logo
search
MFA Security Issues

How to Temporarily Disable MFA in Microsoft Entra ID for Migration

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 869 views

Question details

Administrators need to bypass or temporarily disable MFA in Microsoft Entra ID to allow migration service accounts (such as BitTitan) to authenticate during Microsoft 365 tenant migrations.

How to Temporarily Disable MFA in Microsoft Entra ID for Migrations
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Performing a Microsoft 365 tenant migration using third-party tools where service accounts are blocked by MFA enforcement.
Observed behavior
Migration service accounts fail to authenticate because global MFA enforcement blocks automated or non-interactive login processes.
Before you start

Ensure you have Global Administrator or Security Administrator privileges in Microsoft Entra ID. Because disabling MFA reduces tenant security, it should only be done temporarily during the migration window.

Solution 1Recommended

Disable Security Defaults in Microsoft Entra ID

Turn off global security defaults temporarily if your tenant relies on them for baseline MFA enforcement.

Microsoft enables security defaults on all new tenants by default, which enforces MFA for all users. During a migration, this can block service accounts that do not support interactive MFA prompts. Disabling this setting temporarily will allow legacy authentication and automated logins.

1
Access the Microsoft Entra admin center

Log in to the Microsoft Entra admin center using an account with Global Administrator credentials.

2
Navigate to Identity Properties

In the left-hand navigation menu, expand 'Identity', click on 'Overview', and then select 'Properties'.

3
Manage Security Defaults

Scroll to the bottom of the Properties page and click the 'Manage security defaults' link.

4
Disable and Save

In the side panel, set 'Security defaults' to 'Disabled (not recommended)'. Provide a reason if prompted, and click 'Save' at the bottom.

Disable Security Defaults in Microsoft Entra ID
Security Warning: Re-enable security defaults immediately after your migration is complete to ensure your tenant remains protected against identity attacks.
Free Microsoft Office alternative

Looking for a cost-effective alternative to Microsoft 365 after migration?

Whether you are consolidating tenants or optimizing software costs post-migration, WPS Office provides a powerful, lightweight, and free alternative to Microsoft Office. It offers seamless compatibility without complex Entra ID management overhead.

  1. 1. Download WPS Office: Visit the official WPS Office website and click the 'Free Download' button.
  2. 2. Install the Software: Run the downloaded installer and follow the on-screen instructions to complete the setup.
  3. 3. Start Creating: Launch WPS Office to instantly open and edit your existing Microsoft Office documents.
Fully compatible with Microsoft Office formats including .docx, .xlsx, and .pptx.No complex MFA or tenant administration required for basic offline use.Lightweight installation and low system resource consumption.Familiar user interface ensuring a seamless transition for your team.
microsoft office alternative - wps office

Frequently Asked Questions

Why is BitTitan failing to authenticate during my Microsoft 365 migration?

Migration tools like BitTitan use service accounts that often rely on automated, non-interactive login processes. If Multi-Factor Authentication (MFA) is strictly enforced on the tenant, the tool cannot complete the secondary authentication prompt, causing the login to fail.

Is it safe to disable Security Defaults in Microsoft Entra ID?

Disabling security defaults significantly reduces your tenant's security posture by removing baseline protections. It should only be done temporarily during the designated migration window, and must be re-enabled immediately once the migration completes.

Can I bypass MFA for just one specific user account?

Yes, if your tenant holds Microsoft Entra ID P1 or P2 licenses, you can use Conditional Access policies to enforce MFA for the organization while explicitly excluding the specific migration service accounts.