logo
search
MFA Security Issues

How to Stop Microsoft 365 Admin MFA Prompts for Email and Phone Methods

Maira MehtabMaira Mehtab Sep 21, 2026 869 views

Question details

An organization wants to restrict multifactor authentication (MFA) solely to FIDO2 and TOTP, but administrator accounts continue receiving 'More information required' prompts for email and phone authentication.

Product
Microsoft 365 / Entra ID
Device & OS
not provided
Scenario
Configuring multifactor authentication for Microsoft 365 admins exclusively using FIDO2 and TOTP without disabling security baselines.
Observed behavior
Lower-privileged accounts work correctly, but administrator accounts still get prompted for phone or email authentication even though those methods are disabled in Microsoft Entra ID.
Before you start

Ensure you have global administrator access to the Microsoft Entra admin center to review and modify authentication and password reset policies.

Solution 1Recommended

Check and Disable Legacy Self-Service Password Reset (SSPR) Methods

The 'More information required' prompt is often triggered by legacy SSPR settings that override your modern Authentication methods policy.

Microsoft Entra ID has multiple areas where authentication requirements are enforced. Even if you disable phone and email in the primary Authentication methods policy, the legacy Self-Service Password Reset (SSPR) settings might still require them for administrator roles.

1
Access Microsoft Entra admin center

Sign in to the Microsoft Entra admin center using your administrator credentials.

2
Navigate to Password Reset

In the left-hand navigation pane, expand the 'Protection' menu and select 'Password reset'.

3
Review Authentication Methods

Click on 'Authentication methods'. Here, review the methods that are configured for users to reset their passwords.

4
Disable Unwanted Methods

Uncheck 'Email' and 'Mobile app code' (or any phone-related options) to ensure that only FIDO2 and TOTP-compatible methods remain active.

Administrative Overrides: By default, Microsoft enforces a strong two-gate password reset policy for highly privileged administrator roles, which may require specific recovery methods regardless of user-level settings.
Free Microsoft Office alternative

Need a Powerful and Free Office Suite? Try WPS Office

While managing complex Microsoft 365 administrator settings and Entra ID configurations can be challenging and costly for organizations, your day-to-day document productivity doesn't have to be. WPS Office provides a lightweight, highly compatible, and completely free alternative for your teams to seamlessly create, edit, and collaborate on documents without dealing with expensive subscription tiers.

  1. 1. Download the software: Visit the official WPS Office website to download the free installer for your operating system.
  2. 2. Install and launch: Run the setup file and follow the on-screen instructions to install WPS Office on your device.
  3. 3. Open your documents: Launch the application and immediately start opening, editing, and saving your existing Microsoft Office files without compatibility issues.
Fully compatible with Microsoft Office file formats (Word, Excel, PowerPoint).Lightweight design for fast startup and smooth operation on any computer.Free alternative to Microsoft 365 for standard business document editing and sharing.Familiar, easy-to-use user interface requiring zero learning curve for users.
microsoft office alternative - wps office

Frequently Asked Questions

Why do only admin accounts get the MFA prompt while normal users do not?

Microsoft enforces stricter security baselines and recovery policies for highly privileged administrator roles. Sometimes, these baseline policies mandate secondary authentication channels like phone or email for account recovery, overriding the general disabled methods configured for standard users.

Can I use only FIDO2 security keys for Microsoft 365 administrators?

Yes, it is possible to restrict MFA exclusively to FIDO2 and TOTP. However, you must carefully configure your Authentication Methods policy and ensure that legacy Self-Service Password Reset (SSPR) settings aren't forcing alternative methods in the background.

What happens if I disable Microsoft's default security baselines?

Disabling default security baselines can expose your administrative accounts to unauthorized access risks. It is strongly recommended to keep them enabled and adjust specific authentication policies, or contact Microsoft support for granular control over MFA methods.