Skip to content
WindowsBeginner

How to Change or Remove Microsoft 365 Multi-Factor Authentication (MFA) / Authenticator Settings for Any User from Admin Center

Multi-Factor Authentication (MFA), also known as 2-Step Verification or Two-Factor Authentication (2FA), is an important security layer in Microsoft 365 (Off...

BI
Bison Technical Team Enterprise IT specialists
Updated 27 Nov 2025 2 min read 995 total views

Multi-Factor Authentication (MFA), also known as 2-Step Verification or Two-Factor Authentication (2FA), is an important security layer in Microsoft 365 (Office 365).
However, situations occur when an administrator must change, reset, or disable MFA for a user — for example:

  • User lost their phone

    Advertisement
  • Authenticator app not working

  • Phone number changed

  • New device setup

  • Temporary MFA disable for troubleshooting

This article provides a step-by-step guide for Microsoft 365 administrators to modify, reset, or remove authenticator settings.


? Prerequisites

Before proceeding, ensure:

✔ You are logged into Microsoft 365 Admin Center
✔ Your account has Global Admin or Authentication Admin role


? Part 1 — How to Disable MFA for a Specific User (Per-User MFA)

Follow these steps:

1️⃣ Open Microsoft 365 Admin Center → https://admin.microsoft.com
2️⃣ Navigate to:
Users → Active Users
3️⃣ Select the User
4️⃣ On right panel → Click Manage multifactor authentication
5️⃣ A new MFA dashboard will open
6️⃣ Select the user checkbox
7️⃣ Click Disable under Quick Steps
8️⃣ Confirm the action
9️⃣ Ask the user to sign-in again (MFA will no longer be required)

? Note: This only works if MFA is configured as Per-User MFA, NOT enforced by security defaults or conditional access.


? Part 2 — Reset MFA/Authenticator for a User (Without Disabling MFA)

Use this if a user lost phone or needs to re-register MFA:

1️⃣ Open Azure Active Directory / Entra Admin Center
2️⃣ Go to:
Users → All Users → Select User
3️⃣ Click Authentication Methods
4️⃣ Remove old phone, app enrollment, or methods
5️⃣ Click Require re-register MFA
6️⃣ Save changes

Next login → user will be prompted to set up MFA again successfully.


? Part 3 — Remove Organization-Wide MFA Enforcement

If MFA is still enforced, check these two places:

A) Disable Security Defaults

1️⃣ Go to
Azure AD → Properties → Manage Security Defaults
2️⃣ Toggle OFF
3️⃣ Save Changes

B) Check Conditional Access Policies

(For organizations using Entra ID Premium)

1️⃣ Azure AD → Security → Conditional Access
2️⃣ Edit policies enforcing MFA
3️⃣ Exclude user or remove enforcement temporarily
4️⃣ Save changes

⚠️ Disabling org-wide policies affects tenant security — use caution.


? Conclusion

Depending on the authentication setup in your tenant, you must choose the correct method:

RequirementBest Method
Remove MFA completely for one userDisable Per-User MFA
User lost mobile deviceReset MFA / Require re-registration
MFA still enforcedCheck Security Defaults / Conditional Access

With these steps, administrators can fully manage Microsoft 365 MFA settings without user interruption.


#Microsoft365 #Office365 #MFA #2FA #MultiFactorAuthentication #AuthenticatorApp #AzureAD #EntraID #MicrosoftAdmin #ITAdmin #SecurityDefaults #ConditionalAccess #AdminGuide #TechSupport #CloudSecurity #IdentityManagement #MicrosoftSecurity #ResetMFA #DisableMFA #UserAuthentication #MicrosoftTutorial #AdminCenter #TechHowTo #AuthenticationSetup #ITSecurity #CyberSecurity #EnterpriseSecurity #SecureLogin #TechTraining #UserManagement #PasswordSecurity #MicrosoftHelp #AccountRecovery #AuthenticatorReset #M365Security #AzureSecurity #SignInSupport #DeviceManagement #CorporateSecurity #SystemAdmin #LoginTroubleshoot #DataProtection #SecurityAdmin #BusinessIT #ITSupport #AccountSecurity #AdminTraining #TechArticle #CloudAdmin #SecureAccess

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “How to Change or Remove Microsoft 365 Multi-Factor Authentication (MFA) / Authenticator Settings for Any User from Admin Center”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.