Why Security Defaults MFA Doesn't Show in Microsoft 365 List
Question details
Users want to know why accounts required to use multifactor authentication by Security Defaults are not marked as enabled on the traditional Microsoft 365 per-user MFA page.

- Product
- Microsoft 365 / Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Administrators checking the multifactor authentication (MFA) status and registration for users within a Microsoft 365 tenant.
- Observed behavior
- Users who are prompted to register for MFA due to Security Defaults do not show up as 'Enabled' or 'Enforced' in the legacy per-user MFA status list.
Ensure you have Global Administrator or Security Administrator access to the Microsoft Entra admin center to view tenant properties and user authentication methods.
Manage MFA via Security Defaults in Microsoft Entra ID
Use the Microsoft Entra admin center to verify if Security Defaults are enabled, as this tenant-wide setting replaces the legacy per-user MFA configurations.
Security Defaults and legacy per-user MFA are entirely separate Microsoft identity features. When Security Defaults are active, they require users to register for multifactor authentication globally without marking them as enabled in the traditional Microsoft 365 per-user MFA page.
Sign in to the Microsoft Entra admin center using your global administrator credentials.
In the left navigation pane, expand 'Microsoft Entra ID', select 'Overview', and then click on 'Properties'.
At the bottom of the Properties page, click on 'Manage security defaults' to view or change your tenant's MFA enforcement settings.

Check User MFA Registration Status Directly
Since the legacy MFA list is inaccurate when Security Defaults are used, review user registration status directly through the Users blade in Entra ID.
Simplify Your Workflow with WPS Office
Dealing with complex Microsoft 365 administration and MFA configurations can be time-consuming. If you are looking for a straightforward, lightweight, and highly compatible productivity suite for your team, consider WPS Office as a completely free alternative to Microsoft Office.
- 1. Download the Installer: Visit the official WPS website and download the free WPS Office installer.
- 2. Install the Software: Run the setup file and follow the quick installation prompts on your screen.
- 3. Start Creating Documents: Open WPS Office to immediately view, edit, or create documents compatible with Microsoft formats.

Frequently Asked Questions
What is the difference between Security Defaults and legacy per-user MFA?
Security Defaults is a tenant-wide setting that enforces modern authentication and MFA for all users automatically. Legacy per-user MFA requires administrators to manually enable or enforce MFA for each individual account.
Why does a user prompt for MFA but show as 'Disabled' in the MFA portal?
If Security Defaults or Conditional Access policies are active, they trigger the MFA requirement at sign-in. Because the legacy MFA portal only tracks manually assigned per-user MFA, it will incorrectly show these users as 'Disabled' even though they are protected.
Where can I view all users' MFA registration status if the legacy portal is inaccurate?
You can view accurate registration data in the Microsoft Entra admin center by navigating to 'Users > All users' and checking the authentication methods for each user, or by reviewing the 'Registered users by authentication method' usage report.




