Mandatory MFA enforcement
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit 9871790 · +12 −13 lines · also on GitHub
11
---
22
title: Plan for mandatory Microsoft Entra multifactor authentication (MFA)
3
−description: Plan for mandatory multifactor authentication for users who sign in to Azure and other management portals.
3
+description: Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.
44
ms.topic: concept-article
55
ms.date: 01/28/2026
66
ms.reviewer: shahjoy
7
−ms.custom: sfi-ga-nochange
8
−# Customer intent: As an identity administrator, I want to plan for mandatory MFA for users who sign in to Azure portal.
7
+ms.custom: sfi-ga-nochange, msecd-doc-authoring-106
8
+# Customer intent: As an identity administrator, I want to plan for mandatory MFA for users who sign in to Azure portal so that my organization is prepared before enforcement begins.
99
---
10
−# Planning for mandatory multifactor authentication for Azure and other admin portals
10
+# Mandatory multifactor authentication for Azure and admin portals
1111
1212
At Microsoft, we're committed to providing our customers with the highest level of security. One of the most effective security measures available to them is multifactor authentication (MFA). [Research by Microsoft](https://www.microsoft.com/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks) shows that MFA can block more than 99.2% of account compromise attacks.
1313
⋯ 3 unchanged lines
1717
1818
## Scope of enforcement
1919
20
−The scope of enforcement includes when enforcement is planned to occur, which applications plan to enforce MFA, applications that are out of scope, and which accounts have a mandatory MFA requirement.
20
+The scope of enforcement covers enforcement timing, affected applications, and account requirements.
2121
2222
### Enforcement phases
2323
⋯ 168 unchanged lines
192192
- [Troubleshoot MFA errors in Azure PowerShell](/powershell/azure/troubleshooting#troubleshooting-multifactor-authentication-mfa)
193193
- [Troubleshoot MFA errors in Azure CLI](/cli/azure/use-azure-cli-successfully-troubleshooting#troubleshooting-multifactor-authentication-mfa)
194194
195
−>[!NOTE]
196
−>Users who sign in without MFA can use a [Phase 2 application](#phase-2-applications). But if they try to create, update, or delete a resource, the app returns an error that says they need to sign in with MFA and a claims challenge. Some clients use the claims challenge to prompt the user to step up and perform MFA. Other clients return only the error without an MFA prompt. A Conditional Access policy or security defaults are recommended to help users satisfy MFA before they see an error.
195
+> [!NOTE]
196
+> Users who sign in without MFA can use a [Phase 2 application](#phase-2-applications). But if they try to create, update, or delete a resource, the app returns an error that says they need to sign in with MFA and a claims challenge. Some clients use the claims challenge to prompt the user to step up and perform MFA. Other clients return only the error without an MFA prompt. A Conditional Access policy or security defaults are recommended to help users satisfy MFA before they see an error.
197197
198198
## Request more time to prepare for Phase 1 MFA enforcement
199199
⋯ 1 unchanged line
201201
202202
For each tenant where they want to postpone the start date of enforcement, a Global Administrator can go to the [https://aka.ms/managemfaforazure](https://aka.ms/managemfaforazure) to select a start date.
203203
204
−>[!Caution]
204
+> [!CAUTION]
205205
>
206206
>By postponing the start date of enforcement, you take extra risk because accounts that access Microsoft services like the Azure portal are highly valuable targets for threat actors. We recommend all tenants set up MFA now to secure cloud resources.
207207
208208
## Request more time to prepare for Phase 2 MFA enforcement
209209
210
−Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 2 for their tenants until July 1st, 2026. You can request more time to prepare for Phase 2 MFA enforcement at [https://aka.ms/postponePhase2MFA](https://aka.ms/postponePhase2MFA). Choose another start date, and click **Apply**. After Phase 2 enforcement begins, you can submit a request to Microsoft Help and Support to temporarily lift enforcement. The request must be done by a Global Administrator due to the security implications.
210
+Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 2 for their tenants until July 1st, 2026. You can request more time to prepare for Phase 2 MFA enforcement at [https://aka.ms/postponePhase2MFA](https://aka.ms/postponePhase2MFA). Choose another start date, and select **Apply**. After Phase 2 enforcement begins, you can submit a request to Microsoft Help and Support to temporarily lift enforcement. The request must be done by a Global Administrator due to the security implications.
211211
212
−>[!NOTE]
212
+> [!NOTE]
213213
> If you postponed the start of Phase 1, the start of Phase 2 is also postponed to the same date. You can choose a later start date for Phase 2.
214214
215
−:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/postpone-phase-two.png" alt-text="Screenshot of how to postpone mandatory MFA for phase two."
215
+:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/postpone-phase-two.png" alt-text="Screenshot of how to postpone mandatory MFA for phase two.":::
216216
217217
218218
## Confirm mandatory MFA enforcement
⋯ 48 unchanged lines
267267
268268
**Question**: How can we comply if we enforce MFA by using another identity provider or MFA solution, and we don't enforce by using Microsoft Entra MFA?
269269
270
−**Answer**: Third-party MFA can be integrated directly with Microsoft Entra ID. For more information, see [Microsoft Entra multifactor authentication external method provider reference](concept-authentication-external-method-provider.md). Microsoft Entra ID can be optionally configured with a federated identity provider. If so, the identity provider solution needs to be configured properly to send the multipleauthn claim to Microsoft Entra ID. For more information, see [Satisfy Microsoft Entra ID multifactor authentication (MFA) controls with MFA claims from a federated IdP](how-to-mfa-expected-inbound-assertions.md).
270
+**Answer**: Third-party MFA can be integrated directly with Microsoft Entra ID. For more information, see [Microsoft Entra multifactor authentication external method provider reference](concept-authentication-external-method-provider.md). Microsoft Entra ID can be optionally configured with a federated identity provider. If so, the identity provider solution needs to be configured properly to send the `multipleauthn` claim to Microsoft Entra ID. For more information, see [Satisfy Microsoft Entra ID multifactor authentication (MFA) controls with MFA claims from a federated IdP](how-to-mfa-expected-inbound-assertions.md).
271271
272272
**Question**: Will mandatory MFA impact my ability to sync with Microsoft Entra Connect or Microsoft Entra Cloud Sync?
273273
⋯ 33 unchanged lines
307307
- [How to postpone enforcement for a tenant where users are unable to sign](how-to-unlock-users-for-mandatory-multifactor-authentication.md)
308308
- [How to verify that users are set up for mandatory MFA](how-to-mandatory-multifactor-authentication.md)
309309
- [Tutorial: Secure user sign-in events with Microsoft Entra multifactor authentication](~/identity/authentication/tutorial-enable-azure-mfa.md)
310
−- [Secure sign-in events with Microsoft Entra multifactor](~/identity/authentication/tutorial-enable-azure-mfa.md)
311310
- [Plan a Microsoft Entra multifactor authentication deployment](~/identity/authentication/howto-mfa-getstarted.md)
312311
- [Phishing-resistant MFA methods](~/identity/authentication/phishing-resistant-authentication-videos.md)
313312
- [Microsoft Entra multifactor authentication](~/identity/authentication/concept-mfa-howitworks.md)
⋯ 1 unchanged line
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:50 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.