logo
search
MFA Security Issues

How to Disable the Microsoft 365 Action Required MFA Prompt for One User

Chanuka GeekiyanageChanuka Geekiyanage Sep 27, 2026 868 views

Question details

The user needs to stop the recurring "Action Required" multifactor authentication (MFA) prompt for a specific individual account within a Microsoft 365 environment.

How to Disable the Microsoft 365 Action Required Prompt for One User
Product
Microsoft 365
Device & OS
not provided
Scenario
Managing user authentication settings and security policies in a Microsoft 365 business tenant.
Observed behavior
Microsoft 365 repeatedly interrupts the login process with an "Action Required" screen, forcing the user to set up or verify multifactor authentication.
Before you start

You must have Microsoft 365 Global Administrator or Authentication Administrator privileges to modify tenant-wide security defaults, Conditional Access policies, or per-user MFA settings.

Solution 1Recommended

Modify Microsoft 365 Authentication Policies via the Admin Center

Use the Microsoft Entra admin center (formerly Azure AD) or the Microsoft 365 admin center to adjust the policies enforcing the MFA prompt for the specific user.

In a business environment, multifactor authentication (MFA) and the "Action Required" registration prompts are controlled by tenant-wide authentication policies. Disabling this prompt for a single user requires adjusting the specific policy governing their account.

Please note that creating a per-user exception for MFA reduces account security and is generally advised against by Microsoft security guidelines.

1
Check Security Defaults

Log in to the Microsoft Entra admin center as an administrator. Navigate to 'Identity' > 'Overview' > 'Properties' and check if 'Security defaults' are enabled. If enabled, MFA is required for everyone, and per-user exceptions are not possible without disabling security defaults entirely.

2
Adjust Conditional Access Policies

If your organization uses Conditional Access instead of Security Defaults, go to 'Protection' > 'Conditional Access'. Locate the policy enforcing MFA, edit it, and add the specific user to the 'Exclude' list under the 'Users' assignment.

3
Modify Legacy Per-User MFA

If you are using legacy per-user MFA, log in to the Microsoft 365 Admin Center. Go to 'Users' > 'Active users', click 'Multi-factor authentication' at the top, select the specific user, and change their MFA status to 'Disabled'.

Modify Microsoft 365 Authentication Policies via the Admin Center
Security Warning: Disabling MFA for individual users significantly increases the risk of account compromise. Consider using alternative authentication methods like Windows Hello or hardware security keys instead of removing MFA entirely.
Free Microsoft Office alternative

Tired of Constant Microsoft 365 Login and MFA Prompts? Try WPS Office

If managing complex Microsoft 365 tenant policies, security defaults, and constant "Action Required" MFA prompts is disrupting your workflow, consider switching to WPS Office. It provides a powerful, hassle-free environment for local document editing without forcing continuous online authentication.

Free, lightweight, and fast document editing without forced cloud loginsFully compatible with Microsoft Office formats (DOCX, XLSX, PPTX)Edit files locally without mandatory tenant MFA security policiesFamiliar user interface for a seamless and easy migration
microsoft office alternative - wps office

Frequently Asked Questions

Why does Microsoft 365 keep saying "Action Required" at login?

This prompt appears because your organization has enabled Security Defaults, Conditional Access policies, or a registration campaign that requires you to register the Microsoft Authenticator app or another multi-factor authentication (MFA) method for account security.

Can a standard user disable the MFA action required prompt themselves?

No, standard end-users cannot bypass or disable organizational security policies. Only a Microsoft 365 IT administrator can change these tenant-wide or per-user authentication requirements.

Does disabling MFA for one user affect the rest of the company?

If configured via Conditional Access or legacy per-user MFA, you can exclude a single user without affecting others. However, if your tenant uses "Security defaults," you cannot create exceptions; you would have to disable it for the entire organization, which exposes all users to higher security risks.