logo
search
MFA Security Issues

How to Troubleshoot MFA Enforcement When Security Defaults Are Disabled in Microsoft 365

Nimra MalikNimra Malik Sep 30, 2026 868 views

Question details

Users or administrators are still being prompted for Multi-Factor Authentication (MFA) at login, despite security defaults and account-level MFA being explicitly disabled.

How to Troubleshoot MFA Enforcement When Security Defaults Are Disabled
Product
Microsoft 365 / Microsoft Entra
Device & OS
not provided
Scenario
Managing authentication and security protocols for Microsoft 365 managed accounts.
Observed behavior
The system enforces MFA enrollment or prompts during the sign-in process, overriding the disabled status of tenant security defaults.
Before you start

Ensure you are signed in with an account that has Global Administrator or Security Administrator privileges in Microsoft Entra to view and modify authentication policies.

Solution 1Recommended

Check and Modify Microsoft-Managed Conditional Access Policies

Identify and exclude the affected account from automatically generated Conditional Access policies that enforce MFA.

Microsoft occasionally deploys default Conditional Access policies, such as 'Multifactor authentication for admins', to improve tenant security. These policies function independently and can override disabled security defaults.

1
Access Microsoft Entra

Sign in to the Microsoft Entra admin center using your administrator credentials.

2
Navigate to Conditional Access

On the left sidebar, expand 'Protection' and select 'Conditional Access'.

3
Locate Auto-Added Policies

Review the list of policies for any Microsoft-managed rules, such as 'Multifactor authentication for admins' or similar security-focused policies.

4
Add an Exception

Open the policy, navigate to the 'Users' assignment section, and add the specific account to the 'Exclude' list. Save the policy.

Check and Modify Microsoft-Managed Conditional Access Policies
Security Warning: Only exclude accounts when absolutely necessary and permitted by your organization's security requirements. MFA is highly recommended for all admin roles.
Free Microsoft Office alternative

Switch to WPS Office for a Hassle-Free Document Experience

If complex enterprise administration and unexpected security enforcements in Microsoft 365 are slowing down your team's workflow, consider switching to WPS Office. It provides a lightweight, highly compatible, and easy-to-manage productivity suite without the overhead of enterprise tenant configurations.

Fully compatible with Microsoft Office formats including Word, Excel, and PowerPoint.Completely free for standard daily office tasks without complex admin setups.Lightweight application with fast installation and smooth performance.Familiar user interface for a seamless migration with zero learning curve.
microsoft office alternative - wps office

Frequently Asked Questions

Why am I being asked to set up MFA when I specifically turned off Security Defaults?

Microsoft 365 uses multiple layers of security. Even if broad Security Defaults are disabled, Microsoft Entra may enforce MFA through Microsoft-managed Conditional Access policies (like mandatory admin MFA) or Self-Service Password Reset (SSPR) registration requirements.

Can I permanently delete the 'Multifactor authentication for admins' policy?

You generally cannot delete Microsoft-managed default security policies, but you can edit them to exclude specific users or groups if your organization's security posture allows it.

Can Microsoft community moderators fix my MFA loop?

No. Community moderators on Microsoft forums do not have backend access to your tenant. To resolve backend MFA enforcement issues, an administrator must submit a service request directly through the Microsoft 365 admin center.

How long does it take for MFA policy changes to take effect?

Changes to Conditional Access policies or Security Defaults typically take effect within a few minutes, but can sometimes take up to 24 hours to fully propagate across all Microsoft 365 services.