## TL;DR
Create a Conditional Access policy targeting all users and all cloud apps with the grant control set to require MFA, but start it in report-only mode. Watch the insights for a week to find service accounts, legacy protocols, and users who never registered MFA, fix those, exclude only the break-glass emergency accounts, and then flip the policy on. Flipping it on blind is how you lock out the whole company on a Monday morning.

## Steps
1. In Entra admin go to Protection > Conditional Access > Create new policy. Give it a clear name like "Require MFA for all users". Expected: a new policy saved in report-only or off state.
2. Under Users select All users, then exclude your break-glass emergency accounts, and only those. Expected: the exclusion list contains the break-glass accounts and nothing else.
3. Under Target resources select All cloud apps. Expected: the policy covers every app, not a hand-picked list that someone will forget to extend.
4. Under Grant select Require multifactor authentication. Leave session controls off for version one. Expected: the grant control is set with the operator requiring all selected controls.
5. Enable report-only mode and watch the insights for a week: see who would be blocked. Expected: the report shows affected users with zero actual blocks. Close the SSPR registration gaps and legacy-auth usage it reveals, then switch the policy to On.

## Use this when
- Enforcing MFA org-wide for the first time
- Auditors or cyber insurance require MFA for all users
- Replacing a patchwork of per-app MFA rules with one baseline

## Not for this skill when
- You only need MFA on specific sensitive apps (use a targeted policy)
- The tenant has no break-glass accounts yet (create those first, then enforce)
- Users have not been told MFA is coming (communicate before the flip, not after)

## Compatibility
- Entra ID P1 or P2 (Conditional Access needs P1+)
- Microsoft Authenticator or equivalent MFA methods registered by users

## Variants
### Legacy protocols like IMAP and POP are in the environment
These protocols cannot do MFA at all. Add a companion policy blocking legacy authentication.
### Phased rollout by department
Scope the Users selector to a pilot group first, validate, then widen to All users.

## Why it happens
MFA for everyone is the single highest-leverage identity control, but enforcing it blind breaks service accounts, legacy protocols, and users who never registered a method. Report-only mode surfaces all of that before any user feels it.

## Edge cases
- Service accounts and automation: exclude them by named account and give them their own policy with a different control. Never blanket-exempt them silently.
- Guest users: decide explicitly whether the policy includes guests and document the choice.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_kg5FtjvuucesuV84Flw8KA
