logo
search
MFA & Verification Issues

How to Review Microsoft 365 MFA Status and Settings

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 869 views

Question details

Administrators need to review Multi-Factor Authentication (MFA) settings for Microsoft 365 users and resolve issues where accounts are marked as 'Not capable'.

How to Review Microsoft 365 MFA Status and Settings
Product
Microsoft 365 / Microsoft Entra ID
Device & OS
not provided
Scenario
An IT administrator is auditing organizational security and needs to troubleshoot user accounts, service accounts, and synced on-premises accounts that are not successfully completing MFA prompts.
Observed behavior
Certain accounts appear as 'Not capable' of MFA in the admin center, indicating they may lack registered authentication methods, licensing, or proper Conditional Access configurations.
Before you start

Ensure you have Administrator access to the Microsoft Entra admin center and verify that your organization holds the appropriate Microsoft Entra ID Premium license to configure Conditional Access policies.

Solution 1Recommended

Review Authentication Methods and Resolve 'Not Capable' Status

Check user MFA registration status and enforce policies to prompt unregistered users to set up their authentication methods.

A user marked as 'Not capable' usually means they have not yet registered an authentication method (like the Microsoft Authenticator app or a phone number). Once they sign in and register a method, their status will update to 'Capable'.

1
Access Microsoft Entra admin center

Log in to the Microsoft Entra admin center using your global or authentication administrator credentials.

2
Navigate to user profiles

In the left navigation pane, go to Identity > Users > All users, and select the specific user account you want to investigate.

3
Check Authentication methods

Click on 'Authentication methods' in the user's profile menu. Review the registered methods to confirm if the user has successfully set up MFA.

4
Prompt MFA registration

If the user is unregistered, ensure your tenant's registration campaign or Conditional Access policies are configured to prompt the user to register an MFA method during their next sign-in.

Review Authentication Methods and Resolve 'Not Capable' Status
Handling Service Accounts: Service accounts generally cannot complete MFA programmatically. They should be handled separately and excluded from standard interactive MFA policies.
Free Microsoft Office alternative

Looking for a Lightweight Alternative to Microsoft 365?

Managing complex Microsoft 365 licenses, Entra ID configurations, and MFA administration for a large team can be overwhelming. If you simply need a robust, reliable, and hassle-free office suite for document editing, WPS Office provides everything you need without the complicated administrative overhead.

100% compatible with Microsoft Word, Excel, and PowerPoint formats.Free, lightweight, and fast alternative to heavy Microsoft 365 deployments.No complex MFA or Entra ID administration required for basic offline use.Familiar user interface ensuring seamless migration for your team.
microsoft office alternative - wps office

Frequently Asked Questions

What does 'Not capable' mean for MFA status in Microsoft Entra ID?

'Not capable' typically indicates that the user has not yet signed in and registered a Multi-Factor Authentication method. Once the user completes the registration process for a method like the Microsoft Authenticator app or SMS, their status automatically updates to 'Capable'.

Why are my automated service accounts failing MFA?

Service accounts are generally used by applications or background scripts that cannot interactively respond to MFA prompts. You should create specific Conditional Access exclusions for these accounts or utilize alternative secure authentication methods, such as certificate-based authentication.

Do I need a specific license to use Conditional Access for MFA?

Yes. While basic Security Defaults are available for free, configuring detailed, granular Conditional Access policies for MFA requires your organization to have an active Microsoft Entra ID Premium (P1 or P2) license.

Why do synchronized on-premises users show as 'Not capable'?

Users synchronized from an on-premises Active Directory may appear as 'Not capable' if they have not been assigned a valid Microsoft 365 license in the cloud or if they haven't completed their initial cloud sign-in to register their MFA methods.