Turning on multi-factor authentication in Microsoft 365
How to turn on multi-factor authentication (MFA) in Microsoft 365 — the single most effective step to protect your business email and files from hackers.
- Difficulty
- Beginner
Multi-factor authentication — also called MFA or two-factor authentication — adds a second check when someone signs in. Even if a hacker gets hold of a password, they can't get in without also having your phone.
Quick summary
MFA requires a second step after entering your password — usually approving a notification on your phone or entering a code from an app. It dramatically reduces the risk of your accounts being hacked. Admins turn it on for everyone from the Microsoft Entra admin center at entra.microsoft.com, not from the Microsoft 365 admin center. This is the most important security step you can take.
Why this matters
Password breaches are extremely common. A weak or reused password is all a hacker needs to access your email, files, and business data. MFA means that even if a password is stolen, the attacker still can't sign in without a second factor — your phone.
Microsoft says MFA can block more than 99.2% of account compromise attacks.
Microsoft is also making MFA compulsory for its own admin portals. It began requiring MFA to sign in to the Azure portal, the Microsoft Entra admin center and the Microsoft Intune admin center in October 2024, and started phasing it in for the Microsoft 365 admin center from February 2025. If your team already uses MFA, or signs in with a passkey, nothing changes for them.
Setting up MFA as an admin
Admin access required 10–15 minutesThere are two main ways to turn on MFA for your organization in Microsoft 365:
Option 1: Security defaults (simplest — recommended for most businesses)
Security defaults is Microsoft's pre-configured set of security policies designed for small businesses. Turning security defaults on requires all users to register for MFA, requires administrators to use MFA, and blocks legacy authentication protocols.
Sign in to the Microsoft Entra admin center at entra.microsoft.com with your Microsoft 365 admin account. (Identity settings moved here — they are no longer in the Azure portal, and they are not in the Microsoft 365 admin center.)
Open the identity Overview page. Microsoft's own articles label the menu above it either Entra ID or Identity, depending which one you read — either way you want Overview.
Select the Properties tab, then scroll to the Security defaults section at the bottom.
Click Manage security defaults.
Set Security defaults to Enabled and click Save.
Your tenant may already have this on
Microsoft words this two ways. Its Microsoft 365 admin documentation says tenants created after October 2019 have security defaults turned on by default; its Microsoft Entra documentation says a tenant created on or after 22 October 2019 might have them enabled. Either way, check the current status before you plan any work rather than assuming.
Tell your team before you turn this on
Once security defaults are enabled, every user is prompted to set up MFA when they sign in. Microsoft removed the old 14-day window for registering MFA on 29 July 2024, so the prompt comes straight away. (On a brand-new tenant Microsoft allows a 24-hour grace period before the protections are enforced.) Warn your team in advance so they're not confused when it appears.
Option 2: Conditional access policies (for more control)
If you need more control — for example, requiring MFA only for admin accounts, or only when signing in from outside the office — you can use Conditional Access policies. That needs a Microsoft Entra ID P1 licence or higher, which Microsoft 365 Business Premium includes and Business Basic and Business Standard do not.
Security defaults and Conditional Access can't both be on. While security defaults are enabled you can create Conditional Access policies but you can't switch them on, so you turn security defaults off first.
For most small businesses, security defaults (Option 1) is the right starting point.
Setting up MFA as a user
When you're first prompted to set up MFA after sign-in, here's what to expect:
Sign in as normal with your email and password.
A prompt appears telling you more information is needed to keep your account secure. Follow it.
Download the Microsoft Authenticator app on your phone — it's available from the App Store or Google Play. Then continue.
Open the Authenticator app on your phone and add a work account. Scan the QR code shown on your screen.
Approve the test notification. Microsoft will send a test push notification to your phone. Tap Approve in the app.
You're set up. From now on, when you sign in, you'll get a push notification to approve on your phone.
What happens at sign-in with MFA turned on
Enter your email address on the Microsoft sign-in page.
Enter your password and click Sign in.
A notification appears on your phone. Open the Microsoft Authenticator app and tap Approve (or enter a code if you're using the code method).
You're in. The whole process takes about 10 seconds once you're used to it.
Common questions
What if someone doesn't have a smartphone?
Text message (SMS) codes and automated voice calls have been available as alternatives, but Microsoft is retiring them. Since 1 September 2026, passkeys are the default sign-in experience and users who were set up for SMS or voice are being moved towards registering a passkey. Microsoft-provided SMS and voice delivery retires on 1 February 2027 for most users, and on 1 July 2027 for Global Administrators and external users.
So don't build around SMS. A hardware security key or a passkey is the better answer for someone without a suitable phone, and it's worth talking to us before you commit either way.
This one has a deadline
If anyone on your team relies on a text message or a phone call to sign in, they need to move to a phishing-resistant method — a passkey, Windows Hello, or a FIDO2 security key — before the retirement date that applies to them, or they will be blocked at sign-in until they register one.
What do I do if my phone is lost or stolen?
Contact your Microsoft 365 admin immediately. An admin can clear your registered sign-in methods so you can set up a new device. If you're the admin and can't get in, contact Microsoft support.
Will MFA affect signing in to the mobile apps?
You'll need to approve MFA when you first sign in to each app on a new device, but not every time you open the app. Once signed in, you stay signed in.
I turned on security defaults but I'm having problems. Can I turn them off?
Yes — go back to the same setting in the Microsoft Entra admin center and set security defaults to Disabled. However, we strongly recommend leaving them on: Microsoft's own advice is not to turn security defaults off unless you are switching to Conditional Access policies on Entra ID P1 or P2. If a specific problem arises (like a service that doesn't support MFA), contact us for help finding the right solution.
Related guides
- Security defaults & key settings
- The Microsoft 365 admin center, explained
- Signing in to Microsoft 365
- Turning on 2-step verification in Google Workspace
- Two-factor authentication, explained
Need a hand?
Learn more
Last updated
Microsoft 365 on your phone
How to set up and use Microsoft 365 apps on your iPhone, iPad, or Android phone — including Outlook, OneDrive, Teams, and Word.
Security defaults & key settings in Microsoft 365
The baseline security settings every Microsoft 365 business account should have — including security defaults, admin account protection, and app permissions.