Mandatory MFA enforcement
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit cc0ee77 · +2 −2 lines · also on GitHub
⋯ 2 unchanged lines
33
description: Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.
44
ms.topic: concept-article
55
ms.date: 04/03/2026
6
−ms.reviewer: shahjoy
6
+ms.reviewer: shahjoy, nehakulkarni
77
ms.custom: sfi-ga-nochange, msecd-doc-authoring-106
88
# Customer intent: As an identity administrator, I want to plan for mandatory MFA for users who sign in to Azure portal so that my organization is prepared before enforcement begins.
99
---
⋯ 175 unchanged lines
185185
186186
Conditional Access requires a Microsoft Entra ID P1 or P2 license. If you can't use Conditional Access, enable [security defaults](~/fundamentals/security-defaults.md).
187187
188
−You can self-enforce MFA by using built-in definitions in Azure Policy. To learn more and follow a step-by-step overview to apply these policy assignments in your environment, see [Tutorial: Apply MFA self-enforcement through Azure Policy](/azure/governance/policy/tutorials/mfa-enforcement).
188
+You can self-enforce MFA by using built-in definitions in Azure Policy. To learn more and follow a step-by-step overview to apply these policy assignments in your environment, see [Tutorial: Apply MFA self-enforcement through Azure Policy](/azure/governance/policy/tutorials/mfa-enforcement). Azure Policy supports both the `Audit` effect (which reports noncompliance in policy compliance results) and the `Deny` effect, which blocks noncompliant requests.
189189
190190
For the best compatibility experience, ensure users in your tenant are using Azure CLI version 2.76 and Azure PowerShell version 14.3 or later. Otherwise, you can expect to see error messages as explained in these topics:
191191
⋯ 134 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy today 21:50 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.