Multi-Factor Authentication protects accounts from unauthorized access, but there are times when you may need to turn it off for a specific user. Lost phones, broken devices, or account recovery scenarios often require temporary MFA removal.

This guide explains how to disable MFA for a user in Microsoft 365, step by step, while minimizing security risks.

What Does Disabling MFA Mean in Microsoft 365?

Disabling MFA removes the requirement for a second authentication factor during sign-in.

MFA vs Password-Only Sign-In

With MFA disabled:

Temporary vs Permanent MFA Removal

In most cases, MFA should be disabled temporarily, not permanently.

When You Might Need to Disable MFA

Lost or Replaced Devices

If a user loses access to their authenticator app or phone, MFA must be disabled or reset.

User Locked Out

Repeated failed MFA attempts can prevent sign-in entirely.

Service or Shared Accounts

Some service accounts can’t complete MFA and require exclusions.

MFA Methods Used in Microsoft 365

Microsoft 365 supports MFA through several enforcement methods managed by Microsoft.

Security Defaults

Per-User MFA

Conditional Access

Things to Check Before Disabling MFA

Admin Roles and Permissions

You must be a:

License Requirements

Conditional Access requires Entra ID P1 or higher.

Security Impact

Disabling MFA increases risk. Always confirm business justification.

How to Disable MFA for a User in Microsoft 365

Before making changes, identify how MFA is enforced for the user.

Disable MFA Using Per-User MFA

Step 1: Open Admin Center

Go to:

https://admin.microsoft.com

Step 2: Access Per-User MFA

Step 3: Disable MFA

MFA is removed immediately.

Disable MFA Using Conditional Access

Exclude User from MFA Policy

  1. Open Entra Admin Center

  2. Go to Conditional Access

  3. Select the MFA policy

  4. Exclude the user or group

  5. Save changes

Modify or Disable the Policy

For temporary access, consider:

Test the Change

Sign out and test sign-in to confirm MFA is no longer prompted.

Disable MFA for Admin Accounts

Emergency Access Accounts

Emergency accounts are often excluded from MFA for recovery scenarios. Limit their use and monitor sign-ins closely.

Temporary Admin Exclusions

If an admin loses MFA access:

Common Issues When Disabling MFA

MFA Still Prompting

Possible causes:

Multiple Policies Applied

Review sign-in logs to see which policies evaluated.

Security Defaults Overriding Changes

Security Defaults override per-user settings and must be disabled to exclude users.

Security Risks and Best Practices

Limit MFA Disable Duration

Disable MFA only as long as needed.

Use MFA Reset Instead

Often, resetting MFA methods is safer than disabling MFA entirely.

Audit MFA Changes

Track who disabled MFA and why. Review audit logs regularly.

FAQs About Disabling MFA in Microsoft 365

Can I disable MFA for one user only?

Yes, using Per-User MFA or Conditional Access exclusions.

How long does it take for MFA to be disabled?

Usually immediate, though session tokens may delay results.

Is disabling MFA logged?

Yes. Changes appear in audit and sign-in logs.

✅ Final Thoughts

Knowing how to disable MFA for a user in Microsoft 365 is essential for account recovery and support scenarios. The key is choosing the right method and minimizing risk.

Whenever possible: