Fix Exchange Online Prompting for MFA When Disabled
Question details
Users are being asked to register for Microsoft Authenticator or MFA even though per-user multifactor authentication is disabled for their accounts.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- A user attempts to log into their Exchange Online account and expects a password-only login because per-user MFA is turned off.
- Observed behavior
- The system unexpectedly interrupts the login process and prompts the user to register security information for Microsoft Authenticator.
Ensure you have organization administrator privileges in Microsoft Entra ID (formerly Azure AD) before making changes. Note that changes to authentication policies may take a short time to propagate across your Microsoft 365 environment.
Disable SSPR Security Information Registration
Self-Service Password Reset (SSPR) settings often force users to register security information upon login, mimicking an MFA prompt. Disabling this requirement usually resolves the issue.
In many Microsoft 365 environments, even if per-user MFA is turned off, the default SSPR policies require users to set up security info for account recovery. This registration process uses the same Microsoft Authenticator setup prompt as MFA.
Log in to the Microsoft Entra admin center with your organization administrator credentials.
Go to Identity > Protection > Password reset from the left-hand navigation menu.
Select the 'Registration' tab. Find the option 'Require users to register when signing in' and change it to 'No'. Save the configuration.

Review Conditional Access Policies and Security Defaults
Tenant-wide security configurations might override per-user MFA settings, forcing users to authenticate regardless of their individual account setup.
Escalate to Microsoft Support
If all settings have been verified and the prompt persists, the issue might be rooted in backend synchronization delays or hidden device-join policies.
Looking for a simpler alternative to Microsoft Office?
Managing complex Microsoft 365 admin settings like Exchange Online MFA can be overwhelming. If you are looking for a reliable, lightweight, and cost-effective productivity suite for your team, try WPS Office. It provides powerful document, spreadsheet, and presentation tools without the heavy administrative overhead.
- 1. Download WPS Office: Visit the official WPS Office website and download the installer for your operating system.
- 2. Install the Suite: Run the installation file and follow the straightforward on-screen instructions to set up the software.
- 3. Open and Edit Files: Instantly open your existing .docx, .xlsx, and .pptx files and start working without complicated account configurations.

Frequently Asked Questions
Why is MFA prompting when it shows as disabled for the user?
Microsoft 365 uses multiple security layers. Even if legacy per-user MFA is disabled, tenant-wide settings like Security Defaults, Conditional Access policies, or Self-Service Password Reset (SSPR) registration can still mandate an authentication prompt.
Can I disable MFA for just one specific user?
Yes, but you must ensure that the user is excluded from any Conditional Access policies that enforce MFA, and that tenant-wide Security Defaults are disabled, as these override per-user settings.
What are Microsoft Entra Security Defaults?
Security Defaults are preconfigured identity security settings provided by Microsoft. When enabled, they require all users in the tenant to register for MFA, regardless of individual per-user legacy MFA toggles.
Do I need a premium license to disable SSPR registration?
Basic SSPR settings can be managed with standard licenses. However, creating granular Conditional Access policies to bypass certain users or groups requires a Microsoft Entra ID P1 or P2 premium license.




