How to Disable 2FA in Microsoft Entra ID

Author: Forrest Zhang

Disabling two-factor authentication in Microsoft Entra ID is not always a single-setting change. In many tenants, MFA can be enforced from several different places, so turning off one control does not necessarily stop sign-in prompts.

The practical issue is that administrators often disable Security Defaults and still see users prompted to register Microsoft Authenticator or complete MFA. Based on Microsoft documentation, that usually means another enforcement path is still active, such as the registration campaign, Conditional Access, per-user MFA, authentication method settings, or Microsoft’s mandatory MFA requirements for certain admin portals.


1) Why disabling Security Defaults is not always enough

Microsoft Entra can require MFA through multiple independent controls. Security Defaults is only one of them. Even when Security Defaults is turned off, users can still be affected by Conditional Access policies, per-user MFA states, registration prompts, or admin-portal-specific MFA enforcement documented by Microsoft.

The safest way to troubleshoot this is to check each possible enforcement path one by one rather than assuming there is only a single global MFA switch.


2) Turn off Security Defaults

If your tenant uses Security Defaults, this is the first place to check. Microsoft documents that Security Defaults can be disabled from the tenant properties page.

Path:

  • Microsoft Entra admin center
  • Entra ID
  • Overview
  • Properties
  • Manage security defaults
  • Set Security defaults to Disabled
  • Save

This step removes MFA requirements that come specifically from Security Defaults, but it does not remove MFA requirements enforced somewhere else.


3) Disable the Registration Campaign

One of the most common reasons users still see the Let’s keep your account secure screen is the Microsoft Authenticator registration campaign. Microsoft documents that the registration campaign can prompt eligible users during sign-in to register Microsoft Authenticator, even when administrators think they already turned MFA off elsewhere.

Path:

  • Microsoft Entra admin center
  • Protection
  • Authentication methods
  • Registration campaign
  • Edit
  • Set State to Disabled
  • Save

If your goal is to stop users from being pushed into Authenticator setup, this is one of the most important places to review.


4) Review Conditional Access policies

Conditional Access is completely separate from Security Defaults. A Conditional Access policy can still require MFA for a user, group, cloud app, device state, location, or sign-in scenario. Microsoft’s Conditional Access documentation shows that a policy can enforce MFA through grant controls such as Require multifactor authentication.

Path:

  • Microsoft Entra admin center
  • Protection
  • Conditional Access
  • Policies

Check each policy for:

  • whether the user is included
  • whether the grant controls include Require multifactor authentication

If yes, do one of these:

  • exclude the user
  • disable the policy
  • remove the MFA requirement from that policy

This is often the next place to investigate after Security Defaults and the registration campaign.


5) Disable Per-user MFA

Per-user MFA is another separate control path. Microsoft notes that Conditional Access does not automatically change a user’s per-user MFA state, so a tenant can still have MFA enforced here even if Conditional Access has been adjusted.

Path:

  • Microsoft Entra admin center
  • Users
  • Per-user MFA
  • Find the user
  • Set the user’s MFA status to Disabled

This older control path is easy to overlook, especially in tenants that have evolved over time.


6) Review Authentication Methods policy

Authentication Methods policy settings can also affect sign-in and registration behavior. Even when they are not directly forcing MFA in the same way as Conditional Access, they can still influence what users are asked to register and which methods are available.

Path:

  • Microsoft Entra admin center
  • Protection
  • Authentication methods

Review these areas carefully:

  • Microsoft Authenticator
  • assigned users or groups
  • registration-related settings

This check matters most when users are still being led into setup prompts even after more obvious MFA controls have been disabled.


7) Understand the limitation for Microsoft admin portals

There is an important limitation here. Microsoft has introduced mandatory MFA requirements for certain administrative experiences, including the Azure portal, Microsoft Entra admin center, Microsoft Intune admin center, and later the Microsoft 365 admin center. In practice, that means true username-and-password-only access may not be possible for those admin portals even if you disable the tenant-level settings described above.

This point matters because it changes the troubleshooting outcome. In some cases, the issue is not that you missed a tenant setting. The issue is that Microsoft requires MFA for that admin experience by design.


Recommended Guidance for Project Teams

  • Do not assume Security Defaults is the only MFA control in the tenant.
  • Check the registration campaign early if users are seeing setup prompts for Microsoft Authenticator.
  • Review Conditional Access and per-user MFA separately because they are independent enforcement paths.
  • Validate whether the affected sign-in is for a normal business app or a Microsoft admin portal.
  • Document your tenant’s MFA design so future administrators do not have to guess which control is active.

Practical troubleshooting order

A practical sequence for troubleshooting is:

  1. Turn off Security Defaults
  2. Disable the Registration campaign
  3. Review Conditional Access policies
  4. Disable Per-user MFA
  5. Review Authentication Methods policy
  6. Confirm the user is not signing in to a Microsoft admin portal

This order helps narrow the issue quickly without jumping between unrelated settings.


Quick Summary

Area What to Check Why It Matters
Security Defaults Whether it is enabled It can enforce MFA tenant-wide, but it is only one control path.
Registration campaign Whether users are being targeted It can trigger Authenticator setup prompts during sign-in.
Conditional Access Grant control requiring MFA It can still require MFA even when Security Defaults is off.
Per-user MFA User MFA status It is separate from Conditional Access and easy to miss.
Authentication Methods Assigned users, groups, and registration settings It can affect registration and sign-in behavior.
Admin portals Whether the user is signing in to Microsoft admin experiences Microsoft may require MFA regardless of tenant changes.

Final Thoughts

If you want to disable 2FA in Microsoft Entra ID, do not stop at Security Defaults. That is only one switch in a larger identity control model. The reliable way to resolve unexpected MFA prompts is to check every enforcement path that can still affect the user.

In other words, the real task is not just disabling MFA in one place. It is identifying which Microsoft Entra feature is currently enforcing it.

No comments:

Post a Comment