Introduction:
This guide provides a step-by-step process for enforcing Multi-Factor Authentication (MFA) for users in Microsoft 365 and verifying the availability of the app password authentication method. Enforcing MFA enhances security by requiring users to verify their identity using multiple methods before accessing organizational resources.
Process description:
The process involves enabling MFA for a specific user through the Microsoft Entra Admin Center and ensuring the app password option becomes available in the user’s Microsoft 365 account. This is essential for users who rely on older applications that do not support modern authentication methods.
Prerequisites:
-
Admin credentials for Microsoft 365
-
Access to Microsoft Entra Admin Center
-
The user must have an active Microsoft 365 account
-
MFA should not already be enforced for the user
Gathering materials/resources:
-
Admin login credentials for Microsoft 365
-
The full username or email address of the target user
-
Communication plan to inform the user about the MFA changes
Step-by-step instructions:
1. Log into Microsoft 365 Admin Center
-
Navigate to https://admin.microsoft.com
-
Sign in using your admin credentials
2. Access Active Users
-
From the left navigation panel, click Users > Active users
3. Search for the User
-
Enter the user’s name or email address into the search bar and click their name
4. Manage Multi-Factor Authentication
-
Under the user's profile, locate Multi-factor authentication and click Manage multi-factor authentication
-
A new browser tab will open to the Microsoft Entra Admin Center
5. Locate the User
-
You will need to scroll manually to find the user; search by name will not work
-
The user list is not sorted alphabetically
6. Enable MFA
-
Once located, check the box next to the user’s name
-
Click Enable at the top of the page
-
MFA will be automatically enforced—you do not need to click Enforce
7. Confirm Enforcement
-
Refresh the page
-
Under the Status column, you will see Enforced next to the user’s name
8. Verify App Password Option
-
Ask the user to log into https://office.com using their CPRS credentials
-
Click their profile icon (bottom left of the screen) > View account
-
Navigate to Security info > click Update security info
-
Click the + Add sign-in method
-
App password should now be visible as one of the sign-in method optionsNote: If the app password option is not available immediately after enforcing MFA, wait a few minutes for synchronization to complete.
Tips and best practices:
-
Inform the user before making changes to their account to avoid disruption
-
Always verify the enforcement status before concluding the process
Next steps:
-
Communicate with the user that MFA is now enforced
Additional information:
Disclaimer:
This guide is intended for authorized IT administrators.
Comments
0 comments
Please sign in to leave a comment.