0%
1 min left of 1 min read Microsoft 365 help →
01622 721000 info@kesuk.net
  • Facebook
  • X
  • Instagram
  • Facebook
  • X
  • Instagram
KES
  • Home
  • Managed IT
    • Managed Services
    • Free Technology MOT
    • Essential IT Support Pack
    • Business User Pack
    • Premium Pack
    • Remote Managed IT Support
    • accountants-it
    • IT Support for Professional Services
    • Private Data Rooms
  • Services
    • Microsoft 365
    • Cyber Security
    • Connectivity
    • Hosted Voice
    • IT Support Maidstone
    • Leased Lines
    • Computer Repair
    • Computer Sales
    • Renewed Computers
    • Green Recycling
  • Pricing
    • IT Support Pricing Calculator
    • Leased Line Pricing Calculator
    • Fibre Broadband
    • Managed Services Pricing FAQ
  • Learning Centre
    • IT Support
    • Microsoft 365
      • Microsoft 365 News
      • Microsoft 365 Licensing
      • Microsoft 365 Security
      • Microsoft 365 Guides
    • Cyber Security
    • Backup & Recovery
    • Connectivity
    • View All Articles
  • Contact Us
  • Support
Select Page

How to Check Microsoft 365 MFA Is Enabled for All Users

by Mark Roach | Jul 8, 2026 | Guides, Microsoft 365

Microsoft 365 MFA status shown on an admin dashboard with a smartphone approval prompt

Multi-factor authentication, usually shortened to MFA, is one of the most important security controls for Microsoft 365. It adds an extra verification step when a user signs in, rather than relying on a password alone.

For businesses, the key question is not just whether MFA exists somewhere in Microsoft 365. The real question is whether MFA is actually enabled and working for the users who need it.

This guide explains how to check whether Microsoft 365 MFA is enabled for your users, what to look for, and why MFA should be part of a wider Microsoft 365 security approach.

What is Microsoft 365 MFA?

MFA requires a user to prove their identity using more than just a password. This might involve approving a sign-in using the Microsoft Authenticator app, entering a verification code, using a security key, or another approved authentication method.

Microsoft describes MFA as requiring a second verification method for user sign-ins and says it improves account security. Microsoft 365 organisations can use security defaults, Conditional Access policies, or legacy per-user MFA, depending on their licensing and setup. Microsoft’s MFA setup guidance explains these options.

For most businesses, MFA should be enabled for all users, not just directors, finance staff or administrators.

Why checking MFA status matters

It is common for businesses to assume MFA is enabled because some users receive approval prompts. That does not always mean every account is protected.

Common problems include:

  • Some users have MFA enabled, while others do not
  • Only administrator accounts are protected
  • Old users and leaver accounts are still active
  • Legacy per-user MFA is partly configured
  • Security defaults are disabled
  • Conditional Access policies do not apply to all required users
  • Guest users, shared accounts or service accounts have been missed
  • Users are registered for MFA but not actually required to use it

This is why checking MFA properly is important. A business may think it has MFA in place, while several accounts remain exposed.

First, understand how MFA is being enforced

Before checking individual users, identify how MFA is being enforced in your Microsoft 365 tenant.

There are three common approaches:

  • Security defaults, which provide a simple baseline security configuration for Microsoft Entra ID.
  • Conditional Access, which allows more detailed policies based on users, apps, locations, devices and risk.
  • Legacy per-user MFA, which is still available but is not Microsoft’s preferred modern approach.

Microsoft states that security defaults are available in all Microsoft 365 organisations through Microsoft Entra ID Free, while Conditional Access is available with Microsoft Entra ID P1 or P2 licensing. Microsoft also describes legacy per-user MFA as not recommended except in specific circumstances. Microsoft’s guidance compares the main MFA setup options.

This distinction matters because an MFA check can look different depending on whether your business uses security defaults, Conditional Access or legacy per-user MFA.

How to check if security defaults are enabled

Security defaults are often used by smaller organisations that do not have complex access requirements or Conditional Access licensing.

To check security defaults:

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Identity.
  3. Open Overview.
  4. Select Properties.
  5. Look for Manage security defaults.
  6. Check whether security defaults are set to Enabled.

