Cybersecurity
Guide

MFA in Microsoft 365: A Practical Setup Guide

Microsoft now enforces MFA for sign-ins to specific admin tools, in two phases with different dates. This guide separates what's actually mandatory from what NCSC recommends for everyone, and walks through setting it up in Microsoft 365 without locking out your own admins.

Sep 11, 2026
8 min read
MFA in Microsoft 365: A Practical Setup Guide

Most Dutch SMEs still protect their most valuable accounts with exactly one thing: a password. Multifactor authentication (MFA) adds a second check — something you have or something you are, on top of something you know — and it is, by a wide margin, the single cheapest security improvement an SME can make. Microsoft's own research puts the share of automated account-compromise attempts that MFA blocks above 99%. This guide explains what Microsoft has actually made mandatory (and what it hasn't), why the Dutch National Cyber Security Centre recommends MFA for everyone regardless, and how to turn it on in Microsoft 365 without locking your own admins out.

What MFA actually checks

Multifactor authentication confirms who you are using more than one type of evidence:

  • Something you know — a password or PIN.
  • Something you have — a phone with an authenticator app, or a hardware security key.
  • Something you are — a fingerprint or face scan.

A password alone only proves you know a string of characters, and passwords leak constantly — through phishing, reused credentials from an unrelated breach, or malware. Requiring a second, independent factor means a leaked password is no longer enough on its own to get in.

What Microsoft has actually made mandatory — and what it hasn't

There's a lot of confusion about this. Microsoft is rolling out mandatory MFA in two phases, and both are narrower than "every Microsoft 365 user must use MFA":

Phase 1 requires MFA for accounts signing in to perform create, read, update or delete actions in the Azure portal, the Microsoft Entra admin center, and the Microsoft Intune admin center (enforcement began rolling out from October 2024), and separately for sign-ins to the Microsoft 365 admin center (rolling out from February 2025).

Phase 2 extends this to accounts signing in through Azure CLI, Azure PowerShell, the Azure mobile app, infrastructure-as-code tools, and the Azure Resource Manager REST API to create, update or delete resources. This phase began rolling out on 1 October 2025. Organisations with genuine technical blockers could request a postponement — to 30 September 2025 for Phase 1, and to 1 July 2026 for Phase 2 — but both windows have now closed, so enforcement applies broadly across tenants.

The part that gets lost in translation: this requirement targets administrative sign-ins to management tools, not everyday use of Outlook, Teams or SharePoint. Microsoft's own documentation is explicit that users aren't required to complete MFA to access other applications or services hosted on Azure — each application owner sets its own rules for that. If your finance team logs into Outlook and never touches the Azure portal or the Microsoft 365 admin center, Microsoft's mandate alone does not force MFA onto their mailbox login. That's a separate, and arguably more important, decision your organisation still has to make for itself.

Why NCSC recommends it for everyone anyway

The Dutch National Cyber Security Centre's guidance doesn't stop at what Microsoft enforces. Its advice is to turn on two-factor or multifactor login wherever it's available on business applications, and explicitly names business email as a minimum: at the very least, protect your work email with it. The reasoning holds regardless of what any vendor mandates — a compromised mailbox is routinely the first step in invoice fraud and CEO-fraud schemes, because it gives an attacker a trusted identity to send from.

NCSC's suggested approach is a short risk exercise: work out which information or systems are critical to your business (administration, order systems, backups are common examples), decide how badly it would hurt if an unauthorised person got in, and use that to decide where MFA is worth the extra login step. For most SMEs, that list ends up including at minimum: email, the Microsoft 365 admin account, financial and accounting systems, and any remote access into the company network.

Security defaults vs. Conditional Access: which to use

Microsoft gives Microsoft 365 organisations three ways to require MFA, and they are not equally good:

OptionAvailable onWhat it gives you
Security defaultsEvery Microsoft 365 tenant, via Microsoft Entra ID Free (no extra cost)A single Microsoft-managed baseline: MFA required for everyone, legacy authentication blocked. On by default for tenants created after October 2019. Simple, but not customisable.
Conditional AccessTenants with Microsoft Entra ID P1 or P2 — already included in Microsoft 365 Business Premium and E3 (P1) or E5 (P2)Granular policies: different rules for admins vs. staff, phishing-resistant MFA for admins specifically, exceptions for tightly controlled emergency-access accounts, rules based on location or device.
Legacy per-user MFAEvery tenant, via Microsoft Entra ID FreeWorks, but Microsoft itself no longer recommends it in favour of the two options above.

If your organisation already has Business Premium or E3, Conditional Access costs nothing extra to turn on and is worth the additional setup time — it's the only one of the three that lets you require phishing-resistant MFA for administrator accounts specifically, which matters because admin accounts are the highest-value target in any tenant. Microsoft provides ready-made policy templates for exactly this: "Require MFA for all users," "Require MFA for administrators," "Block legacy authentication," and "Require MFA for Azure management." Security defaults and Conditional Access cannot both be active — switching to Conditional Access means turning security defaults off first and recreating an equivalent baseline before layering on anything more specific.

