How to Enable or Disable Per-User MFA

How to Enable or Disable Per-User MFA

Microsoft 365 administrators can enable or disable multifactor authentication (MFA) for individual users. This guide shows how.

Required permission: You must have permission to manage authentication settings in Microsoft 365.

Open per-user multifactor authentication

The quickest option is to open Per-user multifactor authentication directly in Microsoft Entra.

If the shortcut does not work, use the next section to navigate from the Microsoft 365 admin center.

Open the page from Microsoft 365 admin center

  1. Open the Microsoft 365 admin center, then click Show all in the left navigation.
Microsoft 365 admin center with Show all highlighted in the left navigation
  1. In the expanded navigation, click Settings.
Expanded Microsoft 365 admin center navigation with Settings highlighted
  1. Under Settings, click Org settings.
Settings menu with Org settings highlighted
  1. On the Services tab, search for Multi-factor authentication, then click the result.
Org settings search result for Multi-factor authentication
  1. In the panel, click Configure multi-factor authentication. Microsoft Entra opens the per-user MFA page.
Multi-factor authentication panel with Configure multi-factor authentication highlighted

Enable or disable MFA for a user

  1. Search for the user, then select the checkbox beside their account.
  2. Check the user's current Status.
  3. Click Enable MFA if the status is disabled. Click Disable MFA if MFA is already enabled or enforced.
  4. Review the confirmation, then confirm the change.
Per-user multifactor authentication page with Enable MFA and Disable MFA highlighted

Use Conditional Access for tenant-wide MFA

Per-user MFA manages one account at a time. To require MFA across your organization, use Conditional Access instead.

Review Microsoft's Conditional Access MFA guidance and multifactor authentication deployment guide.