How do I turn on MFA in Microsoft 365?

Turn on security defaults in the Microsoft Entra admin center, under Entra ID, Overview, Properties. Microsoft then has every user register for two-step sign-in, usually with the Authenticator app, and requires it for admins. Staff are asked at their next sign-in. Keep a dated screenshot of security defaults showing Enabled, plus the list of who has registered.
Security defaults is one Microsoft 365 switch that makes everyone set up two-step sign-in.
Check if you already have it
Sign in at entra.microsoft.com, open Entra ID, Overview, Properties, and click Manage security defaults. If it says Enabled, it's on. Then check Protection, Authentication methods, User registration details to see that everyone has registered.
How to set it up
First, write down anything that signs in to email on its own, like a scanner that emails documents, a booking tool or an old mail app on someone's phone. Those can stop working once security defaults is on, so plan to update them. Give each shared mailbox an owner.
Require two-step sign-in for everyone in Microsoft 365
Microsoft 365, needs a Microsoft 365 Global Administrator sign-in
- Sign in at
entra.microsoft.comwith a Global Administrator account. - In the left menu open Entra ID (some screens still say Identity), then Overview, then the Properties tab.
- Click Manage security defaults.
- Set Security defaults to Enabled and click Save.
- Tell everyone that the next time they sign in, Microsoft will ask them to set up the Microsoft Authenticator app. Ask them to do it at that first sign-in rather than putting it off.
How to show it's true: Screenshot the security defaults panel showing Enabled. Once everyone has enrolled, screenshot Protection, then Authentication methods, then User registration details, which lists who has set up two-step sign-in.
- Manage security defaults is greyed out or says you use Conditional Access: your tenant already uses Conditional Access policies. This needs a tech to set up a policy that requires two-step sign-in for all users.
- An old email app keeps asking for the password: remove the account from the app and add it again, or switch to the Outlook app.
Then cut down your admin list:
Protect your Microsoft 365 admin accounts with two-step sign-in
Microsoft 365, needs a Microsoft 365 Global Administrator sign-in
- Sign in at
admin.microsoft.comwith a Global Administrator account. - Go to Roles, then Role assignments, and open Global Administrator. Write down who is on the list.
- Remove anyone who doesn't need it. Keep two at most.
- Turn on security defaults (see the two-step sign-in steps for Microsoft 365). With them on, every admin must use two-step sign-in each time they sign in.
- Make sure each admin has set up the Microsoft Authenticator app.
How to show it's true: Screenshot the Global Administrator assignment list and the security defaults panel showing Enabled.
- Your tenant uses Conditional Access instead of security defaults: a tech should add a policy that requires two-step sign-in for all admin roles.
How to show it's done
Keep three dated screenshots: security defaults showing Enabled, the User registration details list once everyone has registered, and the Global Administrator list. Save them in your proof folder.
Common questions
Does everyone get asked for a code at every sign-in?
Microsoft says everyone must register and admins must use it each time. It doesn't promise a prompt at every sign-in for everyone else. If your form asks whether MFA is "always" on, have a tech check how your account prompts people.
The security defaults option is greyed out. What now?
Your account probably uses Conditional Access already. A tech needs to add a rule that makes everyone use two-step sign-in.
Using Google Workspace instead?
Sources
- Microsoft Learn: Security defaults in Microsoft Entra IDlearn.microsoft.com
- Microsoft Learn: Protect your Microsoft 365 user accountslearn.microsoft.com
- Microsoft Learn: About admin roles in the Microsoft 365 admin centerlearn.microsoft.com