logo
search
MFA Security Issues

Fix Failed to Enable Per-User MFA in Microsoft Entra

Tauseeq MagsiTauseeq Magsi Sep 28, 2026 869 views

Question details

Administrators are unable to enable per-user multifactor authentication for users in Microsoft Entra despite having Authentication Administrator roles.

How to Fix Failed to Enable Per-User MFA in Microsoft Entra
Product
Microsoft Entra
Device & OS
not provided
Scenario
An administrator is attempting to activate per-user multifactor authentication in the Microsoft Entra admin center.
Observed behavior
The system returns a failure message, preventing the administrator from successfully enabling per-user MFA for the selected users.
Before you start

Ensure you have access to a Global Administrator account, as modifying and assigning administrator roles in Microsoft Entra requires elevated privileges.

Solution 1Recommended

Assign the Authentication Policy Administrator Role

Adding the Authentication Policy Administrator role provides the necessary permissions required to modify MFA policies.

In many cases, having only the Authentication Administrator or Privileged Authentication Administrator role is insufficient. The Authentication Policy Administrator role is explicitly required to make changes to user MFA statuses.

1
Sign in to Microsoft Entra

Log in to the Microsoft Entra admin center using an account with Global Administrator privileges.

2
Navigate to Roles

In the left-hand menu, go to Identity, expand Roles & admins, and click on Roles & admins.

3
Locate the Policy Role

Use the search bar to find the 'Authentication Policy Administrator' role and click on it.

4
Assign the Role

Click 'Add assignments', select the administrator experiencing the error, and save the changes.

5
Allow Time to Propagate

Wait for 15 to 30 minutes to allow the new permissions to propagate across the system, then have the administrator log back in and try enabling per-user MFA again.

Assign the Authentication Policy Administrator Role
Propagation Delay: Role assignments in Microsoft Entra are not always instantaneous. If the error persists immediately after assignment, wait a few more minutes and ensure the user logs out and logs back in to refresh their access token.
Free Microsoft Office alternative

Enhance Team Productivity with WPS Office

While you manage identity and security settings in Microsoft Entra, ensure your team has the best tools for document creation. WPS Office is a lightweight, secure, and cost-effective alternative to Microsoft Office that meets all your daily business needs.

  1. 1. Download the Installer: Visit the official WPS website and download the free installation package.
  2. 2. Install the Software: Run the downloaded file and follow the simple on-screen instructions to install WPS Office on your device.
  3. 3. Start Creating: Open WPS Office to instantly view, edit, or create documents with full Microsoft format compatibility.
Completely free and lightweight alternative to Microsoft Office.Seamlessly compatible with Microsoft Word, Excel, and PowerPoint formats.Enterprise-grade security for safe local and cloud document handling.Familiar tabbed user interface reduces the learning curve for your team.
microsoft office alternative - wps office

Frequently Asked Questions

Why do I get an MFA error even with the Authentication Administrator role?

The Authentication Administrator role alone is sometimes insufficient for modifying multifactor authentication policies. You typically must also have the Authentication Policy Administrator role assigned to your account.

How long does it take for a new role assignment to work in Microsoft Entra?

Role assignments can take anywhere from a few minutes to up to 30 minutes to fully propagate across the Microsoft Entra environment. It is strongly recommended that the user logs out and logs back in to acquire a fresh access token.

Can I manage per-user MFA without being a Global Administrator?

Yes. Users with the combination of Authentication Policy Administrator, Privileged Authentication Administrator, and Authentication Administrator roles can manage MFA settings for non-global admin users, provided the permissions have fully propagated.