Mandatory MFA enforcement
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit 6d99589 · +18 −6 lines · also on GitHub
⋯ 2 unchanged lines
33
description: Plan for mandatory multifactor authentication for users who sign in to Azure and other management portals.
44
ms.service: entra-id
55
ms.subservice: authentication
6
−ms.topic: concept-article
7
−ms.date: 09/23/2025
6
+ms.topic: article
7
+ms.date: 10/14/2025
88
ms.author: justinha
99
author: justinha
1010
manager: dougeby
⋯ 219 unchanged lines
230230
231231
## FAQs
232232
233
+**Question**: Which accounts are affected by Phase 2 MFA enforcement?
234
+
235
+**Answer**: Azure Phase 2 enforcement applies to all user accounts that make Azure resource management actions through any Azure client, including PowerShell, CLI, SDKs, or even REST APIs. This enforcement is on the Azure Resource Manager server side, so any requests that target `https://management.azure.com` are under scope of enforcement. Automation accounts are not in scope as long as they use a managed identity or service principle. Any automation accounts that is set up as a user identity will be enforced upon.
236
+
237
+**Question**: How can I understand the impact of MFA enforcement without Conditional Access?
238
+
239
+**Answer**: If your Microsoft Entra ID license doesn't include Conditional Access, you can use Azure Policy to understand how MFA enforcement impacts your tenant. During system enforcement, Microsoft deploys the [Azure Policy](/azure/governance/policy/tutorials/mfa-enforcement) to your tenant. You can folow those steps to deploy the same Azure policy themselves at any time. You can deploy the policy in Audit mode, and then convert to Enforcement mode. You can choose the date to apply this policy in your tenant while you are in Enforcement mode. Then when Microsoft enforce MFA, there's no further impact to your tenant.
240
+
241
+**Question**: Are there any exceptions for specific accounts?
242
+
243
+**Answer**: The system enforcement applies to all user accounts, regardless if they are a student account, break-glass account, an administrator account with activated or eligible roles, or any [user exclusions](~/identity/conditional-access/policy-all-users-mfa-strength.md#user-exclusions) that are enabled for them. Each of these account types can perform resource management actions in Azure, posing the same security risk if they are compromised.
244
+
245
+**Question**: Are Microsoft Graph APIs under the scope for Phase 2 enforcement?
246
+
247
+**Answer**: Generally, Microsoft Graph APIs aren't in scope for Azure MFA enforcement. Only requests sent to `https://management.azure.com/` are under scope of enforcement.
248
+
233249
**Question**: If the tenant is only used for testing, is MFA required?
234250
235251
**Answer**: Yes, every Azure tenant will require MFA, with no exception for test environments.
⋯ 1 unchanged line
237253
**Question**: How does this requirement impact the Microsoft 365 admin center?
238254
239255
**Answer**: Mandatory MFA will roll out to the Microsoft 365 admin center starting in February 2025. Learn more about the mandatory MFA requirement for the Microsoft 365 admin center on the blog post [Announcing mandatory multifactor authentication for the Microsoft 365 admin center](https://techcommunity.microsoft.com/t5/microsoft-365-blog/microsoft-will-require-mfa-to-access-the-microsoft-365-admin/ba-p/4232568).
240
−
241
−**Question**: Is MFA mandatory for all users or only administrators?
242
−
243
−**Answer**: All users who sign in to any of the [applications](#application-ids-and-urls) listed previously are required to complete MFA, regardless of any administrator roles that are activated or eligible for them, or any [user exclusions](~/identity/conditional-access/policy-all-users-mfa-strength.md#user-exclusions) that are enabled for them.
244256
245257
**Question**: Do I need to complete MFA if I choose the option to **Stay signed in**?
246258
⋯ 57 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:50 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.