Microsoft is rolling out a major security upgrade for Azure: starting in 2024, multifactor authentication (MFA) will become mandatory for all Azure sign-ins. This initiative highlights Microsoft’s dedication to enhancing security for its users.
The MFA mandate will cover key platforms like the Azure Portal, Microsoft Entra Admin Center, and Microsoft Intune Admin Center, with enforcement beginning in the latter half of 2024. Additionally, tools such as Azure CLI, Azure PowerShell, the Azure Mobile App, and Infrastructure as Code (IaC) solutions will be included in early 2025.
The requirement targets all users performing Create, Read, Update, or Delete (CRUD) operations on these platforms.
However, end users accessing applications or services hosted on Azure without logging into these specific platforms won’t need to use MFA. Workload identities, including managed identities and service principals, are exempt from this requirement. Microsoft has clarified that emergency access accounts will need to comply with MFA, advising the use of passkey (FIDO2) or certificate-based authentication.
Scope of Enforcement:
The MFA requirement applies to the following key platforms and accounts:
- Azure Portal: Enforcement starts in the second half of 2024.
- Microsoft Entra Admin Center: Enforcement begins in the second half of 2024.
- Microsoft Intune Admin Center: Enforcement starts in the second half of 2024.
- Azure CLI, Azure PowerShell, Azure Mobile App, and IaC Tools: Enforcement starts in early 2025.
Enforcement Phases:
Microsoft’s rollout of MFA enforcement will happen in two stages:
- Phase 1 (Second Half of 2024): MFA will be enforced for the Azure Portal, Microsoft Entra Admin Center, and Microsoft Intune Admin Center.
- Phase 2 (Early 2025): MFA will be enforced for Azure CLI, Azure PowerShell, the Azure Mobile App, and IaC tools.
To facilitate a smooth transition, Microsoft will alert Global Administrators through various channels, including email, service health notifications, portal messages, and the Microsoft 365 message center.
Preparing for Multifactor Authentication:
Administrators should prepare by enabling MFA for all users accessing admin portals and Azure services. This includes becoming familiar with Microsoft Entra MFA, enabling users for multiple MFA methods, and using Conditional Access policies and security defaults.
| Preparation for MFA | Details |
|---|---|
| Requirement | All users accessing admin portals and Azure clients must be set up to use MFA. |
| Resources for Setup | – Learn about Microsoft Entra MFA and available authentication methods. |
| – Enable users for one or more MFA methods. | |
| – Prefer more secure, phishing-resistant MFA methods. | |
| Options for Setting Up MFA | – Use Conditional Access policies (start in report-only mode) targeting all users and Microsoft administration portals. |
| – Require MFA or use authentication strengths for granular control. | |
| – Enable Security defaults. | |
| Configuration and Deployment | – Secure sign-in events with Microsoft Entra MFA. |
| – Plan a Microsoft Entra MFA deployment. | |
| – Learn about phishing-resistant MFA methods. | |
| – Use the MFA wizard for Microsoft Entra ID. | |
| Identifying Users’ MFA Status | – Use PowerShell to export a list of users and their authentication methods. |
| – Use the Multifactor Authentication Gaps workbook. | |
| Application IDs for Queries | – Azure Portal: c44b4083-3bb0-49c1-b47d-974e53cbdf3c |
| – Azure CLI: 04b07795-8ddb-461a-bbee-02f9e1bf7b46 | |
| – Azure PowerShell: 1950a258-227b-4e31-a9cf-717495945fc2 | |
| – Azure Mobile App: 0c1307d4-29d6-4389-a11c-5cbe7f65d7fa |
Support for external MFA solutions is currently in preview, allowing for integration with federated Identity Providers like Active Directory Federation Services.
Recognizing that some customers may require more time to adapt, Microsoft is offering a grace period. From August 15, 2024, to October 15, 2024, Global Administrators can defer the enforcement start date to March 15, 2025, by modifying settings in the Azure portal.
Despite this flexibility, Microsoft strongly advises early adoption of MFA to protect cloud resources from potential security threats.



