Multi-factor authentication, usually shortened to MFA, is one of the most important security controls for Microsoft 365. It adds an extra verification step when a user signs in, rather than relying on a password alone.
For businesses, the key question is not just whether MFA exists somewhere in Microsoft 365. The real question is whether MFA is actually enabled and working for the users who need it.
This guide explains how to check whether Microsoft 365 MFA is enabled for your users, what to look for, and why MFA should be part of a wider Microsoft 365 security approach.
What is Microsoft 365 MFA?
MFA requires a user to prove their identity using more than just a password. This might involve approving a sign-in using the Microsoft Authenticator app, entering a verification code, using a security key, or another approved authentication method.
Microsoft describes MFA as requiring a second verification method for user sign-ins and says it improves account security. Microsoft 365 organisations can use security defaults, Conditional Access policies, or legacy per-user MFA, depending on their licensing and setup. Microsoft’s MFA setup guidance explains these options.
For most businesses, MFA should be enabled for all users, not just directors, finance staff or administrators.
Why checking MFA status matters
It is common for businesses to assume MFA is enabled because some users receive approval prompts. That does not always mean every account is protected.
Common problems include:
- Some users have MFA enabled, while others do not
- Only administrator accounts are protected
- Old users and leaver accounts are still active
- Legacy per-user MFA is partly configured
- Security defaults are disabled
- Conditional Access policies do not apply to all required users
- Guest users, shared accounts or service accounts have been missed
- Users are registered for MFA but not actually required to use it
This is why checking MFA properly is important. A business may think it has MFA in place, while several accounts remain exposed.
First, understand how MFA is being enforced
Before checking individual users, identify how MFA is being enforced in your Microsoft 365 tenant.
There are three common approaches:
- Security defaults, which provide a simple baseline security configuration for Microsoft Entra ID.
- Conditional Access, which allows more detailed policies based on users, apps, locations, devices and risk.
- Legacy per-user MFA, which is still available but is not Microsoft’s preferred modern approach.
Microsoft states that security defaults are available in all Microsoft 365 organisations through Microsoft Entra ID Free, while Conditional Access is available with Microsoft Entra ID P1 or P2 licensing. Microsoft also describes legacy per-user MFA as not recommended except in specific circumstances. Microsoft’s guidance compares the main MFA setup options.
This distinction matters because an MFA check can look different depending on whether your business uses security defaults, Conditional Access or legacy per-user MFA.
How to check if security defaults are enabled
Security defaults are often used by smaller organisations that do not have complex access requirements or Conditional Access licensing.
To check security defaults:
- Sign in to the Microsoft Entra admin center.
- Go to Identity.
- Open Overview.
- Select Properties.
- Look for Manage security defaults.
- Check whether security defaults are set to Enabled.
Microsoft says security defaults help strengthen an organisation’s security posture with preconfigured MFA requirements and legacy authentication protection. Microsoft also notes that security defaults may already be enabled by default for tenants created on or after 22 October 2019. Microsoft’s security defaults documentation explains how to check and enable them.
If security defaults are enabled, this is a good start. However, you should still review users, admin accounts, guest access, old accounts and sign-in activity.
How to check Conditional Access MFA policies
Conditional Access is usually the better option for businesses that need more control. It can apply MFA based on conditions such as user group, location, device compliance, application or sign-in risk.
To check Conditional Access MFA policies:
- Sign in to the Microsoft Entra admin center.
- Go to Protection.
- Select Conditional Access.
- Open Policies.
- Look for policies that require multifactor authentication.
- Check which users, groups, applications and conditions are included.
- Check whether any users, groups or locations are excluded.
- Confirm that the policy is enabled, not left in report-only mode.
Microsoft provides guidance for creating a Conditional Access policy to require MFA for all users. Conditional Access policies can also be tested in report-only mode before being fully enforced. Microsoft’s Conditional Access MFA guidance explains this approach.
When reviewing Conditional Access, pay close attention to exclusions. Exclusions can be valid, but they should be documented and reviewed. An old exclusion group can leave users unprotected without anyone realising.
How to check legacy per-user MFA
Some older Microsoft 365 tenants still use legacy per-user MFA. This is where each user has an MFA state such as disabled, enabled or enforced.
To check legacy per-user MFA:
- Go to the Microsoft 365 admin center.
- Go to Users.
- Select Active users.
- Open the multi-factor authentication page or link.
- Review the MFA status shown for each user.
Microsoft states that changing per-user MFA states is not recommended unless your Microsoft Entra ID licences do not include Conditional Access and you do not want to use security defaults. Microsoft’s per-user MFA documentation explains the older user-state approach.
If your business still relies on legacy per-user MFA, it may be worth reviewing whether security defaults or Conditional Access would be a better long-term setup.
Check MFA registration, not just MFA enforcement
There is an important difference between a user being registered for MFA and a user being required to use MFA.
A user may have registered an authentication method, but if no policy requires MFA for that user, they may not be prompted in the way you expect. Equally, a policy may require MFA, but users who have not registered properly may experience sign-in problems.
