How to turn off MFA for the user in organization

DmitryP 0 Reputation points
2025-02-21T10:28:13.93+00:00

Hello .

How can the MFA policy be disabled? Currently, there is a default MFA policy in Conditional Access that manages MFA for users. The question is: how can it be fully disabled? I have turned it off and added an exclusion for a group of users, but MFA is still being required for the user during sign-in.

Microsoft Entra Private Access
Microsoft Entra Private Access
Microsoft Entra Private Access provides secure and deep identity-aware, Zero Trust network access to all private apps and resources.
85 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Sanoop M 1,000 Reputation points Microsoft Vendor
    2025-02-21T20:05:47.0133333+00:00

    Hello @DmitryP,

    Thank you for posting your query on Microsoft Q&A.

    I understand that there is a default MFA policy in Conditional Access that manages MFA for users in your tenant. The question is: how can it be fully disabled? You have turned it off and added an exclusion for a group of users, but MFA is still being required for the user during sign-in.

    Please note that even though if you have turned off the CA policy and also excluded the user from the CA policy, there are multiple sources through which MFA can be triggered for the users to sign in to the application. Below are the different sources of MFA.

    1.Per-User MFA.

    2.Conditional Access policies.

    3.Security Defaults.

    4.Identity Protection(MFA registration policy).

    1.Per-User MFA

    Please check if the Per-User MFA is enabled or not for the user by following the below mentioned steps.

    View the status for a user

    The per-user MFA administration experience in the Microsoft Entra admin center is recently improved. To view and manage user states, complete the following steps:

    1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
    2. Browse to Identity > Users > All users.
    3. Select a user account, and then select Per-user MFA.
    4. Please refer to the below Screenshot for your reference.

    User's image

    Search for the affected user and check the Per-user MFA status. If it is enabled, please select Disable MFA as shown in the below Screenshot for your reference.

    User's image

    2.Conditional Access policies

    Please note that even though if you have disabled the default MFA based CA policy in your tenant, there might be other CA policies in your tenant where the affected user is part of through which the user is getting prompted to complete MFA.

    You can verify whether any other CA policy is getting applied to complete MFA by following the below mentioned steps.

    To view the sign-in logs from the Microsoft Entra admin center:

    1. Sign in to the Microsoft Entra admin center as at least a Reports Reader.
    2. Go to Users -> All Users -> Select the affected user and select Sign-in logs and check for the sign ins where the Authentication requirement is showing as Multifactor Authentication. Please refer to the below Screenshot for your reference. User's image 3.If any of the sign ins where the Authentication requirement is showing as Multifactor Authentication, please select that sign in and navigate to Conditional Access tab to check which CA is policy is getting applied for that sign in. Please refer to the below Screenshot for your reference. User's image

    3. Security Defaults

    Please note that if there is no CA policy enabled in your tenant, then please check if the Security Defaults is enabled in your tenant by following the below mentioned steps.

    1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
    2. Browse to Identity > Overview > Properties.
    3. Select Manage security defaults.
    4. Check if Security Defaults is enabled or not.

    Please note that this Security Defaults is tenant wide settings and it will be applicable to all the users in your tenant.

    If Security Defaults is enabled in your tenant, then all the users in your tenant are getting MFA through Security Defaults.

    For additional details, please refer to the below document for your reference.

    Providing a default level of security in Microsoft Entra ID - Microsoft Entra | Microsoft Learn

    4.Identity Protection(Multifactor Authentication Registration policy)

    Please check if you have enabled Multi factor Authentication Registration policy from Identity Protection by following the below mentioned steps.

    1. Sign in to the Microsoft Entra admin center as at least a Security Administrator.
    2. Browse to Protection > Identity Protection > Multifactor authentication registration policy.
    3. Please check whether the affected user is part of that policy and also check whether the policy is enabled or not from Policy enforcement section.

    For additional details, please refer to the below document for your reference.

    Configure the MFA registration policy - Microsoft Entra ID Protection | Microsoft Learn

    As I have mentioned above, please check through what source of MFA user is getting prompted to complete MFA and disable that particular source of MFA accordingly.

    I hope this above information provided is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.