MFA portal access with out GA role

Tayla Hentula 21 Reputation points
2021-12-06T14:14:23.507+00:00

Is there a way the Support desk employees can enable and disable MFA for users in our environment without having the Global admin role?

Licence: Azure AD free

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2021-12-06T19:44:52.44+00:00

    If you want to set up MFA for non-admin users you can use the Authentication Administrator role. If you want to configure MFA for all users, including admin users, you need at least the Privileged Authentication Administrator role. You can read more information about these roles here: https://learn.microsoft.com/azure/active-directory/users-groups-roles/directory-assign-admin-roles

    -

    If this answer helps resolve your question, please remember to Accept the answer. This will help others in the community who might be searching for the same solution.


  2. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2021-12-06T21:17:49.27+00:00

    @Tayla Hentula
    Thank you for your post!

    Adding to what @Marilee Turscak-MSFT said, you can have a Security administrator, Conditional Access administrator, or Global administrator enable Security Defaults making it easier to help protect your organization from these attacks with preconfigured security settings:

    • Requiring all users to register for Azure AD Multi-Factor Authentication.
    • Requiring administrators to do multi-factor authentication.
    • Blocking legacy authentication protocols.
    • Requiring users to do multi-factor authentication when necessary.
    • Protecting privileged activities like access to the Azure portal.

    Additional Link:
    Azure AD Security Defaults
    Conditional Access
    Building a Conditional Access policy

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.