How to Disable Multifactor Authentication for a Microsoft 365 Administrator
Question details
The user needs to disable Multifactor Authentication (MFA) for a Microsoft 365 administrator account, specifically when the system continues to prompt for MFA despite user settings showing it as disabled.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Modifying security settings for an admin account within the Microsoft 365 admin center or Microsoft Entra ID.
- Observed behavior
- Multifactor authentication remains active and prompts the administrator during login, even when the Microsoft 365 admin center indicates that MFA is disabled for users.
Ensure you have Global Administrator privileges before attempting to change MFA settings, and consider the severe security risks associated with removing MFA from administrative accounts.
Disable MFA Directly in the Active Users List
Use this method to explicitly turn off per-user MFA for a specific admin account via the Microsoft 365 admin center.
This is the standard approach for managing legacy per-user MFA settings. If this is the only place MFA is enforced, these steps will resolve the issue.
Navigate to the Microsoft 365 admin center and sign in using your Global Administrator credentials.
On the left navigation pane, click on 'Users' and then select 'Active users'.
Click on 'Multi-factor authentication' at the top of the Active users page to open the classic MFA management portal.
Locate and check the box next to the specific administrator account you want to modify.
Under the quick steps menu on the right side of the screen, click 'Disable' and confirm your action in the pop-up dialog.

Check Security Defaults and Conditional Access
If MFA is still enforced after disabling it per-user, a tenant-wide policy or security default is likely overriding your individual settings.
Switch to WPS Office for a Streamlined Document Experience
While Microsoft 365 offers extensive enterprise security policies like MFA, it can sometimes feel overly complex for basic productivity needs. If you are looking for a free, lightweight, and easy-to-manage office suite without complex admin centers, WPS Office is the perfect alternative.
- 1. Download the Installer: Visit the official WPS Office website and click the Free Download button.
- 2. Install WPS Office: Run the downloaded installer file and follow the simple on-screen instructions.
- 3. Start Creating: Open WPS Office and immediately start editing your existing Office files without complex logins.

Frequently Asked Questions
Why is MFA still prompting after I disabled it in the Microsoft 365 admin center?
This usually happens because 'Security defaults' are enabled in Microsoft Entra ID, or a Conditional Access policy is active. These tenant-wide settings override the legacy per-user MFA settings.
Can I disable MFA for just one specific administrator?
Yes, you can disable per-user MFA in the Active users section. However, you must also ensure that no tenant-wide Conditional Access policies are enforcing MFA for the global Admin role, or you will need to add an exclusion for that specific user.
Is it safe to disable MFA for a Microsoft 365 admin account?
No, it is highly discouraged. Administrator accounts have extensive privileges and are prime targets for malicious attacks. Keeping MFA enabled adds a necessary and critical layer of security to your tenant.
Where do I find the Conditional Access policies?
Conditional Access policies are located in the Microsoft Entra admin center under Protection > Conditional Access. Note that managing these policies requires a Microsoft Entra ID P1 or P2 license.




