AzureCIO BriefingsRetrospectives

CIO Brief: Microsoft Now Requires MFA — Is Your Automation Ready?

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2024, written in 2026 with the benefit of hindsight.

The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also through command-line tools and automation. If any of your automated processes sign in as a person with a password, they will stop working.

Why Microsoft forced this

Attacks on cloud administration accounts are common and damaging. Microsoft decided MFA for Azure management should no longer be optional. For well-managed organizations, nothing changed. For others, it was a forced upgrade.

What can break

  • Scripts and tools that log in as a user account with a stored password.
  • Third-party tools connecting to Azure as a user.
  • Emergency accounts without a second factor.

The business impact

  • Improved security for cloud administration.
  • Risk of automation failures if not prepared — backups, deployments or monitoring scripts could stop.

Questions to ask your team

  • Do any automated processes sign in to Azure as a person?
  • Have we moved them to proper machine identities?
  • Do our emergency administrator accounts have MFA that will work during a crisis?
  • Did we request any postponement from Microsoft, and when does it end?

What good looks like

All automation using machine identities with least-privilege permissions, every person managing Azure using MFA (phishing-resistant for admins), and emergency accounts ready.

The decision

Ask for confirmation that no automated process depends on a user account signing in to Azure. If there are exceptions, set a deadline before they break unexpectedly.

azure mandatory mfa impactAzure mandatory MFA2024

More on this story