What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Microsoft began a phased rollout of mandatory multifactor authentication (MFA) for Azure administration in July 2024; it did not switch on MFA for every Azure access method on that date. Portal enforcement followed first. A separate rollout for Azure CLI, PowerShell, SDKs, REST APIs and infrastructure-as-code tools began on October 1, 2025. As of August 2026, the July 1, 2026 deadline to postpone that second phase has passed.
What Microsoft’s Azure MFA requirement covers
The requirement applies to users signing in to Microsoft management surfaces and making Azure resource-management requests. That includes administration through the Azure portal and, in Phase 2, requests to Azure Resource Manager (ARM), such as operations on subscriptions, virtual machines and storage accounts. Microsoft’s mandatory MFA guidance describes the phases, covered tools and exceptions.
It is not a rule that every person using a website or app hosted on Azure must complete Microsoft MFA. Hosting an application on Azure does not, by itself, put its customers under this Azure administration requirement. Nor should it be confused with every sign-in to Microsoft Entra ID or Microsoft Graph: the relevant question is whether the identity is accessing a covered management surface or performing an in-scope Azure resource operation.
How the rollout unfolded
| Date | What changed |
|---|---|
| May 14, 2024 | Microsoft announced a gradual rollout of MFA requirements for Azure users. See the original announcement. |
| July 2024 | The first gradual rollout began, initially focused on Azure portal sign-ins. It was not a simultaneous cutover for every Azure client. |
| June 27, 2024 | Microsoft clarified that the initial phase covered the Azure portal; command-line and infrastructure-as-code access would come later. See its rollout update. |
| October 2024 | Phase 1’s scope included Azure portal, Microsoft Entra admin center and Microsoft Intune admin center sign-ins. |
| February 2025 | A separate gradual MFA rollout began for Microsoft 365 admin center sign-ins. |
| March 2025 | Microsoft reported that Azure portal enforcement had reached 100% of Azure tenants. That milestone concerned Phase 1 portal enforcement, not every Phase 2 client. |
| October 1, 2025 | Phase 2 began rolling out for resource-management operations through Azure CLI, Azure PowerShell, the Azure mobile app, SDKs, REST APIs and IaC tools. See the Phase 2 announcement. |
| July 1, 2026 | The final date Microsoft set for eligible tenants to postpone Phase 2 passed. |
| August 2026 | The practical concern for many engineering teams is whether user-based scripts, pipelines and other ARM clients can satisfy enforcement—not whether July 2024 is still a future start date. |
Which users and tools are affected?
Phase 1: administration through Microsoft portals
Phase 1 covers sign-ins to the Azure portal, Microsoft Entra admin center and Microsoft Intune admin center. Microsoft describes Phase 1 as covering Create, Read, Update and Delete (CRUD) activity. The Microsoft 365 admin center had its own rollout beginning in February 2025.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Phase 2: ARM clients and resource changes
Phase 2 covers resource-management requests made through Azure CLI, Azure PowerShell, the Azure mobile app, SDK client libraries, REST API calls to ARM and IaC tools such as Terraform when they use ARM. For this phase, Microsoft distinguishes operation types: Create, Update and Delete require MFA; Read operations generally do not face the same requirement. A read-only test therefore does not establish that a deployment or other resource-changing workflow will work.
The policy follows the identity and operation, not just a job title. Global Administrators and subscription administrators are in scope, but so may be developers, contractors, delegated administrators, B2B guest administrators and engineers who use personal accounts with CLI, PowerShell or Terraform. A user-based service account is still a user identity; calling it a service account does not make it exempt.
What is not automatically covered
- People using an Azure-hosted application: They are not automatically subject to this Azure management requirement merely because the application runs on Azure. The application’s own sign-in policy is a separate matter.
- Managed identities and service principals: These workload identities do not use interactive user MFA in the same way. They are generally the appropriate direction for unattended automation.
- User identities in automation: These remain within scope. A script that signs in as an ordinary user can encounter MFA enforcement, even if it runs unattended.
- Read-only Phase 2 operations: They generally do not have the same MFA requirement as create, update and delete operations. Confirm the exact client and operation rather than assuming all API calls are treated alike.
- Sovereign clouds: Microsoft’s current documentation says mandatory enforcement applies to the public Azure cloud, not Azure Government or other sovereign clouds. Check the current Microsoft guidance for the cloud your tenant uses.
B2B guest administrators are covered. Their MFA may be satisfied by the home or partner tenant if cross-tenant access settings pass the relevant MFA claim appropriately; otherwise the guest may be prompted to satisfy it in the resource tenant.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Prepare users, tools and automation
1. Find every identity that makes ARM requests
Inventory portal administrators, CLI and PowerShell users, Terraform and other IaC pipelines, SDK and REST clients, scheduled jobs, build agents, self-hosted runners, B2B administrators and emergency-access accounts. Search scripts and pipeline configuration for user-based credentials, including AZURE_USERNAME and AZURE_PASSWORD. The key question is: which identities make requests to ARM, and are any ordinary Microsoft Entra users?
2. Choose an MFA policy approach
Use Security Defaults when you need a straightforward baseline and do not have Conditional Access licensing or a requirement for detailed policy control. Microsoft recommends Security Defaults for organizations without Conditional Access capability. See Configure Security Defaults.
