How to Stop Microsoft 365 Admin MFA Prompts for Email and Phone Methods
Question details
An organization wants to restrict multifactor authentication (MFA) solely to FIDO2 and TOTP, but administrator accounts continue receiving 'More information required' prompts for email and phone authentication.
- Product
- Microsoft 365 / Entra ID
- Device & OS
- not provided
- Scenario
- Configuring multifactor authentication for Microsoft 365 admins exclusively using FIDO2 and TOTP without disabling security baselines.
- Observed behavior
- Lower-privileged accounts work correctly, but administrator accounts still get prompted for phone or email authentication even though those methods are disabled in Microsoft Entra ID.
Ensure you have global administrator access to the Microsoft Entra admin center to review and modify authentication and password reset policies.
Check and Disable Legacy Self-Service Password Reset (SSPR) Methods
The 'More information required' prompt is often triggered by legacy SSPR settings that override your modern Authentication methods policy.
Microsoft Entra ID has multiple areas where authentication requirements are enforced. Even if you disable phone and email in the primary Authentication methods policy, the legacy Self-Service Password Reset (SSPR) settings might still require them for administrator roles.
Sign in to the Microsoft Entra admin center using your administrator credentials.
In the left-hand navigation pane, expand the 'Protection' menu and select 'Password reset'.
Click on 'Authentication methods'. Here, review the methods that are configured for users to reset their passwords.
Uncheck 'Email' and 'Mobile app code' (or any phone-related options) to ensure that only FIDO2 and TOTP-compatible methods remain active.
Consult Microsoft Support for Security Baseline Configuration
If legacy SSPR methods are already disabled, the prompt is likely enforced by underlying security baselines that require professional guidance to modify safely.
Need a Powerful and Free Office Suite? Try WPS Office
While managing complex Microsoft 365 administrator settings and Entra ID configurations can be challenging and costly for organizations, your day-to-day document productivity doesn't have to be. WPS Office provides a lightweight, highly compatible, and completely free alternative for your teams to seamlessly create, edit, and collaborate on documents without dealing with expensive subscription tiers.
- 1. Download the software: Visit the official WPS Office website to download the free installer for your operating system.
- 2. Install and launch: Run the setup file and follow the on-screen instructions to install WPS Office on your device.
- 3. Open your documents: Launch the application and immediately start opening, editing, and saving your existing Microsoft Office files without compatibility issues.

Frequently Asked Questions
Why do only admin accounts get the MFA prompt while normal users do not?
Microsoft enforces stricter security baselines and recovery policies for highly privileged administrator roles. Sometimes, these baseline policies mandate secondary authentication channels like phone or email for account recovery, overriding the general disabled methods configured for standard users.
Can I use only FIDO2 security keys for Microsoft 365 administrators?
Yes, it is possible to restrict MFA exclusively to FIDO2 and TOTP. However, you must carefully configure your Authentication Methods policy and ensure that legacy Self-Service Password Reset (SSPR) settings aren't forcing alternative methods in the background.
What happens if I disable Microsoft's default security baselines?
Disabling default security baselines can expose your administrative accounts to unauthorized access risks. It is strongly recommended to keep them enabled and adjust specific authentication policies, or contact Microsoft support for granular control over MFA methods.




