Microsoft Enforces Mandatory MFA for Microsoft 365 Admin Center Logins
ID: da544fcc-d9bc-5b45-9bee-653041e6feed
STIX ID: report--da544fcc-d9bc-5b45-9bee-653041e6feed
Feed Name: cybersecurityNews.com
Microsoft will enforce MFA for all Microsoft 365 admin center users starting February 9, 2026, blocking logins without MFA across specified admin portals; organizations should enable MFA via the setup wizard or documentation, confirm methods (Authenticator app, SMS, hardware tokens), and audit accounts—especially in hybrid Entra ID/Active Directory environments—to prevent access issues. The mandate aligns with zero-trust and common compliance frameworks (SOC 2, HIPAA, NIST), aims to curb phishing and credential-stuffing risks, and may foreshadow similar requirements for other high-risk admin surfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
