Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Azure CLI

Microsoft Azure MFA Requirement: What Changed Since July 2024

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft began a phased rollout of mandatory multifactor authentication (MFA) for Azure administration in July 2024; it did not switch on MFA for every Azure access method on that date. Portal enforcement followed first. A separate rollout for Azure CLI, PowerShell, SDKs, REST APIs and infrastructure-as-code tools began on October 1, 2025. As of August 2026, the July 1, 2026 deadline to postpone that second phase has passed.

What Microsoft’s Azure MFA requirement covers

The requirement applies to users signing in to Microsoft management surfaces and making Azure resource-management requests. That includes administration through the Azure portal and, in Phase 2, requests to Azure Resource Manager (ARM), such as operations on subscriptions, virtual machines and storage accounts. Microsoft’s mandatory MFA guidance describes the phases, covered tools and exceptions.

It is not a rule that every person using a website or app hosted on Azure must complete Microsoft MFA. Hosting an application on Azure does not, by itself, put its customers under this Azure administration requirement. Nor should it be confused with every sign-in to Microsoft Entra ID or Microsoft Graph: the relevant question is whether the identity is accessing a covered management surface or performing an in-scope Azure resource operation.

How the rollout unfolded

Date What changed
May 14, 2024 Microsoft announced a gradual rollout of MFA requirements for Azure users. See the original announcement.
July 2024 The first gradual rollout began, initially focused on Azure portal sign-ins. It was not a simultaneous cutover for every Azure client.
June 27, 2024 Microsoft clarified that the initial phase covered the Azure portal; command-line and infrastructure-as-code access would come later. See its rollout update.
October 2024 Phase 1’s scope included Azure portal, Microsoft Entra admin center and Microsoft Intune admin center sign-ins.
February 2025 A separate gradual MFA rollout began for Microsoft 365 admin center sign-ins.
March 2025 Microsoft reported that Azure portal enforcement had reached 100% of Azure tenants. That milestone concerned Phase 1 portal enforcement, not every Phase 2 client.
October 1, 2025 Phase 2 began rolling out for resource-management operations through Azure CLI, Azure PowerShell, the Azure mobile app, SDKs, REST APIs and IaC tools. See the Phase 2 announcement.
July 1, 2026 The final date Microsoft set for eligible tenants to postpone Phase 2 passed.
August 2026 The practical concern for many engineering teams is whether user-based scripts, pipelines and other ARM clients can satisfy enforcement—not whether July 2024 is still a future start date.

Which users and tools are affected?

Phase 1: administration through Microsoft portals

Phase 1 covers sign-ins to the Azure portal, Microsoft Entra admin center and Microsoft Intune admin center. Microsoft describes Phase 1 as covering Create, Read, Update and Delete (CRUD) activity. The Microsoft 365 admin center had its own rollout beginning in February 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Phase 2: ARM clients and resource changes

Phase 2 covers resource-management requests made through Azure CLI, Azure PowerShell, the Azure mobile app, SDK client libraries, REST API calls to ARM and IaC tools such as Terraform when they use ARM. For this phase, Microsoft distinguishes operation types: Create, Update and Delete require MFA; Read operations generally do not face the same requirement. A read-only test therefore does not establish that a deployment or other resource-changing workflow will work.

The policy follows the identity and operation, not just a job title. Global Administrators and subscription administrators are in scope, but so may be developers, contractors, delegated administrators, B2B guest administrators and engineers who use personal accounts with CLI, PowerShell or Terraform. A user-based service account is still a user identity; calling it a service account does not make it exempt.

What is not automatically covered

  • People using an Azure-hosted application: They are not automatically subject to this Azure management requirement merely because the application runs on Azure. The application’s own sign-in policy is a separate matter.
  • Managed identities and service principals: These workload identities do not use interactive user MFA in the same way. They are generally the appropriate direction for unattended automation.
  • User identities in automation: These remain within scope. A script that signs in as an ordinary user can encounter MFA enforcement, even if it runs unattended.
  • Read-only Phase 2 operations: They generally do not have the same MFA requirement as create, update and delete operations. Confirm the exact client and operation rather than assuming all API calls are treated alike.
  • Sovereign clouds: Microsoft’s current documentation says mandatory enforcement applies to the public Azure cloud, not Azure Government or other sovereign clouds. Check the current Microsoft guidance for the cloud your tenant uses.

B2B guest administrators are covered. Their MFA may be satisfied by the home or partner tenant if cross-tenant access settings pass the relevant MFA claim appropriately; otherwise the guest may be prompted to satisfy it in the resource tenant.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Prepare users, tools and automation

1. Find every identity that makes ARM requests

Inventory portal administrators, CLI and PowerShell users, Terraform and other IaC pipelines, SDK and REST clients, scheduled jobs, build agents, self-hosted runners, B2B administrators and emergency-access accounts. Search scripts and pipeline configuration for user-based credentials, including AZURE_USERNAME and AZURE_PASSWORD. The key question is: which identities make requests to ARM, and are any ordinary Microsoft Entra users?