Microsoft Entra includes authentication methods activity reporting. Microsoft says these reports can show which authentication methods are used for sign-in and password reset, including sign-ins that required single-factor or multifactor authentication. Microsoft’s authentication methods activity documentation explains the available reporting.
When checking MFA, review both:
- Which users are registered for MFA or strong authentication methods
- Which users are actually required to use MFA when they sign in
Check administrator accounts carefully
Administrator accounts should be checked first and reviewed more carefully than standard users.
Admin accounts can create users, reset passwords, change security settings, access sensitive areas of Microsoft 365 and alter tenant configuration. If an administrator account is compromised, the impact can be much wider than a single mailbox.
Check that:
- All administrator accounts are protected with MFA
- Global Administrator rights are limited
- Admin roles are only assigned where needed
- Old supplier or leaver admin accounts have been removed
- Admin accounts are not used casually for day-to-day email
- Emergency access accounts are documented and protected appropriately
Microsoft has also published guidance around mandatory MFA enforcement for Azure, Microsoft 365 and other admin portals. Microsoft’s mandatory MFA planning guidance explains the direction of travel for admin portal protection.
Check shared, service and old accounts
Normal user accounts are not the only risk. Shared accounts, service accounts and old leaver accounts can also create gaps.
Review:
- Leaver accounts that still allow sign-in
- Accounts used by scanners, applications or old systems
- Shared accounts used by multiple staff
- Accounts excluded from MFA policies
- Accounts with old authentication methods
- Accounts with mailbox access or forwarding rules
Where possible, shared accounts should be avoided or tightly controlled. Service accounts should be documented, limited and reviewed. Leaver accounts should be blocked and handled through a proper offboarding process.
Check for legacy authentication
Legacy authentication is a common weakness because older sign-in methods may not support modern MFA controls in the same way. Blocking legacy authentication is an important part of a secure Microsoft 365 setup.
Security defaults include legacy authentication protection, and Conditional Access can also be used to block legacy authentication where licensing and configuration allow. Microsoft includes legacy authentication protection as part of security defaults.
If legacy authentication is still allowed, review why it is needed and whether any old applications, devices or mail clients should be replaced or reconfigured.
What to do if some users do not have MFA
If your check finds users without MFA, do not simply enable everything without planning. MFA changes can affect users, mobile devices, remote access, admin accounts and older applications.
A sensible rollout usually includes:
- Checking licensing and available MFA options
- Deciding between security defaults and Conditional Access
- Reviewing admin accounts first
- Communicating the change to users
- Helping users register Microsoft Authenticator or another approved method
- Testing with a small group first, where appropriate
- Removing unnecessary exclusions
- Checking sign-in logs after rollout
For many businesses, this is also a good time to review wider Microsoft 365 security rather than treating MFA as a standalone task.
MFA is important, but it is not the whole security plan
MFA is essential, but it does not remove every Microsoft 365 risk. Attackers still use phishing, token theft, malicious consent, mailbox forwarding, weak admin processes and social engineering.
A stronger Microsoft 365 security setup should also consider:
- Conditional Access policies
- Administrator account protection
- Mailbox forwarding rule monitoring
- Phishing protection
- Secure SharePoint and OneDrive sharing
- Microsoft 365 backup
- Endpoint protection
- User awareness training
- Sign-in and identity monitoring
We explain this broader approach in our guide: How to Secure a Microsoft 365 Account Before It Is Compromised.
Microsoft 365 MFA checklist
Use this checklist as a starting point:
- Confirm whether security defaults, Conditional Access or per-user MFA is being used
- Check all active users are covered by MFA
- Check all administrator accounts are protected
- Review Conditional Access exclusions
- Check users are registered with suitable authentication methods
- Review legacy authentication
- Check old, shared and service accounts
- Review sign-in logs for unusual activity
- Document any exceptions
- Retest regularly
Need help checking Microsoft 365 MFA?
KES helps businesses review Microsoft 365 security, including MFA, Conditional Access, admin accounts, sign-in monitoring, mailbox rules, backup and account protection.
If you are not sure whether MFA is properly enabled for all users, or if your setup has grown over time without a full review, KES can help check it properly.
You may also find these useful:
- Microsoft 365 Security articles
- KES Security Review
- Business Email Exposure Check
- Business User Pack
Want KES to check your Microsoft 365 MFA setup?
KES can review your Microsoft 365 users, MFA status, Conditional Access policies, admin accounts and sign-in security to help identify gaps before they become problems.
Sources
- Microsoft Learn: Set up multifactor authentication for Microsoft 365
- Microsoft Learn: Configure security defaults for Microsoft Entra ID
- Microsoft Learn: Require MFA for all users with Conditional Access
- Microsoft Learn: Enable per-user multifactor authentication
- Microsoft Learn: Authentication methods activity reports
- Microsoft Learn: Plan for mandatory Microsoft Entra multifactor authentication