Who Must Set Up Microsoft 365 Tenant MFA: Administrators or All Users?
Question details
An organization needs clarification on whether the October 2024 Microsoft 365 multifactor authentication (MFA) mandate applies solely to administrators or to all end users.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Preparing for the October 15, 2024 deadline to enforce multifactor authentication across a Microsoft 365 organizational tenant.
- Observed behavior
- Determine the exact scope of the MFA requirement to understand whether tenant administrators, all organizational users, or specific groups must complete the authentication setup.
Ensure you have Global Administrator or Security Administrator privileges in the Microsoft Entra admin center to view and manage your organization's current MFA policies.
Determine MFA Scope via Microsoft Entra Settings
Check your tenant's Security Defaults and Conditional Access policies to identify exactly which users are mandated to register for MFA.
The requirement for who must set up MFA depends entirely on how your organization's Microsoft Entra ID (formerly Azure AD) policies are configured. While Microsoft mandates MFA for administrators accessing admin portals, tenant-wide enforcement for regular users relies on your specific policy settings.
Navigate to the Microsoft Entra admin center and log in using an account with Security Administrator permissions.
Go to 'Identity' > 'Overview' > 'Properties' and click on 'Manage security defaults'. If this is set to 'Enabled', all users in your organization are required to register for MFA.
If Security Defaults are disabled, go to 'Protection' > 'Conditional Access' > 'Policies'. Review the active policies to see which specific users, groups, or roles are targeted for MFA enforcement.
Based on the enabled policies, determine the affected users. Administrators must configure and enable these tenant policies, while the targeted end users are responsible for registering their own authentication methods (like the Microsoft Authenticator app).
Looking for a Simpler Office Solution? Try WPS Office
Managing complex tenant configurations, mandatory Entra ID policies, and MFA deadlines in Microsoft 365 can be overwhelming for small teams. If you are looking for a secure, lightweight, and hassle-free productivity suite, WPS Office offers powerful tools without the administrative burden.

Frequently Asked Questions
What happens if a user misses the October 15, 2024 MFA registration deadline?
If a user fails to register their multifactor authentication method by the enforcement deadline set by your tenant policies, they will be blocked from accessing their Microsoft 365 account until they complete the registration process or an administrator resets their sign-in status.
Can I exempt certain users from the Microsoft 365 MFA requirement?
Yes, if you are utilizing Microsoft Entra Conditional Access policies, administrators can specifically exclude certain users, groups, or emergency access 'break-glass' accounts from MFA requirements. However, if 'Security Defaults' are enabled, exemptions cannot be made, and all users must use MFA.
Do end users need to download a specific app to set up MFA?
Microsoft strongly recommends users download the Microsoft Authenticator app for secure push notifications and time-based codes. However, administrators can configure the tenant's Authentication Methods policy to allow alternatives such as SMS, voice calls, or FIDO2 security keys.




