Skip to content

How to Enable MFA for Microsoft 365 Users

A step-by-step admin guide to rolling out multi-factor authentication across a Microsoft 365 tenant.

How to Enable MFA for Microsoft 365 Users
Table of Contents
  1. Before You Begin
  2. Step 1 โ€” Access Security Defaults or Conditional Access
  3. Step 2 โ€” Enable Security Defaults (simplest path)
  4. Step 3 โ€” Or configure a targeted Conditional Access policy
  5. Step 4 โ€” Communicate the change to users
  6. Frequently Asked Questions
  7. Do I need a paid license to enable MFA?
  8. What happens to a user who hasn’t registered MFA when the policy activates?
  9. Conclusion
  10. Related Articles

Multi-factor authentication is the single highest-impact security control most organizations can add โ€” it blocks the vast majority of account-takeover attempts even when a password is compromised.

Before You Begin

Info

Plan a rollout in phases rather than switching it on for everyone at once โ€” start with IT/admin accounts, then a pilot group, then the full organization, to catch any workflow issues early.

Step 1 โ€” Access Security Defaults or Conditional Access

Choose your approach

Small organizations can enable Security Defaults (a simple on/off MFA baseline) from the Entra admin center. Organizations needing more granular control should use Conditional Access policies instead, which requires Microsoft 365 Business Premium or an Entra ID P1/P2 license.

Step 2 โ€” Enable Security Defaults (simplest path)

Turn Security Defaults on

Set the toggle to Yes and save. This requires MFA registration for all users at next sign-in.

Step 3 โ€” Or configure a targeted Conditional Access policy

Step 4 โ€” Communicate the change to users

Notify users in advance

Send clear instructions on how to register the Microsoft Authenticator app before the policy takes effect, to avoid a flood of lockout support tickets on rollout day.

Tip

Frequently Asked Questions

Do I need a paid license to enable MFA?

Security Defaults are available on all Microsoft 365 plans at no extra cost. Conditional Access policies (for more granular control) require Entra ID P1 or higher, typically bundled into Business Premium or E3 licensing.

What happens to a user who hasn’t registered MFA when the policy activates?

They’ll be prompted to register the next time they sign in โ€” this is why advance communication (Step 4) matters, so it doesn’t look like an unexpected lockout.

Conclusion

For most small-to-medium organizations, Security Defaults is the fastest way to get baseline MFA protection in place; Conditional Access is worth the extra licensing once you need more granular exceptions and rules.

Microsoft 365 MFA Problems โ€” Troubleshooting Guide Related Article Microsoft 365 MFA Problems โ€” Troubleshooting Guide → Microsoft Authenticator Not Receiving Approval Requests Related Article Microsoft Authenticator Not Receiving Approval Requests →

Was this guide helpful?

Share it with someone who needs it, or subscribe for more practical IT tutorials.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get practical IT tutorials in your inbox

No spam โ€” just useful troubleshooting guides and tips.