Microsoft says security defaults help strengthen an organisation’s security posture with preconfigured MFA requirements and legacy authentication protection. Microsoft also notes that security defaults may already be enabled by default for tenants created on or after 22 October 2019. Microsoft’s security defaults documentation explains how to check and enable them.

If security defaults are enabled, this is a good start. However, you should still review users, admin accounts, guest access, old accounts and sign-in activity.

How to check Conditional Access MFA policies

Conditional Access is usually the better option for businesses that need more control. It can apply MFA based on conditions such as user group, location, device compliance, application or sign-in risk.

To check Conditional Access MFA policies:

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Protection.
  3. Select Conditional Access.
  4. Open Policies.
  5. Look for policies that require multifactor authentication.
  6. Check which users, groups, applications and conditions are included.
  7. Check whether any users, groups or locations are excluded.
  8. Confirm that the policy is enabled, not left in report-only mode.

Microsoft provides guidance for creating a Conditional Access policy to require MFA for all users. Conditional Access policies can also be tested in report-only mode before being fully enforced. Microsoft’s Conditional Access MFA guidance explains this approach.

When reviewing Conditional Access, pay close attention to exclusions. Exclusions can be valid, but they should be documented and reviewed. An old exclusion group can leave users unprotected without anyone realising.

How to check legacy per-user MFA

Some older Microsoft 365 tenants still use legacy per-user MFA. This is where each user has an MFA state such as disabled, enabled or enforced.

To check legacy per-user MFA:

  1. Go to the Microsoft 365 admin center.
  2. Go to Users.
  3. Select Active users.
  4. Open the multi-factor authentication page or link.
  5. Review the MFA status shown for each user.

Microsoft states that changing per-user MFA states is not recommended unless your Microsoft Entra ID licences do not include Conditional Access and you do not want to use security defaults. Microsoft’s per-user MFA documentation explains the older user-state approach.

If your business still relies on legacy per-user MFA, it may be worth reviewing whether security defaults or Conditional Access would be a better long-term setup.

Check MFA registration, not just MFA enforcement

There is an important difference between a user being registered for MFA and a user being required to use MFA.

A user may have registered an authentication method, but if no policy requires MFA for that user, they may not be prompted in the way you expect. Equally, a policy may require MFA, but users who have not registered properly may experience sign-in problems.

Microsoft Entra includes authentication methods activity reporting. Microsoft says these reports can show which authentication methods are used for sign-in and password reset, including sign-ins that required single-factor or multifactor authentication. Microsoft’s authentication methods activity documentation explains the available reporting.

When checking MFA, review both:

  • Which users are registered for MFA or strong authentication methods
  • Which users are actually required to use MFA when they sign in

Check administrator accounts carefully

Administrator accounts should be checked first and reviewed more carefully than standard users.

Admin accounts can create users, reset passwords, change security settings, access sensitive areas of Microsoft 365 and alter tenant configuration. If an administrator account is compromised, the impact can be much wider than a single mailbox.

Check that:

  • All administrator accounts are protected with MFA
  • Global Administrator rights are limited
  • Admin roles are only assigned where needed
  • Old supplier or leaver admin accounts have been removed
  • Admin accounts are not used casually for day-to-day email
  • Emergency access accounts are documented and protected appropriately

Microsoft has also published guidance around mandatory MFA enforcement for Azure, Microsoft 365 and other admin portals. Microsoft’s mandatory MFA planning guidance explains the direction of travel for admin portal protection.

Check shared, service and old accounts

Normal user accounts are not the only risk. Shared accounts, service accounts and old leaver accounts can also create gaps.

Review:

  • Leaver accounts that still allow sign-in
  • Accounts used by scanners, applications or old systems
  • Shared accounts used by multiple staff
  • Accounts excluded from MFA policies
  • Accounts with old authentication methods
  • Accounts with mailbox access or forwarding rules

Where possible, shared accounts should be avoided or tightly controlled. Service accounts should be documented, limited and reviewed. Leaver accounts should be blocked and handled through a proper offboarding process.

Check for legacy authentication

Legacy authentication is a common weakness because older sign-in methods may not support modern MFA controls in the same way. Blocking legacy authentication is an important part of a secure Microsoft 365 setup.

