Microsoft is making Multi-Factor Authentication (MFA) mandatory for all sign-ins to its cloud platform, Microsoft Azure in October 2024. The move is designed to secure the use of Azure more tightly, reducing chances for unauthorized access in enterprises.
Any of the traditional approach to login, where user need to recall his password is seriously heavily vulnerable against any attack like brute force/ phishingMinimal access accounts for users. MFA adds a second form of verification, such as entering a one-time code that was sent by your service through email, via SMS or another means into the login process to make it much harder for nefarious individuals to access an account.
Microsoft Azure’s MFA enforcement will be rolled out in two phases:
The benefits of enforcing MFA on Microsoft Azure are extensive:
To prepare for the upcoming changes, businesses should:
Microsoft Azure offers several ways to implement MFA through Microsoft Entra:
Microsoft will also continue to support external MFA solutions and federated identity providers, as long as they send the required MFA claim.
Enforcing Mandatory MFA on Microsoft Azure is a fundamental move in fashioning a sound, conducive cloud ecosystem. Microsoft will implement this another round of security specifically to provide a better protection for businesses that use Azure and their sensitive data or resources. By preparing for this change now you would be better suited to transitioning your business and hardening its cloud security overall.
Multi-Factor Authentication (MFA) on Microsoft Azure requires users to provide a second form of verification, in addition to their password, when signing in to the platform.
The enforcement will begin in October 2024 for core admin portals, with the second phase covering all Azure clients starting in early 2025.
MFA adds an extra layer of security, reducing the risk of unauthorized access, even if a password is compromised.
Microsoft Azure offers options such as the Microsoft Authenticator app, FIDO2 security keys, certificate-based authentication, passkeys, and SMS or voice approval.
Businesses should plan ahead by monitoring Microsoft’s communications, preparing for MFA deployment, and reaching out for extended timelines if necessary.