Require phishing-resistant multifactor authentication for Microsoft Entra administrator roles - Microsoft Entra ID (original) (raw)

Overview

Accounts with privileged administrative roles are frequent targets of attackers. Requiring phishing-resistant multifactor authentication (MFA) for these accounts reduces the risk of compromise.

Microsoft recommends requiring phishing-resistant multifactor authentication for at least the following roles:

Organizations can include or exclude roles based on their requirements.

Organizations can use this policy with features like Privileged Identity Management (PIM), which lets you require MFA for role activation.

Authentication strength

This article helps your organization create an MFA policy for your environment using authentication strengths. Microsoft Entra ID offers three built-in authentication strengths:

Use one of the built-in strengths or create a custom authentication strength based on the authentication methods you want to require.

For external user scenarios, the MFA authentication methods that a resource tenant accepts vary depending on whether the user completes MFA in their home tenant or in the resource tenant. For more information, see Authentication strength for external users.

User exclusions

Conditional Access policies are powerful tools. We recommend excluding the following accounts from your policies:

Template deployment

Organizations can deploy this policy by following the steps outlined below or by using the Conditional Access templates.

Create a Conditional Access policy

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
  2. Browse to Entra ID > Conditional Access > Policies.
  3. Select New policy.
  4. Name your policy. Create a meaningful naming standard for your organization's policies.
  5. Under Assignments, select Users or workload identities.
    1. Under Include, select Directory roles and choose at least the previously listed roles.
    2. Under Exclude, select Users and groups, and choose your organization's emergency access or break-glass accounts.
  6. Under Target resources > Resources (formerly cloud apps) > Include, select All resources (formerly 'All cloud apps').
  7. Under Access controls > Grant, select Grant access.
    1. Select Require authentication strength, then select Phishing-resistant MFA strength from the list.
    2. Select Select.
  8. Confirm your settings, and set Enable policy to Report-only.
  9. Select Create to enable your policy.

After confirming your settings using policy impact or report-only mode, move the Enable policy toggle from Report-only to On.