Office 365 Multi-Factor Authentication

Office 365 MFA


User - Manage/Change Authentication Methods (Direct Link)


Management (MFA) - Enable/Enforce/Disable

  • Users > Active Users > Multi-Factor Authentication (Tab) - or Azure Portal > Users > Multi-Factor Authentication
  • Select user to enable/disable MFA

Global Settings (Trusted IPs, Allow app passwords)

Reference - https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#trusted-ips

  • Log into https://portal.office.com as Global Admin
  • Users > Active Users > Multi-Factor Authentication (Tab) > Service Settings (Not so obvious tab up top)
  • App Passwords - By disallowing App passwords, users will need to use OWA (cant use Outlook?)
  • Trusted IPs - Skips MFA on specific IP addresses
  • Verification Options - Methods available to users (i.e. text message, mobile app)

Audit Logs