How To Enable MFA for All Users in Microsoft Entra

How To Enable MFA for All Users in Microsoft Entra

Multifactor authentication (MFA) is remarkably effective at blocking cyberattacks. How effective? Well, it’s often difficult to get stats on things that didn’t happen, so here’s what did: According to Microsoft’s data, over 99.9% of compromised accounts weren’t using MFA. 

That’s why it’s typically required in order to qualify for cybersecurity insurance, and many businesses are starting to grow wary of working with other businesses that don’t use it. Fortunately, Microsoft has made it relatively easy for businesses to enable it for all users in Entra. In this blog, I’ll show you how. 

What Is Microsoft Entra?

Employee learning new cloud tool

Microsoft product names evolve along with their capabilities. So basically, Microsoft Entra ID is a new version of Azure Active Directory that provides user authentication and authorization for Microsoft services.

Essentially, it can help you implement MFA to make sure that only authorized users can access your sensitive information — even if their login credentials have been compromised. 

How To Enable MFA for Users in Microsoft Entra

Here’s your step-by-step guide. Keep in mind that as Microsoft continues to update its tools, your steps may vary slightly. 

  1. Log In to Entra ID 
  2. Select Security
  3. In your Entra ID admin center, click Security in the menu on the left 
  4. Select MFA, then Manage, and then click Multi-Factor Authentication 
  5. Select the users you’d like to include (I’d recommend including all)
  6. Click Enable 

How To Customize and Configure Your Microsoft MFA Setup

Microsoft ‍Entra ID will allow you to offer some flexibility to your users on which MFA methods work best for them. Some methods of MFA are more secure than others, however. And considering the recent news regarding the Chinese telecom hack, you might want to get pickier about phone and SMS options for your most sensitive accounts.

  1. Log in to Entra ID 
  2. In your portal, click on Identity
  3. Select Users and then Authentication Methods 

Here, you can set up a default MFA method and select which methods are usable and not usable by your users. 

Setting Up MFA on a Per-User Basis

We normally advise our clients not to use per-user MFA, as security is important for all users! However, there is a way to set up MFA for some users, but not all, and see who’s using it and who isn’t. 

From the admin center, go to Identity, Users, and choose All Users. Then click Per-User MFA, where you’ll see a complete list of user accounts and their MFA status to the right. 

Setting Up Conditional Access ‍

You can also control when and how MFA will be required based on things like user location, app, and more. 

From the admin center, click on Protection and Conditional Access and then select +New Policy to see your options. ‍

Which Methods Can Be Used To Implement Multifactor Authentication?

Face ID MFA

You can verify your identity by using something you know (like a PIN), something you own (like a device), or something you are. 

Here’s how that translates into MFA methods: 

  • Text (SMS messaging), which sends a one-time passcode to a verified user’s device 
  • Email authentication, which sends a link or passcode to a verified email address 
  • App-based authentication, which uses an app to generate passcodes
  • Biometric authentication, using fingerprint or facial recognition technology

Email authentication is considered less secure than text-based authentication (although that could change due to the telecom hack); app-based or biometric authentication is considerably more secure. 

Additional Tools To Evaluate Your Organization’s Cybersecurity Posture

We do have a new service that focuses on securing your Microsoft environment. It’s a good fit for organizations that may not need fully managed IT, but need to upgrade their managed detection and response (MDR) capabilities for Microsoft 365 cloud services, add backup and recovery options for M365 apps, and receive help desk support and simplified license management.

Our cybersecurity experts at Marco have also created an interactive checklist so it’s easy to see exactly where you’re at and which updates are needed to bring you up to speed. Click the link below to get started! 

Get Our Cybersecurity Checklist  Download Now

Related Posts

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...

Cybersecurity Tips for Small Business Owners
Cybersecurity Tips for Small Business Owners

Too many small business owners still think they’re “too small” to be targeted by a cybercriminal. Unfortunately, 43% of cyberattacks each year are aimed at small businesses.

5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

Why Is MFA Important — and Is Your Business Using It Correctly?
Why Is MFA Important — and Is Your Business Using It Correctly?

Passwords alone haven't been enough to protect business accounts for years. Most IT professionals know this. Most business owners have heard it. And yet credential theft remains on...

What Is Cloud-Native Security?
What Is Cloud-Native Security?

Most businesses didn't set out to build a cloud-native environment. They started using Microsoft 365, added a cloud-based phone system, migrated a few workloads to Azure or AWS, an...

The Security Strategy AI-Powered Attacks Demand
The Security Strategy AI-Powered Attacks Demand

The threat environment changed. Not gradually. Abruptly. Tools like Anthropic’s Claude Mythos and the latest generation of AI-assisted exploitation capabilities have fundamentally ...

Data Security Governance Best Practices for 2026
Data Security Governance Best Practices for 2026

Data security has reached a breaking point. Sensitive information now lives in more places than ever, sprawled across SaaS applications, cloud drives, on-premises servers, and incr...

Top Cybersecurity Laws and Regulations To Know About in 2026
Top Cybersecurity Laws and Regulations To Know About in 2026

Many companies are now facing the challenges posed by malicious hackers attacking their IT environment. Unfortunately, the fallout continues even after the attack is contained, inc...