Microsoft is enforcing mandatory multi-factor authentication (MFA) for all users accessing the Microsoft 365 admin center, with the policy taking full effect on February 9, 2026. This move follows a phased rollout that began in February 2025 and targets key administrative portals, including portal.office.com/adminportal/home, admin.cloud.microsoft, and admin.microsoft.com. Administrators without MFA enabled will be blocked from signing in, and Microsoft urges organizations to act immediately to avoid disruptions to IT operations and administrative functions. The enforcement is part of Microsoft's broader strategy to combat credential-based attacks, which remain a leading cause of security breaches.
By requiring MFA, Microsoft aims to significantly reduce the risk of account compromise, prevent unauthorized access, and safeguard sensitive data managed through the admin center. The company highlights that MFA is a critical defense against phishing, credential stuffing, brute-force attacks, and password reuse. Administrators are advised to use the MFA Wizard or official documentation to configure organization-wide MFA, while individual users can verify or add authentication methods through the designated setup portal. This policy aligns with Microsoft's ongoing efforts to strengthen identity security, including previous enforcement of MFA for Azure Portal sign-ins across all tenants.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Full enforcement is set to begin on this date, making MFA mandatory for Microsoft 365 admin center access across key administrative URLs. Users and administrators without MFA configured will be unable to sign in.
Microsoft announced that starting February 9, 2026, all users accessing the Microsoft 365 admin center will be required to use MFA and non-MFA sign-ins will be blocked. The company warned organizations to enable MFA before the deadline to avoid administrative lockouts and service disruptions.
Microsoft scheduled broader MFA enforcement for Azure CLI, PowerShell, SDKs, and APIs, extending mandatory stronger authentication beyond web portals. This expanded the company's MFA requirements across administrative and programmatic access paths.
Microsoft began enforcing MFA for Azure Portal access as part of its broader effort to require stronger authentication for administrative and cloud management interfaces. The change was cited as part of the company's wider MFA enforcement program.
Microsoft started a phased rollout of multi-factor authentication requirements for users accessing the Microsoft 365 admin center. This marked the beginning of the transition away from password-only sign-ins for administrative access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.