Why Microsoft 365 Apps Still Prompt for MFA After Being Disabled
Question details
Installed Microsoft 365 desktop applications continue to request Multi-Factor Authentication (MFA) prompts even after MFA has been completely disabled for all users in the admin center.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Accessing installed Microsoft 365 desktop applications after disabling multi-factor authentication for the tenant.
- Observed behavior
- The applications ignore the disabled status in the admin center and continue to block access by prompting the user for MFA verification.
Ensure you are logged into the Microsoft 365 Admin Center with an account that has Global Administrator privileges, as tenant-wide authentication changes and support ticket creations require full admin rights.
Create a Service Ticket for Backend Authentication Investigation
Because the disabled MFA settings are not syncing to the desktop apps, Microsoft support engineers must investigate the backend authentication and tenant settings.
In some cases, tenant-level MFA settings or Azure Active Directory security defaults can become out of sync with what is displayed in the Microsoft 365 admin portal. Only Microsoft support engineers have the necessary backend permissions to investigate and force-sync these account authentication configurations.
Navigate to the Microsoft 365 Admin Center and log in using your Global Administrator credentials.
Click on the 'Support' or 'Help & support' icon located in the bottom right corner of the admin dashboard.
Enter a brief description of the MFA issue (e.g., 'MFA disabled but desktop apps still prompting'). Follow the prompts to create a formal service ticket requesting engineers to investigate your tenant's authentication sync.
Verify Administrator Roles and Settings Validation
Check your admin status and have another administrator verify the settings to ensure no conflicting configurations exist.
Switch to WPS Office to Avoid Complex Authentication Issues
Tired of dealing with complex Microsoft 365 admin settings, forced MFA prompts, and syncing issues? WPS Office offers a lightweight, easy-to-use alternative with full offline capabilities, letting you focus on your work instead of troubleshooting account access.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the Software: Run the downloaded file and follow the straightforward on-screen instructions to install the suite.
- 3. Open Your Documents: Launch WPS Office and open your existing Word, Excel, and PowerPoint files immediately without complicated sign-ins.

Frequently Asked Questions
How long does it take for MFA settings to update in Microsoft 365 apps?
When you disable MFA in the Microsoft 365 admin center, it can take anywhere from a few minutes to 24 hours for the changes to fully propagate across all Azure Active Directory services and desktop applications.
Can Security Defaults override disabled MFA settings?
Yes. If your tenant has 'Security Defaults' enabled in Azure Active Directory, it will automatically require MFA for all users, completely overriding the per-user MFA settings configured in the Microsoft 365 Admin Center.
Why do I need a Global Administrator to fix MFA sync issues?
Tenant-level authentication policies, including MFA enforcement and Azure AD sync troubleshooting, are strictly protected. Only accounts holding the Global Administrator role have the clearance to view these backend settings and authorize Microsoft support to make changes.