Choosing an MFA method: skip SMS where you can

Not every second factor offers the same protection. NCSC's clearest, most specific piece of advice here is to avoid SMS-based codes where an alternative is available. SMS messages aren't encrypted and can be intercepted; NCSC points to a real, documented case where attackers used "MFA fatigue" — repeatedly triggering approval prompts until an exhausted user approved one by mistake — to break into a software company's business email accounts, which they then used to commit invoice fraud.

An authenticator app on a smartphone is the practical default for most SMEs: no extra hardware cost, works across common platforms, and is meaningfully harder to intercept than SMS. A hardware security key raises the bar further but costs more per user and needs a distribution and replacement process. NCSC's checklist for comparing apps is worth applying: ease of daily use, licensing and management cost, dependence on a cloud service you'd lose access to if it went down, and whether staff can use it on the phones and laptops they actually have. One detail for anyone considering biometric methods: a fingerprint or face scan counts as a special category of personal data under the AVG, worth understanding before rolling it out company-wide.

Rolling it out without locking anyone out

MFA rollouts go wrong in one of two ways: they're never finished, or they lock out the one admin account that could have fixed the problem. A short, deliberate rollout avoids both:

  • 1. List what actually needs protecting. Email, the Microsoft 365 admin account, financial systems, remote access — start with what would hurt most if it were compromised.
  • 2. Set up at least two emergency-access ("break glass") accounts first, excluded from your MFA policies and used only when something else has gone wrong. Without this, a misconfigured policy or an authenticator app failure can leave nobody able to sign in and fix it.
  • 3. Choose your method — security defaults for a fast baseline, Conditional Access if you already have the licensing for more control — deciding this together with whoever supports your IT if you don't run it in-house.
  • 4. Communicate before you flip the switch. Tell staff what's changing, how to install and register an authenticator app, and who to call if they get stuck.
  • 5. Turn it on for a small group first, confirm nobody is locked out and that the emergency-access accounts still work, then roll out to everyone else.

Common misconceptions, corrected

"Microsoft made MFA mandatory for all our staff." Not yet, and not through this rollout — Microsoft's mandate covers sign-ins to specific admin tools and portals, not everyday mailbox or Teams access. Whether to require it for all staff is your own decision, and NCSC's advice is to make it anyway.

"SMS codes are secure enough." They're better than nothing, but NCSC specifically advises against them where an authenticator app or hardware key is an option, precisely because SMS can be intercepted.

"Security defaults and Conditional Access do the same thing." Security defaults give you one fixed baseline for everyone. Conditional Access lets you require stronger, phishing-resistant MFA specifically for admin accounts and build exceptions for emergency access — worth the setup time if you already have the licence for it.

FAQ

Is MFA mandatory in Microsoft 365? Microsoft requires it for sign-ins to specific admin tools — the Azure portal, Microsoft Entra admin center, Intune admin center and Microsoft 365 admin center, and (since October 2025) Azure CLI, PowerShell and related management tools. It does not, on its own, require MFA for everyday use of Outlook, Teams or SharePoint — that's a separate decision for your organisation.

What's the difference between security defaults and Conditional Access? Security defaults are a free, one-size-fits-all baseline available to every tenant. Conditional Access, included with Microsoft 365 Business Premium and E3 or E5, lets you set different rules for different groups — including phishing-resistant MFA for admins specifically.

Is an SMS code good enough? It works, but NCSC advises against relying on it where an authenticator app or hardware key is available, because SMS messages can be intercepted.

Does turning on MFA cost extra? Security defaults are included with every Microsoft 365 tenant at no extra cost. Conditional Access needs Microsoft Entra ID P1 or P2, which is already part of Business Premium, E3 and E5 — so most SMEs already have access to it without buying anything new.

What happens if an employee loses their phone? This is exactly why emergency-access accounts and a documented recovery process matter before you roll MFA out broadly — plan for lost or replaced devices as part of the rollout, not as an afterthought once it happens.

Get MFA rolled out properly

Turning on security defaults takes minutes; rolling out Conditional Access with the right exceptions, emergency-access accounts and a method staff will actually use takes planning. Our Cybersecurity & Identity service covers exactly this: choosing the right MFA setup for your licensing, configuring Conditional Access policies, and making sure nobody — including your own admins — ends up locked out. If your Microsoft 365 environment could use a wider health check while you're at it, our Managed IT Support team can look at patching, backup and device management at the same time. See also our guide to preventing ransomware in the SMB for how MFA fits into a broader defence.

Cybersecurity
MFA
Microsoft 365
MKB

Related Articles

Cybersecurity

AI-Powered Cybersecurity: How Machine Learning Is Transforming Threat Detection

Cyberattacks are growing in volume and sophistication. AI-powered security tools are shifting the balance back to defenders. This article examines how Dutch organisations are using ML-driven SIEM, EDR, and threat intelligence to stay ahead.

Read More
Cybersecurity

NIS2 for SMBs: What the Law Means and What You Must Arrange

The Dutch Cyberbeveiligingswet (NIS2) lands in 2026 and brings duty of care, a 24-hour reporting duty and personal director liability. Here is who is in scope, what you must arrange, and a practical step-by-step plan for SMBs.

Read More
Cybersecurity

Preventing Ransomware in the SMB: 8 Measures That Actually Work

SMBs are now the primary target for ransomware precisely because attackers assume their defences are weak. The good news: a handful of well-implemented measures stop the vast majority of attacks. Here are the 8 that deliver the most protection per euro.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.