Microsoft Entra ID
Authentication

Mandatory multifactor authentication for Azure and admin portals

In brief

The article was edited for spelling, headings, and presentation while retaining its documented enforcement phases, dates, affected applications, account scope, and break-glass guidance.

What Entra admins need to know

Administrators can use the revised article as a clearer reference for MFA enforcement planning. No action is specified.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


Mandatory multifactor authentication for Azure and admin portals

At Microsoft, we're committed to providing our customers with the highest level of security. One of the most effective security measures available to them is multifactor authentication (MFA). Research by Microsoft shows that MFA can block more than 99.2% of account compromise attacks.

That's why, starting in 2024, we'll enforce mandatory MFA for all Azure sign-in attempts. For more background about this requirement, see our blog posts Azure mandatory multifactor authentication: Phase 2 starting in October 2025 and Announcing mandatory multifactor authentication for Azure sign-in. This topic covers which applications and accounts are affected, how enforcement gets rolled out to tenants, and other common questions and answers.

There's no change for users if your organization already enforces MFA for them, or if they sign in with stronger methods like passwordless or passkey (FIDO2). To verify that MFA is enabled, see How to verify that users are set up for mandatory MFA.

Scope of enforcement

The scope of enforcement covers enforcement timing, affected applications, and account requirements.

Enforcement phases

The enforcement of MFA for applications rolls out in two phases.

Phase 1 applications

Starting in October 2024, MFA is required for accounts that sign in to the Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center to perform any Create, Read, Update, or Delete (CRUD) operation. The enforcement will gradually roll out to all tenants worldwide. Starting in February 2025, MFA enforcement gradually begins for sign in to Microsoft 365 admin center. Phase 1 won't impact other Azure clients such as Azure CLI, Azure PowerShell, Azure mobile app, or IaC tools.

Phase 2 applications

Starting October 1, 2025, MFA enforcement will gradually begin for accounts that sign in to Azure CLI, Azure PowerShell, Azure mobile app, IaC tools, and REST API endpoints to perform any Create, Update, or Delete operation. Read operations won't require MFA.

Some customers may use a user account in Microsoft Entra ID as a service account. It's recommended to migrate these user-based service accounts to secure cloud-based service accounts with workload identities.

Application IDs and URLs

The following table lists affected apps, app IDs, and URLs for Azure.

Application Name App ID Enforcement starts
Azure command-line interface (Azure CLI) 04b07795-8ddb-461a-bbee-02f9e1bf7b46 October 1, 2025
Azure PowerShell 1950a258-227b-4e31-a9cf-717495945fc2 October 1, 2025
Azure mobile app 0c1307d4-29d6-4389-a11c-5cbe7f65d7fa October 1, 2025
Infrastructure as Code (IaC) tools Use Azure CLI or Azure PowerShell IDs October 1, 2025
REST API (Control Plane) N/A October 1, 2025
Azure SDK N/A October 1, 2025

The following table lists affected apps and URLs for Microsoft 365.

Application Name URL Enforcement starts
Microsoft 365 admin center https://admin.cloud.microsoft February 2025
Microsoft 365 admin center https://admin.microsoft.com February 2025

Accounts

All accounts that sign in to perform operations cited in the applications section must complete MFA when the enforcement begins. Users aren't required to use MFA if they access other applications, websites, or services hosted on Azure. Each application, website, or service owner listed earlier controls the authentication requirements for users.

Break glass or emergency access accounts are also required to sign in with MFA once enforcement begins. We recommend that you update these accounts to use passkey (FIDO2) or configure certificate-based authentication for MFA. Both methods satisfy the MFA requirement.

Workload identities, such as managed identities and service principals, aren't impacted by either phase of this MFA enforcement. If user identities are used to sign in as a service account to run automation (including scripts or other automated tasks), those user identities need to sign in with MFA once enforcement begins. User identities aren't recommended for automation. You should migrate those user identities to workload identities.

