Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
Azure AD

Easiest Controlled Way to Require MFA for Admins with Microsoft Entra Conditional Access

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The easiest supportable method is to create the built-in Microsoft Entra Conditional Access policy for administrative roles, deliberately exclude and monitor emergency-access accounts, run the policy in Report-only mode, inspect sign-in results, and then switch it to On. Azure Active Directory is now called Microsoft Entra ID; the older “Azure AD Conditional Access” wording refers to the same service.

Choose the right MFA method first

Approach Best fit Trade-off
Conditional Access Admin-only targeting, resource scope, pilots, exclusions and authentication strengths Requires Microsoft Entra ID P1 or P2 (or an entitlement that includes it)
Security Defaults Tenants without Conditional Access licensing that need a quick baseline Much less targeting and customization
Per-user MFA Legacy fallback where neither option is available Microsoft advises not combining it with Conditional Access or Security Defaults

Conditional Access is the recommended controlled option when granular policy logic is required. See Microsoft’s Conditional Access documentation and its guidance on MFA user states at learn.microsoft.com.

Before you create the policy

Verify licensing and permissions

  • Confirm Microsoft Entra ID P1 or P2, either directly or through a qualifying Microsoft 365 or Enterprise Mobility + Security entitlement. Verify the actual subscription and user assignment rather than relying on a suite name.
  • Use the Conditional Access Administrator role, or another explicitly delegated role that can manage policies, instead of routinely using a permanent Global Administrator account. Microsoft lists this role in its MFA tutorial: tutorial-enable-azure-mfa.
  • Make sure administrators can register a usable authentication method before enforcement.

Prepare recovery and testing

  • Maintain at least two cloud-only emergency-access (break-glass) accounts. Exclude them deliberately from policies that could lock out every administrator, monitor any use, store credentials securely, and test the recovery procedure.
  • Prepare a non-emergency test administrator or controlled pilot group.
  • Inventory automation, service principals, managed identities, CLI and PowerShell workflows. Interactive administrator MFA does not authenticate noninteractive workloads.

A template may exclude the policy author by default in some portal versions. Treat that as a temporary safety measure to review, not as a permanent protection gap or a substitute for emergency accounts.

Create the administrator MFA Conditional Access policy

Portal labels change, but the current logical path is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Open the Microsoft Entra admin center.
  2. Go to Entra ID > Conditional Access > Policies.
  3. Select Create new policy, or open the policy-template workflow if your tenant displays it.
  4. Choose the administrator template, commonly labelled Require multifactor authentication for admins or Require MFA for administrators.
  5. Name it clearly, such as CA-ADMIN-001-Require-MFA.
  6. Under Users or workload identities, confirm that the included directory roles are the intended privileged roles. Common examples are Global Administrator, Privileged Role Administrator, Security Administrator, Conditional Access Administrator, Exchange Administrator, SharePoint Administrator, Intune Administrator, User Administrator and Authentication Administrator. Review billing and other high-impact roles for your tenant.
  7. Review exclusions for emergency-access accounts and any pilot design. Do not assume every custom role is included automatically.
  8. Under Target resources, select the scope that matches the risk decision: Microsoft Admin Portals, Windows Azure Service Management API, selected cloud resources, or All cloud resources. Portal-only coverage is narrower than protecting management APIs or every application.
  9. Under Access controls > Grant, select Require multifactor authentication for the fastest broad-compatible baseline. If your administrators have registered stronger methods, choose an authentication strength instead.
  10. Set Enable policy to Report-only, then create the policy.

Microsoft’s administrator MFA guidance uses Microsoft Admin Portals and the Windows Azure Service Management API as important targets: mandatory multifactor authentication. Its older administrator policy reference is at policy-old-require-mfa-admin.

Understand which identities the policy protects

Microsoft Entra directory roles are not the same population as Azure RBAC roles. An Azure subscription Owner or Contributor may have powerful resource permissions without holding a directory administrator role, while a service principal or managed identity is not an interactive user. Review those identities separately and apply workload-identity controls, credential rotation or workload federation as appropriate. A template aimed at directory roles cannot automatically solve every Azure RBAC, automation or custom-role exposure.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Validate in Report-only mode

  1. Open Conditional Access > Policies and confirm the new policy is still Report-only.
  2. Use a fresh private-browser session to sign in as a test administrator to the Azure portal, Microsoft Entra admin center, Intune admin center and any other targeted resource.
  3. Open Entra ID > Monitoring > Sign-in logs, select each event, and inspect the Conditional Access and Report-only details.
  4. Confirm the expected role and resource matched, the result indicates that MFA or the selected strength would be required, and no emergency-access account was unexpectedly included.
  5. Check client type and noninteractive events for automation or legacy protocols that could be affected.

