How to Roll Out MFA to Every Microsoft 365 User Without a Help Desk Meltdown
Retrospective: this article looks back at events from December 2016, written in 2026 with the benefit of hindsight.
Turning on multi-factor authentication for every Microsoft 365 user is the single most effective identity control you can deploy. It is also the change most likely to flood your help desk if you rush it. Here is a rollout plan that avoids both problems.
Before you start
- Check licensing. Entra ID P1 (included in Microsoft 365 Business Premium and E3/E5) gives you Conditional Access. Without it, use Security Defaults.
- Create two emergency access (break-glass) accounts excluded from your MFA policies and protected separately.
- Decide on methods: the Microsoft Authenticator app with number matching as the baseline; passkeys or FIDO2 keys for administrators.
Step 1: Communicate early
Tell users what is changing, why, and when, two weeks before enforcement. Include a short video or screenshots of the registration screens.
Step 2: Run a registration campaign
Use the authentication methods registration campaign in the Entra admin center to prompt users to set up Microsoft Authenticator at their next sign-in, before anything is enforced.
Step 3: Pilot
Create a Conditional Access policy requiring MFA for all cloud apps, scoped to IT and a group of volunteers. Run it in Report-only first, then enforce for the pilot group.
Step 4: Roll out in waves
Expand by department over two to four weeks. Watch sign-in logs for failures and the help desk queue after each wave.
Step 5: Close the gaps
- Block legacy authentication, which cannot do MFA.
- Find service accounts that sign in interactively and move them to managed identities or workload identities.
- Require stronger methods for admins.
Common mistakes
- Excluding executives "temporarily" — they are the most targeted.
- Allowing SMS as the primary method long-term.
- No process for lost phones. Define how the help desk verifies identity before resetting MFA.