how to require mfa for all users with entra conditional access
Builds an Entra Conditional Access policy that requires MFA for every user on every sign-in. Covers policy scoping, the grant control, break-glass exclusions, and safe rollout through report-only mode. Use when enforcing org-wide MFA. Not for per-app MFA exceptions, which belong in separate targeted policies.
TL;DR
Create a Conditional Access policy targeting all users and all cloud apps with the grant control set to require MFA, but start it in report-only mode. Watch the insights for a week to find service accounts, legacy protocols, and users who never registered MFA, fix those, exclude only the break-glass emergency accounts, and then flip the policy on. Flipping it on blind is how you lock out the whole company on a Monday morning.
Steps
- In Entra admin go to Protection > Conditional Access > Create new policy. Give it a clear name like "Require MFA for all users". Expected: a new policy saved in report-only or off state.
- Under Users select All users, then exclude your break-glass emergency accounts, and only those. Expected: the exclusion list contains the break-glass accounts and nothing else.
- Under Target resources select All cloud apps. Expected: the policy covers every app, not a hand-picked list that someone will forget to extend.
- Under Grant select Require multifactor authentication. Leave session controls off for version one. Expected: the grant control is set with the operator requiring all selected controls.
- Enable report-only mode and watch the insights for a week: see who would be blocked. Expected: the report shows affected users with zero actual blocks. Close the SSPR registration gaps and legacy-auth usage it reveals, then switch the policy to On.
Use this when
- Enforcing MFA org-wide for the first time
- Auditors or cyber insurance require MFA for all users
- Replacing a patchwork of per-app MFA rules with one baseline
Not for this skill when
- You only need MFA on specific sensitive apps (use a targeted policy)
- The tenant has no break-glass accounts yet (create those first, then enforce)
- Users have not been told MFA is coming (communicate before the flip, not after)
Compatibility
- Entra ID P1 or P2 (Conditional Access needs P1+)
- Microsoft Authenticator or equivalent MFA methods registered by users
Variants
Legacy protocols like IMAP and POP are in the environment
These protocols cannot do MFA at all. Add a companion policy blocking legacy authentication.
Phased rollout by department
Scope the Users selector to a pilot group first, validate, then widen to All users.
Why it happens
MFA for everyone is the single highest-leverage identity control, but enforcing it blind breaks service accounts, legacy protocols, and users who never registered a method. Report-only mode surfaces all of that before any user feels it.
Edge cases
- Service accounts and automation: exclude them by named account and give them their own policy with a different control. Never blanket-exempt them silently.
- Guest users: decide explicitly whether the policy includes guests and document the choice.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_kg5FtjvuucesuV84Flw8KA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.