ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 13:50 UTC Customize Public modeDiscuss ChangeIntel on Discord

Microsoft's edit ·

Merge pull request #9723 from Justinha/mfa-tenant-update

Microsoft's commit message in MicrosoftDocs/entra-docs · commit 6d99589 · +18 −6 lines · also on GitHub

⋯ 2 unchanged lines
33 description: Plan for mandatory multifactor authentication for users who sign in to Azure and other management portals.
44 ms.service: entra-id
55 ms.subservice: authentication
6 −ms.topic: concept-article
7 −ms.date: 09/23/2025
6 +ms.topic: article
7 +ms.date: 10/14/2025
88 ms.author: justinha
99 author: justinha
1010 manager: dougeby
⋯ 219 unchanged lines
230230
231231 ## FAQs
232232
233 +**Question**: Which accounts are affected by Phase 2 MFA enforcement?
234 +
235 +**Answer**: Azure Phase 2 enforcement applies to all user accounts that make Azure resource management actions through any Azure client, including PowerShell, CLI, SDKs, or even REST APIs. This enforcement is on the Azure Resource Manager server side, so any requests that target `https://management.azure.com` are under scope of enforcement. Automation accounts are not in scope as long as they use a managed identity or service principle. Any automation accounts that is set up as a user identity will be enforced upon.
236 +
237 +**Question**: How can I understand the impact of MFA enforcement without Conditional Access?
238 +
239 +**Answer**: If your Microsoft Entra ID license doesn't include Conditional Access, you can use Azure Policy to understand how MFA enforcement impacts your tenant. During system enforcement, Microsoft deploys the [Azure Policy](/azure/governance/policy/tutorials/mfa-enforcement) to your tenant. You can folow those steps to deploy the same Azure policy themselves at any time. You can deploy the policy in Audit mode, and then convert to Enforcement mode. You can choose the date to apply this policy in your tenant while you are in Enforcement mode. Then when Microsoft enforce MFA, there's no further impact to your tenant.
240 +
241 +**Question**: Are there any exceptions for specific accounts?
242 +
243 +**Answer**: The system enforcement applies to all user accounts, regardless if they are a student account, break-glass account, an administrator account with activated or eligible roles, or any [user exclusions](~/identity/conditional-access/policy-all-users-mfa-strength.md#user-exclusions) that are enabled for them. Each of these account types can perform resource management actions in Azure, posing the same security risk if they are compromised.
244 +
245 +**Question**: Are Microsoft Graph APIs under the scope for Phase 2 enforcement?
246 +
247 +**Answer**: Generally, Microsoft Graph APIs aren't in scope for Azure MFA enforcement. Only requests sent to `https://management.azure.com/` are under scope of enforcement.
248 +
233249 **Question**: If the tenant is only used for testing, is MFA required?
234250
235251 **Answer**: Yes, every Azure tenant will require MFA, with no exception for test environments.
⋯ 1 unchanged line
237253 **Question**: How does this requirement impact the Microsoft 365 admin center?
238254
239255 **Answer**: Mandatory MFA will roll out to the Microsoft 365 admin center starting in February 2025. Learn more about the mandatory MFA requirement for the Microsoft 365 admin center on the blog post [Announcing mandatory multifactor authentication for the Microsoft 365 admin center](https://techcommunity.microsoft.com/t5/microsoft-365-blog/microsoft-will-require-mfa-to-access-the-microsoft-365-admin/ba-p/4232568).
240 −
241 −**Question**: Is MFA mandatory for all users or only administrators?
242 −
243 −**Answer**: All users who sign in to any of the [applications](#application-ids-and-urls) listed previously are required to complete MFA, regardless of any administrator roles that are activated or eligible for them, or any [user exclusions](~/identity/conditional-access/policy-all-users-mfa-strength.md#user-exclusions) that are enabled for them.
244256
245257 **Question**: Do I need to complete MFA if I choose the option to **Stay signed in**?
246258
⋯ 57 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:50 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 13:50 UTC · 252 of 253 readable · documentation 391/391 current