Our IT Expertise: Services & Guides for SMBs
12 September 2026
The 3-2-1 Backup Rule: Is Your Data Really Protected?
6 October 2026Since 2024, Microsoft has been making multifactor authentication (MFA) mandatory for part of its administration tools. Many business owners found out through an email from Microsoft or from an administrator blocked at sign-in. The next question is always the same: does this now protect all our accounts? The short answer is no. Here is what Microsoft requires, what remains up to you, and where to start.
What Microsoft already requires
Microsoft is rolling out mandatory MFA in two phases (Microsoft Learn).
- Phase 1, since October 2024: MFA is required to sign in to the Azure portal, the Microsoft Entra admin center and the Intune admin center. The Microsoft 365 admin center has been covered gradually since February 2025.
- Phase 2, since October 1, 2025: MFA is required to create, update or delete resources with Azure CLI, Azure PowerShell, the Azure mobile app, infrastructure as code tools, the REST API and the Azure SDKs.
Microsoft states there is no way to opt out, and the possible postponements have expired. Emergency ("break glass") accounts are in scope too: Microsoft recommends a FIDO2 passkey or certificate-based authentication for them.
What is not covered
This is where many SMBs get it wrong. The requirement targets administration tools. Microsoft says it plainly: users are not required to use MFA for other applications, websites or services hosted on Azure (Microsoft Learn).
In other words, Microsoft’s requirement does not, on its own, protect your accountant’s mailbox, or the employee who signs in to the Microsoft 365 portal. Those accounts are protected by MFA only if your tenant requires it, through security defaults or Conditional Access policies.
Why it matters: Microsoft states that MFA can block more than 99.2% of account compromise attacks (Microsoft Learn). Yet a single account without MFA is enough to open the door.
Security defaults: the minimum, with no extra licence
Microsoft Entra offers security defaults, with no additional licence (Microsoft Learn). Once turned on, they:
- require every user to register for MFA;
- require MFA from administrators at every sign-in;
- ask users for MFA when Microsoft deems it necessary;
- block legacy authentication, such as IMAP, POP3 and SMTP with older mail clients.
That last point matters: according to the same page, most compromising sign-in attempts today come from legacy authentication. Recently created tenants often have these settings on from the start. An older tenant, or one where someone turned them off to fix a printer or a scanner, may well not have them.
Businesses that need finer rules (requiring MFA based on location or device, for example) use Conditional Access, which requires a Microsoft Entra ID P1 licence or higher.
Not all MFA is equal
The Canadian Centre for Cyber Security recommends requiring MFA from users and administrators alike on cloud and internet-connected services, especially where sensitive data is involved (ITSAP.30.030). It also notes that MFA can be bypassed, for example when a tired employee approves a request they did not make, or when a session token is stolen. Hence its recommendation to favour phishing-resistant technologies, such as FIDO keys.
In practice, that means:
- avoiding text message codes when an authenticator app or a key is possible;
- training employees to refuse a sign-in request they did not start;
- keeping hardware keys for the most sensitive accounts, starting with administrators.
Where to start in an SMB
- Check your tenant: are security defaults on, or do Conditional Access policies replace them?
- List the accounts without MFA, including shared accounts and former employees’ accounts.
- Block legacy authentication and replace the devices that depend on it.
- Protect administrator accounts with the strongest method you can use, and keep at least one emergency account protected by a FIDO2 key.
- Review these settings regularly: a change made to fix a device can reopen a door without anyone remembering it.
That last point is the one most often forgotten. MPJM’s monthly security review gives you a written report every month of what happened on your network, and what changed. For the cloud side, see also our Cloud and Microsoft 365 page.
What now?
Not sure whether every account in your business is protected by MFA? Ask for MPJM’s free network analysis.



