Mandatory MFA enforcement
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit 45751de · +5 −5 lines · also on GitHub
⋯ 2 unchanged lines
33
description: Plan for mandatory multifactor authentication for users who sign in to Azure and other management portals.
44
ms.service: entra-id
55
ms.subservice: authentication
6
−ms.topic: concept-article
7
−ms.date: 01/27/2026
6
+ms.topic: article
7
+ms.date: 01/28/2026
88
ms.author: justinha
99
author: justinha
1010
manager: dougeby
⋯ 201 unchanged lines
212212
213213
## Request more time to prepare for Phase 2 MFA enforcement
214214
215
−Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 2 for their tenants until July 1st, 2026. You can request more time to prepare for Phase 2 MFA enforcement at [https://aka.ms/postponePhase2MFA](https://aka.ms/postponePhase2MFA). Choose another start date, and click **Apply**. After Phase 2 enforcement begins, your tenant admin must submit a request to Microsoft Help and Support to temporarily lift enforcement due to the security implications.
215
+Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 2 for their tenants until July 1st, 2026. You can request more time to prepare for Phase 2 MFA enforcement at [https://aka.ms/postponePhase2MFA](https://aka.ms/postponePhase2MFA). Choose another start date, and click **Apply**. After Phase 2 enforcement begins, you can submit a request to Microsoft Help and Support to temporarily lift enforcement. The request must be done by a Global Administrator due to the security implications.
216216
217217
>[!NOTE]
218218
> If you postponed the start of Phase 1, the start of Phase 2 is also postponed to the same date. You can choose a later start date for Phase 2.
⋯ 13 unchanged lines
232232
233233
**Question**: Which accounts are affected by Phase 2 MFA enforcement?
234234
235
−**Answer**: Azure Phase 2 enforcement applies to all user accounts that make Azure resource management actions through any Azure client, including PowerShell, CLI, SDKs, or even REST APIs. This enforcement is on the Azure Resource Manager server side, so any requests that target `https://management.azure.com` are under scope of enforcement. Automation accounts are not in scope as long as they use a managed identity or service principle. Any automation accounts that is set up as a user identity will be enforced upon.
235
+**Answer**: Azure Phase 2 enforcement applies to all user accounts that make Azure resource management actions through any Azure client, including PowerShell, CLI, SDKs, or even REST APIs. This enforcement is on the Azure Resource Manager server side, so any requests that target `https://management.azure.com` are under scope of enforcement. Automation accounts are not in scope as long as they use a managed identity or service principal. Any automation accounts that are set up as user identities will be enforced upon.
236236
237237
**Question**: How can I understand the impact of MFA enforcement without Conditional Access?
238238
239
−**Answer**: If your Microsoft Entra ID license doesn't include Conditional Access, you can use Azure Policy to understand how MFA enforcement impacts your tenant. During system enforcement, Microsoft deploys the [Azure Policy](/azure/governance/policy/tutorials/mfa-enforcement) to your tenant. You can folow those steps to deploy the same Azure policy themselves at any time. You can deploy the policy in Audit mode, and then convert to Enforcement mode. You can choose the date to apply this policy in your tenant while you are in Enforcement mode. Then when Microsoft enforce MFA, there's no further impact to your tenant.
239
+**Answer**: If your Microsoft Entra ID license doesn't include Conditional Access, you can use Azure Policy to understand how MFA enforcement impacts your tenant. During system enforcement, Microsoft deploys the [Azure Policy](/azure/governance/policy/tutorials/mfa-enforcement) to your tenant. You can follow those steps to deploy the same Azure policy yourself at any time. You can deploy the policy in Audit mode, and then convert to Enforcement mode. You can choose the date to apply this policy in your tenant while you are in Enforcement mode. Then when Microsoft enforces MFA, there's no further impact to your tenant.
240240
241241
**Question**: Are there any exceptions for specific accounts?
242242
⋯ 73 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:50 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.