Roll out MFA as a controlled identity change. Prepare recovery, include privileged accounts and test ordinary work before expanding enforcement.
Find the identities behind the user count
A staff list may miss administrators, guests, shared-resource access and accounts used by applications. Identify the identities involved and the systems they reach before choosing a policy. Do not assume that every account can use the same method or follows the same sign-in path.
Record the business owner for exceptions. An exception without an owner and review date can become a permanent gap. Where an older dependency cannot support the intended control, investigate a supported alternative and document any approved transition.
Prepare recovery before enforcement
| Readiness item | Evidence |
|---|---|
| Administrator access | Authorised recovery arrangements are understood and tested appropriately. |
| User registration | People know the approved method and how to register. |
| Lost device | A controlled support route exists without sharing another person’s credentials. |
| Application dependencies | Affected services and their owners are identified. |
| Pilot users | Representative roles and devices are included. |
| Rollback decision | The authorised administrator knows when and how to stop a problematic rollout. |
Choose the policy for the actual tenant
Microsoft documents security defaults and Conditional Access as different approaches with different capabilities and entitlement requirements. Review the current tenant configuration and licences before prescribing either. Do not blindly layer settings from a generic checklist.
A buying conversation should establish which identities are covered, which methods are supported and who maintains the policy. A licence line on an invoice is not evidence that the intended accounts are enrolled or that recovery has been considered.
Test the work people need to do
Use authorised test identities and representative devices to verify normal access, expected challenges and intended restrictions. Include remote work and important business applications where they are in scope. Record the result without exposing authentication secrets.
Tell users what an expected prompt looks like and where to report an unexpected one. They should not approve an authentication request simply because it appears on a phone. The reporting route is part of the rollout, not an optional note after enforcement.
Close the rollout with an exception record
- Which identities are covered and which are not?
- Which registration or application issues remain?
- Who owns each exception and the next action?
- How are new starters and departures incorporated?
- When will recovery and policy ownership be reviewed?
MFA reduces certain account risks; it does not make an organisation immune to phishing, session misuse or poor access decisions. Keep it within the wider identity and cybersecurity scope.
Sources and further reading
Put the decision into practice
Share the tenant, user groups and access concerns so the appropriate Microsoft 365 scope can be assessed.
Explore Microsoft 365 & Email Security Discuss the requirement by email