Use the sign-in-log workflow described in Microsoft’s tutorial at tutorial-enable-azure-mfa. Resolve unexpected matches or exclusions before enforcement.

Turn enforcement on safely

  1. Reopen the validated policy and change Enable policy from Report-only to On.
  2. Save, then test again with a non-emergency administrator in a fresh private session.
  3. Confirm the MFA challenge or authentication-strength requirement succeeds.
  4. Continue watching sign-in failures and emergency-account alerts.

Existing browser sessions are not guaranteed to be challenged immediately. Token lifetime and reauthentication behavior affect timing; test a new session rather than treating a still-open session as proof that enforcement failed. An already signed-in user may be asked to authenticate again and can see AADSTS50076, which indicates that MFA is required because of an administrative configuration change. Do not promise a fixed propagation interval.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Generic MFA or phishing-resistant authentication strength?

Require multifactor authentication

This is the quickest deployment and works with the broadest range of registered methods, but it does not guarantee phishing resistance. It may allow methods your privileged-account standard considers too weak.

Authentication strength

Authentication strengths specify acceptable method combinations and can separate ordinary users from privileged administrators. They require registration planning and can fail for an administrator who has only SMS or voice configured. Microsoft documents grant controls at concept-conditional-access-grant.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Phishing-resistant MFA

For mature privileged-access protection, use FIDO2 security keys, supported passkeys, Windows Hello for Business or certificate-based authentication. Microsoft provides an administrator policy for this at policy-admin-phish-resistant-mfa. SMS and voice should not be treated as the preferred protection for highly privileged accounts. Method capabilities are described at concept-mfa-howitworks.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

MFA registration is a separate control

A sign-in policy requiring MFA does not prove that every administrator has registered an approved method. Use a separate security-information registration policy, and consider Temporary Access Pass onboarding where configured. Microsoft’s registration guidance is at policy-all-users-security-info-registration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Troubleshoot common failures

The administrator cannot complete MFA

  • Try another registered method or re-register Authenticator.
  • Use a Temporary Access Pass, FIDO2 key or passkey if your tenant supports it.
  • Have an Authentication Administrator update the method.
  • Use the documented emergency-access process; do not permanently exempt the user as a casual workaround.

Authenticator request times out

Retry or send another request, check device connectivity and verify that the correct account is enrolled. Wording such as “We didn’t hear from you” can vary by client and tenant.

Legacy authentication or scripts fail

Legacy authentication generally cannot satisfy modern MFA. Test a separate policy to block legacy authentication after application compatibility review. Update Azure CLI and Azure PowerShell clients before testing claims challenges; Microsoft’s version-specific guidance currently cites Azure CLI 2.76 and Azure PowerShell 14.3 or later at concept-mandatory-multifactor-authentication. Replace user-based automation with service principals, managed identities or federated credentials where appropriate.

Rollback is required

Use an emergency-access account to reach the admin center, set the policy back to Report-only or exclude the affected test scope, correct registration or resource targeting, and repeat validation before re-enabling it. Keep a named owner for this procedure.

Security Defaults and per-user MFA alternatives

Use Security Defaults when the tenant lacks Conditional Access licensing and a broad baseline is acceptable. They cannot provide the same admin-only, application-specific, location, device, risk or authentication-strength logic; see Microsoft’s comparison guidance. Per-user MFA is a legacy fallback and should not be enabled alongside Conditional Access or Security Defaults; see howto-mfa-userstates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft may also impose MFA requirements for Azure, Microsoft Entra and Intune administrative access. Tenant policy remains valuable because it gives you deliberate role/resource scope, report-only testing, exclusions and sign-in-log visibility.

Deployment checklist

  • Entra ID P1/P2 entitlement verified.
  • Conditional Access Administrator or delegated operator assigned.
  • Two emergency-access accounts tested, excluded and monitored.
  • Administrator methods registered.
  • Directory roles, custom roles, Azure RBAC and workload identities inventoried.
  • Target resources chosen deliberately.
  • Policy tested in Report-only mode with sign-in logs.
  • CLI, PowerShell, legacy clients and automation tested.
  • Policy switched to On and verified in a fresh session.
  • Monitoring, alerting and rollback ownership documented.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.