How to Review Microsoft 365 MFA Status and Settings
Question details
Administrators need to review Multi-Factor Authentication (MFA) settings for Microsoft 365 users and resolve issues where accounts are marked as 'Not capable'.

- Product
- Microsoft 365 / Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- An IT administrator is auditing organizational security and needs to troubleshoot user accounts, service accounts, and synced on-premises accounts that are not successfully completing MFA prompts.
- Observed behavior
- Certain accounts appear as 'Not capable' of MFA in the admin center, indicating they may lack registered authentication methods, licensing, or proper Conditional Access configurations.
Ensure you have Administrator access to the Microsoft Entra admin center and verify that your organization holds the appropriate Microsoft Entra ID Premium license to configure Conditional Access policies.
Review Authentication Methods and Resolve 'Not Capable' Status
Check user MFA registration status and enforce policies to prompt unregistered users to set up their authentication methods.
A user marked as 'Not capable' usually means they have not yet registered an authentication method (like the Microsoft Authenticator app or a phone number). Once they sign in and register a method, their status will update to 'Capable'.
Log in to the Microsoft Entra admin center using your global or authentication administrator credentials.
In the left navigation pane, go to Identity > Users > All users, and select the specific user account you want to investigate.
Click on 'Authentication methods' in the user's profile menu. Review the registered methods to confirm if the user has successfully set up MFA.
If the user is unregistered, ensure your tenant's registration campaign or Conditional Access policies are configured to prompt the user to register an MFA method during their next sign-in.

Audit Sign-in Logs and Conditional Access Policies
Investigate why specific users are not receiving MFA prompts by reviewing Azure AD sign-in logs and evaluating Conditional Access requirements.
Looking for a Lightweight Alternative to Microsoft 365?
Managing complex Microsoft 365 licenses, Entra ID configurations, and MFA administration for a large team can be overwhelming. If you simply need a robust, reliable, and hassle-free office suite for document editing, WPS Office provides everything you need without the complicated administrative overhead.

Frequently Asked Questions
What does 'Not capable' mean for MFA status in Microsoft Entra ID?
'Not capable' typically indicates that the user has not yet signed in and registered a Multi-Factor Authentication method. Once the user completes the registration process for a method like the Microsoft Authenticator app or SMS, their status automatically updates to 'Capable'.
Why are my automated service accounts failing MFA?
Service accounts are generally used by applications or background scripts that cannot interactively respond to MFA prompts. You should create specific Conditional Access exclusions for these accounts or utilize alternative secure authentication methods, such as certificate-based authentication.
Do I need a specific license to use Conditional Access for MFA?
Yes. While basic Security Defaults are available for free, configuring detailed, granular Conditional Access policies for MFA requires your organization to have an active Microsoft Entra ID Premium (P1 or P2) license.
Why do synchronized on-premises users show as 'Not capable'?
Users synchronized from an on-premises Active Directory may appear as 'Not capable' if they have not been assigned a valid Microsoft 365 license in the cloud or if they haven't completed their initial cloud sign-in to register their MFA methods.