Security defaults include legacy authentication protection, and Conditional Access can also be used to block legacy authentication where licensing and configuration allow. Microsoft includes legacy authentication protection as part of security defaults.

If legacy authentication is still allowed, review why it is needed and whether any old applications, devices or mail clients should be replaced or reconfigured.

What to do if some users do not have MFA

If your check finds users without MFA, do not simply enable everything without planning. MFA changes can affect users, mobile devices, remote access, admin accounts and older applications.

A sensible rollout usually includes:

  • Checking licensing and available MFA options
  • Deciding between security defaults and Conditional Access
  • Reviewing admin accounts first
  • Communicating the change to users
  • Helping users register Microsoft Authenticator or another approved method
  • Testing with a small group first, where appropriate
  • Removing unnecessary exclusions
  • Checking sign-in logs after rollout

For many businesses, this is also a good time to review wider Microsoft 365 security rather than treating MFA as a standalone task.

MFA is important, but it is not the whole security plan

MFA is essential, but it does not remove every Microsoft 365 risk. Attackers still use phishing, token theft, malicious consent, mailbox forwarding, weak admin processes and social engineering.

A stronger Microsoft 365 security setup should also consider:

  • Conditional Access policies
  • Administrator account protection
  • Mailbox forwarding rule monitoring
  • Phishing protection
  • Secure SharePoint and OneDrive sharing
  • Microsoft 365 backup
  • Endpoint protection
  • User awareness training
  • Sign-in and identity monitoring

We explain this broader approach in our guide: How to Secure a Microsoft 365 Account Before It Is Compromised.

Microsoft 365 MFA checklist

Use this checklist as a starting point:

  • Confirm whether security defaults, Conditional Access or per-user MFA is being used
  • Check all active users are covered by MFA
  • Check all administrator accounts are protected
  • Review Conditional Access exclusions
  • Check users are registered with suitable authentication methods
  • Review legacy authentication
  • Check old, shared and service accounts
  • Review sign-in logs for unusual activity
  • Document any exceptions
  • Retest regularly

Need help checking Microsoft 365 MFA?

KES helps businesses review Microsoft 365 security, including MFA, Conditional Access, admin accounts, sign-in monitoring, mailbox rules, backup and account protection.

If you are not sure whether MFA is properly enabled for all users, or if your setup has grown over time without a full review, KES can help check it properly.

You may also find these useful:

  • Microsoft 365 Security articles
  • KES Security Review
  • Business Email Exposure Check
  • Business User Pack

Want KES to check your Microsoft 365 MFA setup?

KES can review your Microsoft 365 users, MFA status, Conditional Access policies, admin accounts and sign-in security to help identify gaps before they become problems.

Speak to KES about Microsoft 365 MFA

Sources

  • Microsoft Learn: Set up multifactor authentication for Microsoft 365
  • Microsoft Learn: Configure security defaults for Microsoft Entra ID
  • Microsoft Learn: Require MFA for all users with Conditional Access
  • Microsoft Learn: Enable per-user multifactor authentication
  • Microsoft Learn: Authentication methods activity reports
  • Microsoft Learn: Plan for mandatory Microsoft Entra multifactor authentication
author avatar
Mark Roach
See Full Bio

Recent Posts

  • Microsoft Planner Is Adding Task Completion Percentages
  • Will Microsoft 365 Shared Calendars Stop Working in October?
  • What Are Passkeys, and Should Your Business Use Them?
  • Why Is the Microsoft 365 Copilot App Changing?
  • Microsoft Teams Can Block External AI Meeting Bots

Recent Comments

No comments to show.
KES logo: circular blue gradient with the letters KES in lighter blue

Kent Electronic Services (KES) Limited, provide IT managed services & support. Your trusted outsourced IT department provider.

Managed Services

  • Managed Services
  • Remote Monitoring & Management
  • Microsoft 365
  • M365 Cloud Backup
  • Referral Program
  • Contact Us
  • Terms & Conditions
  • Privacy
  • Sitemap

Our Address

Map showing Kent Electronic Services at The Friars in Aylesford Open in Google Maps

Copyright © 2026 - Kent Electronic Services (KES) Limited

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}