's image

Microsoft Security | Microsoft Entra | Microsoft Entra ID

2 answers

Sort by: Most helpful
  1. Vivian-HT 17,795 Reputation points Microsoft External Staff Moderator
    2026-06-12T07:05:25.23+00:00

    Dear @Edwin Kambale

    I understand how confusing this behavior can be, especially when Multi-Factor Authentication (MFA) appears to be disabled in the admin settings, but you are still being prompted for a verification code.

    Therefore, here are some steps I recommend you check again:

    Step 1: Disable Per-User MFA:

    Go to the Microsoft 365 admin center > Navigate to Users > Active users > Select the user in question > Click on Manage multifactor authentication > Select the user again and choose Disable multi-factor authentication.

    For reference: disable the two factor authentication from single user.

    26343-1.png

    26365-2.png

    Step 2: Check Conditional Access Policies:

    Sign in to the Entra Amin Center portal > Go to Conditional Access > Review any Conditional Access policies that might be enforcing MFA for the user. Ensure that there are no policies requiring MFA for the specific user or their group.

    Or create a new policy. Assign all users under Include, and any users/groups to be exempted under Exclude > For Cloud apps, select apps to apply or exclude > Under Grant, choose Grant access and ensure Require multi-factor authentication is unchecked > Enable and save the policy. This creates a Conditional Access policy that allows selected users to bypass MFA, while others remain protected.

    For reference: Manage Conditional Access policies

    Step 3: Check Security Defaults:

    If MFA seems enabled globally even though you haven’t created any policies, Security Defaults are likely the reason. Microsoft enforces these for newer tenants to improve baseline security. Security defaults enforce MFA for all users by default. You must turn these off before customizing MFA settings:

    Sign in to the Microsoft Entra admin center > On the overview page, select the Properties tab, and the go to the Security defaults section at the bottom of the tab > Click Manage security defaults > Set to Disabled and save.

    For reference: Turn off security defaults and Manage security defaults

    For more information, please refer to this article: How to Disable Multi-Factor Authentication (MFA) in Microsoft 365?

    Disclaimer: This link is shared by community members for your convenience. It points to a third-party site that is not managed or verified by Microsoft. We can’t guarantee the quality, safety, or suitability of any content or software found there. Please review carefully and make sure you understand any potential risks before using it.

    Note: Please understand that as a forum moderator, my role is to provide general guidance and troubleshooting support. I don’t have access to internal systems or backend tools, and I appreciate your understanding of these limits.

    I hope the information shared helps point you in the right direction. Please try the steps above and let me know if they work. If not, we can continue working together to narrow this down.

    The first response may not always resolve the issue right away, but with your help and more details, we can work toward a solution.

    Thank you for your patience and understanding. I'm looking forward for your reply.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".   

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-06-12T06:05:53.2366667+00:00

    The prompts are coming from the account’s security configuration, not from per‑user MFA in the Microsoft 365 admin center. Even if MFA is disabled there, sign‑in to Azure and security‑sensitive portals can still require strong authentication because of:

    • Mandatory MFA for Azure/admin portals
    • Conditional Access or security defaults in the tenant
    • Previously registered methods that now need to be re‑registered

    To regain access and stop the loop, an administrator with sufficient rights in the tenant must reset the user’s MFA registration so that new methods can be configured.

    From the Microsoft Entra admin center:

    1. Sign in with another account that has Global Administrator (or equivalent) rights. If there is no such account and the only global admin is locked out, a support ticket with Microsoft Data Protection support is required to restore access.
    2. Go to Identity → Users → All users.
    3. Select the affected user account.
    4. Open Authentication methods.
    5. Select Require re-register MFA.
    6. Have the user sign in again; the account will be prompted to set up MFA from scratch (for example with Microsoft Authenticator, SMS, or other allowed methods).

    If this is a personal account that has been added as a guest to an Azure AD tenant, the same process must be done in that tenant: create or use another global admin account, then perform Require re-register MFA on the guest user.

    If no other global admin exists and the tenant is effectively locked out, Microsoft support (Data Protection team) must be engaged via a support ticket to reset MFA and restore access.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.