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Choose an MFA policy approach

Use Security Defaults when you need a straightforward baseline and do not have Conditional Access licensing or a requirement for detailed policy control. Microsoft recommends Security Defaults for organizations without Conditional Access capability. See Configure Security Defaults.

Use Conditional Access when you need tailored targeting, device, location or risk conditions, authentication strengths, or carefully managed exclusions. Conditional Access requires Microsoft Entra ID P1 or P2 licensing. It offers more control, but a misconfigured policy can cause unexpected prompts or lockout. Neither approach is a substitute for testing the actual admin and automation flows.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Approach Best fit Trade-off
Security Defaults Organizations needing a simple baseline without Conditional Access licensing Limited customization of conditions, exclusions and authentication requirements
Conditional Access Licensed organizations needing granular targeting, authentication strengths or tailored controls Requires Entra ID P1 or P2; policies require careful design and testing
Microsoft-enforced requirement alone A baseline when a tenant has not configured its own MFA policy Not a complete identity-security design; a breakage may become visible only during a resource-changing operation
Third-party MFA Organizations with a broader external identity strategy or a specific integration need Adds integration and support dependencies; legacy Conditional Access Custom Controls do not satisfy this requirement

Microsoft-native options may be sufficient; purchasing a third-party MFA product is not inherently required. If using an external provider, verify that it is integrated through a supported external authentication method. Microsoft says deprecated Conditional Access Custom Controls do not satisfy the requirement.

3. Register and test user authentication methods

Confirm that affected users have registered a supported method, such as Microsoft Authenticator or, where suitable, a FIDO2 security key or passkey, and have an approved recovery method. Security Defaults uses number matching in Authenticator. A method that satisfies MFA is not necessarily phishing-resistant: push approval and SMS are not equivalent to a passkey or FIDO2 key for privileged users. The Microsoft registration verification guidance explains how to check mandatory MFA setup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Update tools and remove password-based user flows

Microsoft’s current compatibility guidance recommends Azure CLI 2.76 or later and Azure PowerShell 14.3 or later. Treat these as the versions cited in that guidance, not permanent minimums; check the current documentation when updating your environment.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Replace unattended sign-in patterns built around a username and password. Microsoft flags username/password use in Azure identity libraries, including DefaultAzureCredential configured with username and password environment variables, EnvironmentCredential configured the same way, and UsernamePasswordCredential. For workloads, use a suitable noninteractive identity such as a managed identity, service principal or federated workload identity. Choose the credential design that fits the platform and secure its permissions and lifecycle.

5. Test the operations that matter

  • Sign in interactively to the Azure portal and other relevant admin centers.
  • Test fresh Azure CLI and PowerShell logins with affected users.
  • Run Terraform plan and apply, and test the deployment path used by your other IaC tools.
  • Test SDK and REST clients, including resource create, update and delete operations—not only reads.
  • Exercise scheduled jobs, build agents, self-hosted runners and any network-restricted administrative workflow.
  • Test B2B administration and emergency-access recovery procedures.

6. Check enforcement status and logs

As a Global Administrator, sign in to the Azure portal and open https://aka.ms/managemfaforazure to check the Phase 1 status banner. For Phase 2, open https://aka.ms/postponePhase2MFA and check its status banner. Entra sign-in logs can help identify which application generated an MFA requirement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot MFA failures

CLI or PowerShell fails after sign-in

Check for an outdated client, a cached token that predates the MFA requirement, an unregistered method, or a policy that the client’s authentication flow cannot satisfy. Update the tool, sign out and perform a fresh interactive login, confirm registration, inspect Entra sign-in logs, then test the exact resource-changing operation. For unattended work, move away from a user login to a workload identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A claims challenge appears but no MFA prompt

Some clients can handle a claims challenge and display an interactive prompt; others return an error because they cannot complete an interactive step. This can affect older SDKs, custom REST clients, IaC runners and username/password credential flows. Update the client or redesign the workload authentication; suppressing the MFA requirement is not a sound fix.

Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

A user already has Conditional Access but is still prompted

Check whether the existing policy targets the relevant cloud application and whether the user has registered the authentication method it requires. Also verify the tenant being accessed, B2B MFA claim handling and whether a cached session is older than the policy. If an external MFA provider is involved, confirm that the integration uses a supported method rather than deprecated Custom Controls.

A service account stops working

If the account is an ordinary Entra user, it can be subject to enforcement. Migrate the job to a managed identity, service principal or federated workload identity where supported; do not create another password-only user as a workaround.

Emergency access and support escalation

Design emergency access so a failure in the normal MFA path does not eliminate every recovery route. Microsoft’s guidance should inform the number and protection of emergency accounts. Keep credentials protected separately, alert on use, test sign-in periodically and document recovery. Any Conditional Access exclusion should be narrow, monitored and reviewed, not treated as a broad bypass.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft provided postponement processes for tenants facing technical barriers, but not a general opt-out. The stated Phase 1 postponement deadline was September 30, 2025, and Phase 2’s was July 1, 2026; both have passed. If an enforcement problem remains, consult Microsoft’s current support guidance and contact Microsoft Support where necessary rather than assuming the tenant can still defer rollout.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.