Hardening · 10 July 2026 · 4 min read
How to enable MFA in Microsoft 365 — a step-by-step guide
Multi-factor authentication stops most account attacks. A concrete guide for Microsoft 365: what to enable, in what order, and how to verify it actually works.
ClearSecurity Vision
Most compromised accounts don’t fall to sophisticated attacks. They fall to a stolen password — phished in an email, leaked in a breach at another service where an employee reused it, or simply guessed. Multi-factor authentication (MFA) adds a second step to sign-in — a confirmation on the phone — and blocks the vast majority of these attacks, even when the password is already in the wrong hands.
If your company runs on Microsoft 365, enabling MFA is probably the most valuable hour you can invest in security. This guide takes you from zero to “enabled and verified”.
Who this guide is for
- Companies using Microsoft 365 (Business Basic, Standard or Premium)
- You need an account with the Global Administrator role and about an hour
- Employees need a phone that can run the Microsoft Authenticator app (free, iOS and Android)
Pick the right route
Microsoft gives you two paths. The choice depends on your licence:
Route A — Security defaults. Available on every licence, at no extra cost. A single switch: it requires MFA for all users and blocks legacy authentication protocols, which bypass MFA. No exceptions, no fine-grained rules. For most small companies, this is the right choice.
Route B — Conditional Access. Requires an Entra ID P1 licence (included in Business Premium). It gives you fine control: require MFA only in certain situations, exclude specific accounts, apply stricter rules to administrators. Pick this if you already have Business Premium or specific needs.
Route A: enable security defaults
- Open entra.microsoft.com and sign in with your Global Administrator account.
- In the left menu, go to Identity → Overview → Properties.
- At the bottom of the page, select Manage security defaults.
- Set the toggle to Enabled and save.
From this point on, at their next sign-in, every user is prompted to register the Microsoft Authenticator app. They get a 14-day grace period — after that, registration becomes mandatory.
Important: tell the team beforehand. A short message like “starting tomorrow, Microsoft will ask you to install an app on your phone at sign-in — it’s a protection measure, it takes 2 minutes” saves a lot of calls to IT.
Route B: a Conditional Access policy
- In entra.microsoft.com, go to Protection → Conditional Access → Policies and create a new policy.
- Under Users: include All users, but exclude one emergency account (see common mistakes below).
- Under Target resources: All cloud apps.
- Under Grant: tick Require multifactor authentication.
- Run the policy in Report-only mode for a few days first — check the sign-in logs to see who it would affect — then switch it to On.
If you take route B, turn security defaults off (the two don’t combine) and leave legacy per-user MFA set to “Disabled” for everyone — otherwise some users get double prompts.
Verify the result
Don’t stop at “I flipped the switch”. Check:
- Open a private browsing window and sign in to office.com with a regular account (not the admin). You should get the confirmation prompt in the app.
- In entra.microsoft.com → Identity → Monitoring → Sign-in logs, open a recent sign-in: “Authentication requirement” should read multifactor authentication.
- A week in, check who hasn’t registered yet (Protection → Authentication methods → User registration details) and follow up individually.
Common mistakes
- No emergency account. If you use Conditional Access, keep one administrator account excluded from the policy, with a very long password stored in a safe. If the MFA service has an outage or the only admin phone is lost, you still have a way in.
- Starting with regular users and postponing the admins. Do the opposite: admin accounts are the most valuable to an attacker — they get MFA first.
- SMS as the primary method. Text-message codes are better than nothing, but they can be intercepted. The Authenticator app is the reasonable standard; hardware security keys are the next step for critical accounts.
- Legacy protocols left enabled. IMAP/POP/SMTP basic auth bypass MFA. Security defaults block them automatically; with Conditional Access, block them explicitly (a “Block legacy authentication” policy).
Under NIS2? Multi-factor authentication is explicitly listed among the law’s minimum measures — this guide closes one of the most frequently flagged gaps in security assessments.
One step done. See the full picture.
Answer a few questions across the 8 essential areas — from passwords and backups to suppliers — and get a report by email with your weak spots and next steps.
Start the self-assessment →
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.