logo
search
MFA Security Issues

Why Security Defaults MFA Doesn't Show in Microsoft 365 List

Olivia MillerOlivia Miller Sep 28, 2026 869 views

Question details

Users want to know why accounts required to use multifactor authentication by Security Defaults are not marked as enabled on the traditional Microsoft 365 per-user MFA page.

Why Security Defaults MFA Doesn't Appear in the Microsoft 365 MFA List
Product
Microsoft 365 / Microsoft Entra ID
Device & OS
not provided
Scenario
Administrators checking the multifactor authentication (MFA) status and registration for users within a Microsoft 365 tenant.
Observed behavior
Users who are prompted to register for MFA due to Security Defaults do not show up as 'Enabled' or 'Enforced' in the legacy per-user MFA status list.
Before you start

Ensure you have Global Administrator or Security Administrator access to the Microsoft Entra admin center to view tenant properties and user authentication methods.

Solution 1Recommended

Manage MFA via Security Defaults in Microsoft Entra ID

Use the Microsoft Entra admin center to verify if Security Defaults are enabled, as this tenant-wide setting replaces the legacy per-user MFA configurations.

Security Defaults and legacy per-user MFA are entirely separate Microsoft identity features. When Security Defaults are active, they require users to register for multifactor authentication globally without marking them as enabled in the traditional Microsoft 365 per-user MFA page.

1
Access Microsoft Entra Admin Center

Sign in to the Microsoft Entra admin center using your global administrator credentials.

2
Navigate to Properties

In the left navigation pane, expand 'Microsoft Entra ID', select 'Overview', and then click on 'Properties'.

3
Manage Security Defaults

At the bottom of the Properties page, click on 'Manage security defaults' to view or change your tenant's MFA enforcement settings.

Manage MFA via Security Defaults in Microsoft Entra ID
Conditional Access Alternative: If you have Microsoft Entra ID P1 or P2 licenses, you might be using Conditional Access policies instead of Security Defaults to enforce MFA. Both will bypass the legacy MFA status page.
Free Microsoft Office alternative

Simplify Your Workflow with WPS Office

Dealing with complex Microsoft 365 administration and MFA configurations can be time-consuming. If you are looking for a straightforward, lightweight, and highly compatible productivity suite for your team, consider WPS Office as a completely free alternative to Microsoft Office.

  1. 1. Download the Installer: Visit the official WPS website and download the free WPS Office installer.
  2. 2. Install the Software: Run the setup file and follow the quick installation prompts on your screen.
  3. 3. Start Creating Documents: Open WPS Office to immediately view, edit, or create documents compatible with Microsoft formats.
Seamless compatibility with Microsoft Office formats including Word, Excel, and PowerPointLightweight installer that doesn't bog down system resourcesFamiliar user interface allowing a smooth transition with no steep learning curveFree to use for essential document creation and team productivity
microsoft office alternative - wps office

Frequently Asked Questions

What is the difference between Security Defaults and legacy per-user MFA?

Security Defaults is a tenant-wide setting that enforces modern authentication and MFA for all users automatically. Legacy per-user MFA requires administrators to manually enable or enforce MFA for each individual account.

Why does a user prompt for MFA but show as 'Disabled' in the MFA portal?

If Security Defaults or Conditional Access policies are active, they trigger the MFA requirement at sign-in. Because the legacy MFA portal only tracks manually assigned per-user MFA, it will incorrectly show these users as 'Disabled' even though they are protected.

Where can I view all users' MFA registration status if the legacy portal is inaccurate?

You can view accurate registration data in the Microsoft Entra admin center by navigating to 'Users > All users' and checking the authentication methods for each user, or by reviewing the 'Registered users by authentication method' usage report.