How to Temporarily Disable MFA in Microsoft Entra ID for Migration
Question details
Administrators need to bypass or temporarily disable MFA in Microsoft Entra ID to allow migration service accounts (such as BitTitan) to authenticate during Microsoft 365 tenant migrations.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Performing a Microsoft 365 tenant migration using third-party tools where service accounts are blocked by MFA enforcement.
- Observed behavior
- Migration service accounts fail to authenticate because global MFA enforcement blocks automated or non-interactive login processes.
Ensure you have Global Administrator or Security Administrator privileges in Microsoft Entra ID. Because disabling MFA reduces tenant security, it should only be done temporarily during the migration window.
Disable Security Defaults in Microsoft Entra ID
Turn off global security defaults temporarily if your tenant relies on them for baseline MFA enforcement.
Microsoft enables security defaults on all new tenants by default, which enforces MFA for all users. During a migration, this can block service accounts that do not support interactive MFA prompts. Disabling this setting temporarily will allow legacy authentication and automated logins.
Log in to the Microsoft Entra admin center using an account with Global Administrator credentials.
In the left-hand navigation menu, expand 'Identity', click on 'Overview', and then select 'Properties'.
Scroll to the bottom of the Properties page and click the 'Manage security defaults' link.
In the side panel, set 'Security defaults' to 'Disabled (not recommended)'. Provide a reason if prompted, and click 'Save' at the bottom.

Exclude Migration Accounts via Conditional Access
If you have Microsoft Entra ID P1 or P2 licenses, exclude specific migration service accounts rather than disabling MFA tenant-wide.
Looking for a cost-effective alternative to Microsoft 365 after migration?
Whether you are consolidating tenants or optimizing software costs post-migration, WPS Office provides a powerful, lightweight, and free alternative to Microsoft Office. It offers seamless compatibility without complex Entra ID management overhead.
- 1. Download WPS Office: Visit the official WPS Office website and click the 'Free Download' button.
- 2. Install the Software: Run the downloaded installer and follow the on-screen instructions to complete the setup.
- 3. Start Creating: Launch WPS Office to instantly open and edit your existing Microsoft Office documents.

Frequently Asked Questions
Why is BitTitan failing to authenticate during my Microsoft 365 migration?
Migration tools like BitTitan use service accounts that often rely on automated, non-interactive login processes. If Multi-Factor Authentication (MFA) is strictly enforced on the tenant, the tool cannot complete the secondary authentication prompt, causing the login to fail.
Is it safe to disable Security Defaults in Microsoft Entra ID?
Disabling security defaults significantly reduces your tenant's security posture by removing baseline protections. It should only be done temporarily during the designated migration window, and must be re-enabled immediately once the migration completes.
Can I bypass MFA for just one specific user account?
Yes, if your tenant holds Microsoft Entra ID P1 or P2 licenses, you can use Conditional Access policies to enforce MFA for the organization while explicitly excluding the specific migration service accounts.




