AzureHow-To & HardeningRetrospectives

Azure Mandatory MFA Readiness Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2024, written in 2026 with the benefit of hindsight.

Use this checklist to confirm your organization is ready for Azure's mandatory MFA.

Phase 1 (portals)

  • All users accessing the Azure portal, Entra admin center and Intune admin center have an MFA method registered.
  • External and guest users who manage Azure resources can complete MFA.
  • Break-glass accounts have FIDO2 keys or certificate-based authentication registered.

Phase 2 (CLI, PowerShell, IaC, APIs)

  • Inventory of scripts and tools using Azure CLI, PowerShell, Terraform, Bicep, Ansible or REST APIs.
  • User accounts used for automation identified.
  • Each migrated to a managed identity or service principal (with federation or certificate).
  • Third-party tools confirmed compatible or updated.
  • Azure CLI and PowerShell modules updated to versions that support MFA flows.

Identity configuration

  • Conditional Access policies requiring MFA for Azure management (aligned with Microsoft's enforcement).
  • Phishing-resistant MFA for privileged Azure roles.
  • Workload identity least-privilege RBAC reviewed.

Communications

  • Administrators and developers informed of enforcement dates.
  • Help desk briefed.

Monitoring

  • Sign-in logs reviewed for MFA failures on Azure management apps.
  • Alerts for user accounts signing in non-interactively to Azure.

Postponement

  • If needed, postponement requested through Microsoft's process with a remediation plan.
azure mfa readiness checklistAzure mandatory MFA2024

More on this story