Migrate user-based service accounts to workload identities

We recommend that customers discover user accounts that are used as service accounts and begin to migrate them to workload identities. Migration often requires updating scripts and automation processes to use workload identities.

Review How to verify that users are set up for mandatory MFA to identify all user accounts, including user accounts being used as service accounts, that sign in to the applications.

For more information about how to migrate from user-based service accounts to workload identities for authentication with these applications, see:

Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a workload identities license to apply Conditional Access for workload identities.

Migrate federated Identity Provider to external MFA

Support for external MFA solutions is available with external MFA, and can be used to meet the MFA requirement. The legacy Conditional Access custom controls preview doesn't satisfy the MFA requirement. You should migrate to external MFA to use an external solution with Microsoft Entra ID.

Prepare for mandatory MFA enforcement

To prepare for MFA enforcement, configure a Conditional Access policy that requires users to sign in with MFA. If you configured exceptions or exclusions in the policy, they no longer apply. If you have more restrictive Conditional Access policies that target Azure and require stronger authentication, such as phishing-resistant MFA, they remain enforced.

Conditional Access requires a Microsoft Entra ID P1 or P2 license. If you can't use Conditional Access, enable security defaults.

You can self-enforce MFA by using built-in definitions in Azure Policy. To learn more and follow a step-by-step overview to apply these policy assignments in your environment, see Tutorial: Apply MFA self-enforcement through Azure Policy. Azure Policy supports both the Audit effect (which reports noncompliance in policy compliance results) and the Deny effect, which blocks noncompliant requests.

For the best compatibility experience, ensure users in your tenant are using Azure CLI version 2.76 and Azure PowerShell version 14.3 or later. Otherwise, you can expect to see error messages as explained in these topics:

Request more time to prepare for Phase 1 MFA enforcement

We understand that some customers may need more time to prepare for this MFA requirement. Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 1 for their tenants until September 30, 2025.

For each tenant where they want to postpone the start date of enforcement, a Global Administrator can go to the https://aka.ms/managemfaforazure to select a start date.

Request more time to prepare for Phase 2 MFA enforcement

Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 2 for their tenants until July 1st, 2026. You can request more time to prepare for Phase 2 MFA enforcement at https://aka.ms/postponePhase2MFA. Choose another start date, and select Apply. After Phase 2 enforcement begins, you can submit a request to Microsoft Help and Support to temporarily lift enforcement. The request must be done by a Global Administrator due to the security implications.

:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/postpone-phase-two.png" alt-text="Screenshot of how to postpone mandatory MFA for phase two.":::

FAQs

Question: Which accounts are affected by Phase 2 MFA enforcement?

Answer: Azure Phase 2 enforcement applies to all user accounts that make Azure resource management actions through any Azure client, including PowerShell, CLI, SDKs, or even REST APIs. This enforcement is on the Azure Resource Manager server side, so any requests that target https://management.azure.com are under scope of enforcement. Automation accounts are not in scope as long as they use a managed identity or service principal. Any automation accounts that are set up as user identities will be enforced upon.

Question: How can I understand the impact of MFA enforcement without Conditional Access?

Answer: If your Microsoft Entra ID license doesn't include Conditional Access, you can use Azure Policy to understand how MFA enforcement impacts your tenant. During system enforcement, Microsoft deploys the Azure Policy to your tenant. You can follow those steps to deploy the same Azure policy yourself at any time. You can deploy the policy in Audit mode, and then convert to Enforcement mode. You can choose the date to apply this policy in your tenant while you are in Enforcement mode. Then when Microsoft enforces MFA, there's no further impact to your tenant.

Question: Are there any exceptions for specific accounts?

Answer: The system enforcement applies to all user accounts, regardless if they are a student account, break-glass account, an administrator account with activated or eligible roles, or any user exclusions that are enabled for them. Each of these account types can perform resource management actions in Azure, posing the same security risk if they are compromised.

Question: Are Microsoft Graph APIs under the scope for Phase 2 enforcement?

