logo
search
MFA Security Issues

Who Must Set Up Microsoft 365 Tenant MFA: Administrators or All Users?

Chanuka GeekiyanageChanuka Geekiyanage Sep 25, 2026 869 views

Question details

An organization needs clarification on whether the October 2024 Microsoft 365 multifactor authentication (MFA) mandate applies solely to administrators or to all end users.

Who Is Required to Set Up Microsoft 365 Tenant MFA?
Product
Microsoft 365
Device & OS
not provided
Scenario
Preparing for the October 15, 2024 deadline to enforce multifactor authentication across a Microsoft 365 organizational tenant.
Observed behavior
Determine the exact scope of the MFA requirement to understand whether tenant administrators, all organizational users, or specific groups must complete the authentication setup.
Before you start

Ensure you have Global Administrator or Security Administrator privileges in the Microsoft Entra admin center to view and manage your organization's current MFA policies.

Solution 1Recommended

Determine MFA Scope via Microsoft Entra Settings

Check your tenant's Security Defaults and Conditional Access policies to identify exactly which users are mandated to register for MFA.

The requirement for who must set up MFA depends entirely on how your organization's Microsoft Entra ID (formerly Azure AD) policies are configured. While Microsoft mandates MFA for administrators accessing admin portals, tenant-wide enforcement for regular users relies on your specific policy settings.

1
Sign in to Microsoft Entra ID

Navigate to the Microsoft Entra admin center and log in using an account with Security Administrator permissions.

2
Check Security Defaults

Go to 'Identity' > 'Overview' > 'Properties' and click on 'Manage security defaults'. If this is set to 'Enabled', all users in your organization are required to register for MFA.

3
Review Conditional Access Policies

If Security Defaults are disabled, go to 'Protection' > 'Conditional Access' > 'Policies'. Review the active policies to see which specific users, groups, or roles are targeted for MFA enforcement.

4
Identify Affected Users

Based on the enabled policies, determine the affected users. Administrators must configure and enable these tenant policies, while the targeted end users are responsible for registering their own authentication methods (like the Microsoft Authenticator app).

Mandatory Administrator MFA: Even if user-level MFA is not enforced via Conditional Access, Microsoft is strictly enforcing MFA for all administrator roles signing into Microsoft admin portals starting in the second half of 2024.
Free Microsoft Office alternative

Looking for a Simpler Office Solution? Try WPS Office

Managing complex tenant configurations, mandatory Entra ID policies, and MFA deadlines in Microsoft 365 can be overwhelming for small teams. If you are looking for a secure, lightweight, and hassle-free productivity suite, WPS Office offers powerful tools without the administrative burden.

Fully compatible with Microsoft Office formats including Word, Excel, and PowerPointNo complex tenant administration or mandatory cloud security configurations requiredBuilt-in local document security and PDF editing capabilitiesLightweight software with a familiar, easy-to-use interface
microsoft office alternative - wps office

Frequently Asked Questions

What happens if a user misses the October 15, 2024 MFA registration deadline?

If a user fails to register their multifactor authentication method by the enforcement deadline set by your tenant policies, they will be blocked from accessing their Microsoft 365 account until they complete the registration process or an administrator resets their sign-in status.

Can I exempt certain users from the Microsoft 365 MFA requirement?

Yes, if you are utilizing Microsoft Entra Conditional Access policies, administrators can specifically exclude certain users, groups, or emergency access 'break-glass' accounts from MFA requirements. However, if 'Security Defaults' are enabled, exemptions cannot be made, and all users must use MFA.

Do end users need to download a specific app to set up MFA?

Microsoft strongly recommends users download the Microsoft Authenticator app for secure push notifications and time-based codes. However, administrators can configure the tenant's Authentication Methods policy to allow alternatives such as SMS, voice calls, or FIDO2 security keys.