Do You Need to Enable Microsoft 365 MFA with Authentication Strength?
Question details
The user wants to know if they need to manually enable the Microsoft 365 admin center MFA setting when utilizing Microsoft Entra Authentication Strength and Conditional Access to enforce security key logins.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Administrators configuring Conditional Access policies and Authentication Strength for Microsoft 365 user groups.
- Observed behavior
- Seeking confirmation on best practices regarding overlapping legacy admin center MFA settings and modern Entra Conditional Access requirements.
Ensure you have global administrator or security administrator privileges in Microsoft Entra ID and access to the Microsoft 365 admin center to manage Conditional Access policies safely.
Configure Conditional Access with Authentication Strength
The recommended approach is to rely entirely on Conditional Access and Authentication Strength rather than the legacy per-user MFA settings.
Authentication Strength and Conditional Access together determine which authentication methods (such as security keys) are required for users. When configured properly, the legacy Microsoft 365 admin center MFA setting does not need to be separately enabled.
Sign in to the Microsoft Entra admin center as an administrator.
Navigate to Protection > Authentication methods > Authentication strengths to define the permitted authentication combinations (e.g., requiring FIDO2 security keys).
Go to Protection > Conditional Access > Policies and create or modify a policy to enforce your newly created Authentication Strength for the target users or groups.
Review and Maintain Admin Center MFA Settings
Verify that legacy MFA settings are not conflicting with your modern Conditional Access policies.
Looking for a Hassle-Free Alternative to Microsoft 365?
Managing complex Microsoft 365 administrative settings like Conditional Access and Authentication Strength can be overwhelming. If your team simply needs a robust, easy-to-use office suite for daily document work, consider WPS Office. It provides powerful tools without the administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website and click the Free Download button.
- 2. Install WPS Office: Run the installer file and follow the on-screen instructions to set up the software on your device.
- 3. Open Office Files Instantly: Double-click any existing Microsoft docx, xlsx, or pptx file to open and edit it natively in WPS Office.

Frequently Asked Questions
What is Microsoft Entra Authentication Strength?
Authentication Strength is a Conditional Access control that allows administrators to specify exactly which combinations of authentication methods (such as phishing-resistant security keys or Microsoft Authenticator) must be used to access a resource.
Does Conditional Access override per-user MFA settings?
Yes, Conditional Access policies take precedence over legacy per-user MFA settings in the Microsoft 365 admin center. It is highly recommended to migrate fully to Conditional Access for centralized policy management.
Do I need to disable per-user MFA to use Authentication Strength?
You do not necessarily need to proactively disable it if it wasn't enabled, but Microsoft recommends keeping per-user MFA disabled when enforcing MFA via Conditional Access to prevent policy overlaps and unexpected user prompts.
Can I test Conditional Access policies before enforcing them?
Yes, Microsoft Entra allows you to create Conditional Access policies in 'Report-only' mode. This lets you evaluate the impact of the policy on user sign-ins before actively enforcing the Authentication Strength.