Answer: Generally, Microsoft Graph APIs aren't in scope for Azure MFA enforcement. Only requests sent to https://management.azure.com/ are under scope of enforcement.

Question: If the tenant is only used for testing, is MFA required?

Answer: Yes, every Azure tenant will require MFA, with no exception for test environments.

Question: How does this requirement impact the Microsoft 365 admin center?

Answer: Mandatory MFA will roll out to the Microsoft 365 admin center starting in February 2025. Learn more about the mandatory MFA requirement for the Microsoft 365 admin center on the blog post Announcing mandatory multifactor authentication for the Microsoft 365 admin center.

Question: Do I need to complete MFA if I choose the option to Stay signed in?

Question: Does the enforcement apply to B2B guest accounts?

Answer: Yes, MFA has to be adhered to either from the partner resource tenant, or the user's home tenant if it's set up properly to send MFA claims to the resource tenant by using cross-tenant access.

Question: Does the enforcement apply to Azure for US Government or Azure sovereign clouds?

Answer: Microsoft enforces mandatory MFA only in the public Azure cloud. Microsoft doesn't currently enforce MFA in Azure for US Government or other Azure sovereign clouds.

Question: How can we comply if we enforce MFA by using another identity provider or MFA solution, and we don't enforce by using Microsoft Entra MFA?

Answer: Third-party MFA can be integrated directly with Microsoft Entra ID. For more information, see Microsoft Entra multifactor authentication external method provider reference. Microsoft Entra ID can be optionally configured with a federated identity provider. If so, the identity provider solution needs to be configured properly to send the multipleauthn claim to Microsoft Entra ID. For more information, see Satisfy Microsoft Entra ID multifactor authentication (MFA) controls with MFA claims from a federated IdP.

Question: Will mandatory MFA impact my ability to sync with Microsoft Entra Connect or Microsoft Entra Cloud Sync?

Answer: No. The synchronization service account isn't affected by the mandatory MFA requirement. Only applications listed earlier require MFA for sign in.

Question: Will I be able to opt out?

Answer: There's no way to opt out. This security motion is critical to the safety and security of the Azure platform and is being repeated across cloud vendors. For example, see Secure by Design: AWS to enhance MFA requirements in 2024.

An option to postpone the enforcement start date is available for customers. Global Administrators can go to the Azure portal to postpone the start date of enforcement for their tenant. Global Administrators must have elevated access before they postpone the start date of MFA enforcement on this page. They must perform this action for each tenant that needs postponement.

Question: Can I test MFA before Azure enforces the policy to ensure nothing breaks?

Answer: Yes, you can test your MFA through the manual setup process for MFA. We encourage you to set this up and test. If you use Conditional Access to enforce MFA, you can use Conditional Access templates to test your policy. For more information, see Require multifactor authentication for admins accessing Microsoft admin portals. If you run a free edition of Microsoft Entra ID, you can enable security defaults.

Question: What if I already have MFA enabled, what happens next?

Answer: Customers that already require MFA for their users who access the applications listed earlier don't see any change. If you only require MFA for a subset of users, then any users not already using MFA will now need to use MFA when they sign in to the applications.

Question: How can I review MFA activity in Microsoft Entra ID?

Answer: To review details about when a user is prompted to sign in with MFA, use the Microsoft Entra sign-in logs. For more information, see Sign-in event details for Microsoft Entra multifactor authentication.

Question: What if I have a "break glass" scenario?

Answer: We recommend updating these accounts to use passkey (FIDO2) or configure certificate-based authentication for MFA. Both methods satisfy the MFA requirement.

Question: What if I don't receiveanreceive an email about enabling MFA before it was enforced, and then I get locked-out. How should I resolve it?

Answer: Users shouldn't be locked out, but they may get a message that prompts them to enable MFA once enforcement for their tenant has started. If the user is locked out, there may be other issues. For more information, see Account has been locked.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…