Use Conditional Access when you need tailored targeting, device, location or risk conditions, authentication strengths, or carefully managed exclusions. Conditional Access requires Microsoft Entra ID P1 or P2 licensing. It offers more control, but a misconfigured policy can cause unexpected prompts or lockout. Neither approach is a substitute for testing the actual admin and automation flows.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Approach | Best fit | Trade-off |
|---|---|---|
| Security Defaults | Organizations needing a simple baseline without Conditional Access licensing | Limited customization of conditions, exclusions and authentication requirements |
| Conditional Access | Licensed organizations needing granular targeting, authentication strengths or tailored controls | Requires Entra ID P1 or P2; policies require careful design and testing |
| Microsoft-enforced requirement alone | A baseline when a tenant has not configured its own MFA policy | Not a complete identity-security design; a breakage may become visible only during a resource-changing operation |
| Third-party MFA | Organizations with a broader external identity strategy or a specific integration need | Adds integration and support dependencies; legacy Conditional Access Custom Controls do not satisfy this requirement |
Microsoft-native options may be sufficient; purchasing a third-party MFA product is not inherently required. If using an external provider, verify that it is integrated through a supported external authentication method. Microsoft says deprecated Conditional Access Custom Controls do not satisfy the requirement.
3. Register and test user authentication methods
Confirm that affected users have registered a supported method, such as Microsoft Authenticator or, where suitable, a FIDO2 security key or passkey, and have an approved recovery method. Security Defaults uses number matching in Authenticator. A method that satisfies MFA is not necessarily phishing-resistant: push approval and SMS are not equivalent to a passkey or FIDO2 key for privileged users. The Microsoft registration verification guidance explains how to check mandatory MFA setup.
4. Update tools and remove password-based user flows
Microsoft’s current compatibility guidance recommends Azure CLI 2.76 or later and Azure PowerShell 14.3 or later. Treat these as the versions cited in that guidance, not permanent minimums; check the current documentation when updating your environment.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Replace unattended sign-in patterns built around a username and password. Microsoft flags username/password use in Azure identity libraries, including DefaultAzureCredential configured with username and password environment variables, EnvironmentCredential configured the same way, and UsernamePasswordCredential. For workloads, use a suitable noninteractive identity such as a managed identity, service principal or federated workload identity. Choose the credential design that fits the platform and secure its permissions and lifecycle.
5. Test the operations that matter
- Sign in interactively to the Azure portal and other relevant admin centers.
- Test fresh Azure CLI and PowerShell logins with affected users.
- Run Terraform plan and apply, and test the deployment path used by your other IaC tools.
- Test SDK and REST clients, including resource create, update and delete operations—not only reads.
- Exercise scheduled jobs, build agents, self-hosted runners and any network-restricted administrative workflow.
- Test B2B administration and emergency-access recovery procedures.
6. Check enforcement status and logs
As a Global Administrator, sign in to the Azure portal and open https://aka.ms/managemfaforazure to check the Phase 1 status banner. For Phase 2, open https://aka.ms/postponePhase2MFA and check its status banner. Entra sign-in logs can help identify which application generated an MFA requirement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot MFA failures
CLI or PowerShell fails after sign-in
Check for an outdated client, a cached token that predates the MFA requirement, an unregistered method, or a policy that the client’s authentication flow cannot satisfy. Update the tool, sign out and perform a fresh interactive login, confirm registration, inspect Entra sign-in logs, then test the exact resource-changing operation. For unattended work, move away from a user login to a workload identity.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →A claims challenge appears but no MFA prompt
Some clients can handle a claims challenge and display an interactive prompt; others return an error because they cannot complete an interactive step. This can affect older SDKs, custom REST clients, IaC runners and username/password credential flows. Update the client or redesign the workload authentication; suppressing the MFA requirement is not a sound fix.
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
A user already has Conditional Access but is still prompted
Check whether the existing policy targets the relevant cloud application and whether the user has registered the authentication method it requires. Also verify the tenant being accessed, B2B MFA claim handling and whether a cached session is older than the policy. If an external MFA provider is involved, confirm that the integration uses a supported method rather than deprecated Custom Controls.
A service account stops working
If the account is an ordinary Entra user, it can be subject to enforcement. Migrate the job to a managed identity, service principal or federated workload identity where supported; do not create another password-only user as a workaround.
Emergency access and support escalation
Design emergency access so a failure in the normal MFA path does not eliminate every recovery route. Microsoft’s guidance should inform the number and protection of emergency accounts. Keep credentials protected separately, alert on use, test sign-in periodically and document recovery. Any Conditional Access exclusion should be narrow, monitored and reviewed, not treated as a broad bypass.
Free tools Windows power users keep installed
One-click scans. No signup required.
Microsoft provided postponement processes for tenants facing technical barriers, but not a general opt-out. The stated Phase 1 postponement deadline was September 30, 2025, and Phase 2’s was July 1, 2026; both have passed. If an enforcement problem remains, consult Microsoft’s current support guidance and contact Microsoft Support where necessary rather than assuming the tenant can still defer rollout.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




