Multi-Factor Authentication (MFA), also known as 2-Step Verification or Two-Factor Authentication (2FA), is an important security layer in Microsoft 365 (Office 365).
However, situations occur when an administrator must change, reset, or disable MFA for a user β for example:
User lost their phone
Authenticator app not working
Phone number changed
New device setup
Temporary MFA disable for troubleshooting
This article provides a step-by-step guide for Microsoft 365 administrators to modify, reset, or remove authenticator settings.
Before proceeding, ensure:
β You are logged into Microsoft 365 Admin Center
β Your account has Global Admin or Authentication Admin role
Follow these steps:
1οΈβ£ Open Microsoft 365 Admin Center β https://admin.microsoft.com
2οΈβ£ Navigate to:
Users β Active Users
3οΈβ£ Select the User
4οΈβ£ On right panel β Click Manage multifactor authentication
5οΈβ£ A new MFA dashboard will open
6οΈβ£ Select the user checkbox
7οΈβ£ Click Disable under Quick Steps
8οΈβ£ Confirm the action
9οΈβ£ Ask the user to sign-in again (MFA will no longer be required)
? Note: This only works if MFA is configured as Per-User MFA, NOT enforced by security defaults or conditional access.
Use this if a user lost phone or needs to re-register MFA:
1οΈβ£ Open Azure Active Directory / Entra Admin Center
2οΈβ£ Go to:
Users β All Users β Select User
3οΈβ£ Click Authentication Methods
4οΈβ£ Remove old phone, app enrollment, or methods
5οΈβ£ Click Require re-register MFA
6οΈβ£ Save changes
Next login β user will be prompted to set up MFA again successfully.
If MFA is still enforced, check these two places:
1οΈβ£ Go to
Azure AD β Properties β Manage Security Defaults
2οΈβ£ Toggle OFF
3οΈβ£ Save Changes
(For organizations using Entra ID Premium)
1οΈβ£ Azure AD β Security β Conditional Access
2οΈβ£ Edit policies enforcing MFA
3οΈβ£ Exclude user or remove enforcement temporarily
4οΈβ£ Save changes
β οΈ Disabling org-wide policies affects tenant security β use caution.
Depending on the authentication setup in your tenant, you must choose the correct method:
| Requirement | Best Method |
|---|---|
| Remove MFA completely for one user | Disable Per-User MFA |
| User lost mobile device | Reset MFA / Require re-registration |
| MFA still enforced | Check Security Defaults / Conditional Access |
With these steps, administrators can fully manage Microsoft 365 MFA settings without user interruption.
#Microsoft365 #Office365 #MFA #2FA #MultiFactorAuthentication #AuthenticatorApp #AzureAD #EntraID #MicrosoftAdmin #ITAdmin #SecurityDefaults #ConditionalAccess #AdminGuide #TechSupport #CloudSecurity #IdentityManagement #MicrosoftSecurity #ResetMFA #DisableMFA #UserAuthentication #MicrosoftTutorial #AdminCenter #TechHowTo #AuthenticationSetup #ITSecurity #CyberSecurity #EnterpriseSecurity #SecureLogin #TechTraining #UserManagement #PasswordSecurity #MicrosoftHelp #AccountRecovery #AuthenticatorReset #M365Security #AzureSecurity #SignInSupport #DeviceManagement #CorporateSecurity #SystemAdmin #LoginTroubleshoot #DataProtection #SecurityAdmin #BusinessIT #ITSupport #AccountSecurity #AdminTraining #TechArticle #CloudAdmin #SecureAccess