MFA — Multi-Factor Authentication
Category: cloud
Last reviewed by the MSLicenseHub Licensing Desk.
Multi-Factor Authentication (MFA) is a security protocol that requires users to provide two or more distinct forms of identification before granting access to a Microsoft 365 or Azure resource. These factors typically include something the user knows (a password), something the user has (a mobile device or hardware token), or something the user is (biometric data like a fingerprint or facial scan).
Licensing Tiers and Enforcement Mechanisms
In the Microsoft ecosystem, MFA is not a single product but a capability delivered through different licensing levels, each offering varying degrees of control:
- Security Defaults: Included at no extra cost with all Microsoft 365 and Azure subscriptions. It enforces basic MFA for all users via the Microsoft Authenticator app but lacks granular customization.
- Microsoft Entra ID P1 (included in Business Premium and E3): Introduces Conditional Access. This allows administrators to set specific rules for when MFA is challenged (e.g., "require MFA only when logging in from outside the office" or "require MFA for users with administrative roles").
- Microsoft Entra ID P2 (included in E5): Adds Risk-Based Conditional Access, which uses machine learning to automatically trigger MFA if a login attempt appears suspicious or originates from a leaked credential.
Mandatory Enforcement and Evolution
Microsoft has transitioned from MFA being an optional security feature to a mandatory requirement. For all new tenants, Security Defaults are enabled by default. For existing tenants, Microsoft is executing a phased rollout through 2026 that mandates MFA for all users accessing administrative portals (such as the Azure Portal, Entra Admin Center, and Intune Admin Center), regardless of their specific license level.
Common Misunderstandings
- "MFA requires a P1 license": While advanced management requires P1, basic MFA is free for all users via Security Defaults.
- "MFA is only for admins": While Microsoft prioritizes admin accounts, modern security standards and many cyber insurance policies require MFA for all standard user accounts.
- SMS vs. App-based: Microsoft is actively moving away from SMS/Voice-based MFA due to "SIM swapping" risks, favoring the Authenticator App or FIDO2 hardware keys.
Related Terms
- Conditional Access: The policy engine used to deploy MFA based on specific signals (location, device state, or application).
- Passwordless Authentication: An advanced form of MFA where the password is removed entirely in favor of biometrics or hardware tokens.
- Self-Service Password Reset (SSPR): A feature often configured alongside MFA that allows users to reset their own passwords using their MFA factors.
Practical Buying Advice
When reviewing a quote or Enterprise Agreement (EA), MFA capabilities are rarely listed as a line item. Instead, look for Microsoft Entra ID (formerly Azure AD) or Microsoft 365 Business Premium/E3/E5 suites. If your organization requires specific compliance rules—such as exempting trusted office IP addresses from MFA prompts—you must ensure your quote includes at least Entra ID P1. Organizations relying on basic Business Basic or Standard licenses will be limited to the "all or nothing" approach of Security Defaults.
Need this in a quote?
Our team translates glossary concepts into concrete licenses, part numbers and price lists.
Request a quote