Disable MFA for Entra ID users

  • Assumption
    • As the common user does not have to have the MFA to access, except the administrator role user in the Entra ID organization/Tenant, the MFA can be disabled as default.
    • Security defaults is being turned on as the default of M365 Tenant setting.
    • To disable the MFA by default for all users, the Security Defaults must be turned off.
    • Even if the Security Defaults is turned off, the user who has administrator role assignment in Tenant keeps the MFA getting turned on.
  • Step
    • Go to M365 Admin Center.
    • Identity -> Go to Identity console.

    • Overview -> Properties.

    • Go to bottom of the configuration items, and “Manage Security Defaults”.

    • Change the setting to Disabled in dropdown list and select one suitable reason for this setting.

    • Save.