Fix Failed to Enable Per-User MFA in Microsoft Entra
Question details
Administrators are unable to enable per-user multifactor authentication for users in Microsoft Entra despite having Authentication Administrator roles.

- Product
- Microsoft Entra
- Device & OS
- not provided
- Scenario
- An administrator is attempting to activate per-user multifactor authentication in the Microsoft Entra admin center.
- Observed behavior
- The system returns a failure message, preventing the administrator from successfully enabling per-user MFA for the selected users.
Ensure you have access to a Global Administrator account, as modifying and assigning administrator roles in Microsoft Entra requires elevated privileges.
Assign the Authentication Policy Administrator Role
Adding the Authentication Policy Administrator role provides the necessary permissions required to modify MFA policies.
In many cases, having only the Authentication Administrator or Privileged Authentication Administrator role is insufficient. The Authentication Policy Administrator role is explicitly required to make changes to user MFA statuses.
Log in to the Microsoft Entra admin center using an account with Global Administrator privileges.
In the left-hand menu, go to Identity, expand Roles & admins, and click on Roles & admins.
Use the search bar to find the 'Authentication Policy Administrator' role and click on it.
Click 'Add assignments', select the administrator experiencing the error, and save the changes.
Wait for 15 to 30 minutes to allow the new permissions to propagate across the system, then have the administrator log back in and try enabling per-user MFA again.

Remove and Reassign Existing Authentication Roles
If the correct roles are already assigned but the error persists, removing and reassigning them can resolve backend permission glitches.
Enhance Team Productivity with WPS Office
While you manage identity and security settings in Microsoft Entra, ensure your team has the best tools for document creation. WPS Office is a lightweight, secure, and cost-effective alternative to Microsoft Office that meets all your daily business needs.
- 1. Download the Installer: Visit the official WPS website and download the free installation package.
- 2. Install the Software: Run the downloaded file and follow the simple on-screen instructions to install WPS Office on your device.
- 3. Start Creating: Open WPS Office to instantly view, edit, or create documents with full Microsoft format compatibility.

Frequently Asked Questions
Why do I get an MFA error even with the Authentication Administrator role?
The Authentication Administrator role alone is sometimes insufficient for modifying multifactor authentication policies. You typically must also have the Authentication Policy Administrator role assigned to your account.
How long does it take for a new role assignment to work in Microsoft Entra?
Role assignments can take anywhere from a few minutes to up to 30 minutes to fully propagate across the Microsoft Entra environment. It is strongly recommended that the user logs out and logs back in to acquire a fresh access token.
Can I manage per-user MFA without being a Global Administrator?
Yes. Users with the combination of Authentication Policy Administrator, Privileged Authentication Administrator, and Authentication Administrator roles can manage MFA settings for non-global admin users, provided the permissions have fully propagated.




