How to Troubleshoot MFA Enforcement When Security Defaults Are Disabled in Microsoft 365
Question details
Users or administrators are still being prompted for Multi-Factor Authentication (MFA) at login, despite security defaults and account-level MFA being explicitly disabled.

- Product
- Microsoft 365 / Microsoft Entra
- Device & OS
- not provided
- Scenario
- Managing authentication and security protocols for Microsoft 365 managed accounts.
- Observed behavior
- The system enforces MFA enrollment or prompts during the sign-in process, overriding the disabled status of tenant security defaults.
Ensure you are signed in with an account that has Global Administrator or Security Administrator privileges in Microsoft Entra to view and modify authentication policies.
Check and Modify Microsoft-Managed Conditional Access Policies
Identify and exclude the affected account from automatically generated Conditional Access policies that enforce MFA.
Microsoft occasionally deploys default Conditional Access policies, such as 'Multifactor authentication for admins', to improve tenant security. These policies function independently and can override disabled security defaults.
Sign in to the Microsoft Entra admin center using your administrator credentials.
On the left sidebar, expand 'Protection' and select 'Conditional Access'.
Review the list of policies for any Microsoft-managed rules, such as 'Multifactor authentication for admins' or similar security-focused policies.
Open the policy, navigate to the 'Users' assignment section, and add the specific account to the 'Exclude' list. Save the policy.

Verify Self-Service Password Reset (SSPR) Registration Requirements
Ensure that SSPR registration settings are not inadvertently forcing users to enroll in MFA methods upon sign-in.
Contact Microsoft 365 Support
If all policies are verified and MFA is still enforced, backend synchronization issues may require Microsoft's direct intervention.
Switch to WPS Office for a Hassle-Free Document Experience
If complex enterprise administration and unexpected security enforcements in Microsoft 365 are slowing down your team's workflow, consider switching to WPS Office. It provides a lightweight, highly compatible, and easy-to-manage productivity suite without the overhead of enterprise tenant configurations.

Frequently Asked Questions
Why am I being asked to set up MFA when I specifically turned off Security Defaults?
Microsoft 365 uses multiple layers of security. Even if broad Security Defaults are disabled, Microsoft Entra may enforce MFA through Microsoft-managed Conditional Access policies (like mandatory admin MFA) or Self-Service Password Reset (SSPR) registration requirements.
Can I permanently delete the 'Multifactor authentication for admins' policy?
You generally cannot delete Microsoft-managed default security policies, but you can edit them to exclude specific users or groups if your organization's security posture allows it.
Can Microsoft community moderators fix my MFA loop?
No. Community moderators on Microsoft forums do not have backend access to your tenant. To resolve backend MFA enforcement issues, an administrator must submit a service request directly through the Microsoft 365 admin center.
How long does it take for MFA policy changes to take effect?
Changes to Conditional Access policies or Security Defaults typically take effect within a few minutes, but can sometimes take up to 24 hours to fully propagate across all Microsoft 365 services.




