CIO Brief: Microsoft Now Requires MFA — Is Your Automation Ready?
Retrospective: this article looks back at events from October 2024, written in 2026 with the benefit of hindsight.
The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also through command-line tools and automation. If any of your automated processes sign in as a person with a password, they will stop working.
Why Microsoft forced this
Attacks on cloud administration accounts are common and damaging. Microsoft decided MFA for Azure management should no longer be optional. For well-managed organizations, nothing changed. For others, it was a forced upgrade.
What can break
- Scripts and tools that log in as a user account with a stored password.
- Third-party tools connecting to Azure as a user.
- Emergency accounts without a second factor.
The business impact
- Improved security for cloud administration.
- Risk of automation failures if not prepared — backups, deployments or monitoring scripts could stop.
Questions to ask your team
- Do any automated processes sign in to Azure as a person?
- Have we moved them to proper machine identities?
- Do our emergency administrator accounts have MFA that will work during a crisis?
- Did we request any postponement from Microsoft, and when does it end?
What good looks like
All automation using machine identities with least-privilege permissions, every person managing Azure using MFA (phishing-resistant for admins), and emergency accounts ready.
The decision
Ask for confirmation that no automated process depends on a user account signing in to Azure. If there are exceptions, set a deadline before they break unexpectedly.
- Mandatory MFA for the Azure Portal Begins (Oct 2024) Platform Changes
- How to Prepare Service Accounts and Automation for Azure Mandatory MFA How-To & Hardening
- Azure Mandatory MFA Readiness Checklist How-To & Hardening