Microsoft 365 Admin MFA: The Deadline Has Passed

by | Feb 10, 2026 | Cybersecurity

Home  ›  Blog  ›  Current Post

What Every Small Business Owner Needs to Know — Before They Get Locked Out or Taken Over

By Dayton Allied Business Solutions  ·  Published February 2026

On February 9, 2026, Microsoft completed its phased enforcement of mandatory multi-factor authentication for all Microsoft 365 admin center sign-ins. If you manage a Microsoft 365 tenant and your admin accounts were not set up with MFA by that date, you are now blocked from signing into the admin portal. Not warned. Blocked.

If you are reading this because something stopped working, this article will tell you exactly what happened and how to recover. If you are reading this proactively, it will tell you how to make sure this never becomes your emergency.

And if you think this is a minor configuration issue that can wait until next week, the threat data from 2025 should change your mind.

What Microsoft Did and Why It Matters

Microsoft’s mandatory MFA rollout for admin accounts is part of its Secure Future Initiative, a sweeping security program announced in 2023 in response to high-profile cloud compromises — including a state-sponsored breach of Microsoft’s own email systems. The rollout happened in phases:

  • October 2024: MFA required for Azure portal, Microsoft Entra admin center, and Intune admin center
  • February 2025: MFA enforcement began rolling out to Microsoft 365 admin center (portal.office.com, admin.microsoft.com, admin.cloud.microsoft)
  • February 9, 2026: Full enforcement completed — any admin user without MFA is now blocked from signing in
  • October 2025 onward: Phase 2 enforcement expanding to Azure CLI, PowerShell, SDKs, and REST APIs

The reason Microsoft is pushing this hard is straightforward: admin accounts without MFA are one of the most reliable entry points for complete tenant takeover. A global admin account with only a password is not a secure credential in 2025 — it is an invitation.

99.99% of MFA-protected accounts successfully block hacking attempts, even when the password is compromised (Microsoft internal research)

Source: Microsoft Learn — Plan for mandatory Microsoft Entra MFA

Why Attackers Target Admin Accounts Specifically

It is worth being precise about what an attacker can do with a compromised global admin account, because “full access” understates it.

A global admin in Microsoft 365 can read every user’s email, access every file in SharePoint and OneDrive, reset any user’s password including executives, create new admin accounts, delete existing ones, change MFA settings for all users, configure mail forwarding rules to external addresses, access audit logs — and disable them. One account. One password. Everything.

Attackers can initiate Business Email Compromise actions — including creating inbox forwarding rules — in as little as 14 minutes after gaining access to a Microsoft 365 account. (eSentire, 2025 Year in Review)

The scale of targeting is not theoretical. Account compromise surged 389% year over year in 2025, according to eSentire’s January 2026 threat report. Credential theft accounted for 74% of all observed cyber threats. Microsoft 365 accounts were specifically called out as prime targets throughout the year.

Proofpoint tracked attempted account compromises affecting nearly 3,000 user accounts across more than 900 Microsoft 365 environments in 2025 alone — with a confirmed success rate exceeding 50%. The attacks used legitimate-looking shared document links, OAuth application tricks, and adversary-in-the-middle phishing kits that can intercept MFA codes in real time.

According to Microsoft’s own data, attackers make 4,000 password compromise attempts per second against Microsoft cloud accounts. Admin accounts without MFA are the highest-value targets in that constant stream of attacks.

Source: eSentire 2025 Year in Review & 2026 Threat Landscape Outlook

The Most Common Ways Businesses Got Caught Unprepared

The businesses that ran into trouble after the February 9 deadline almost universally fell into one of these patterns. If any of these describe your current setup, they need to be addressed even if enforcement hasn’t hit you yet.

Only One Admin Account

Many small businesses have a single global admin account — often set up years ago, sometimes shared, sometimes tied to a former employee’s contact information. When MFA enforcement hits and that account can’t complete authentication, there is no fallback. You are locked out of your own tenant.

MFA Tied to One Person’s Phone

Even when MFA is enabled, it is often configured with only a single authentication method — typically a text message or authenticator app on one specific phone. If that person leaves, loses their phone, or gets a new number, the MFA cannot be completed and the account becomes inaccessible.

Former Employee Contact Information Still Attached

Admin accounts that were set up by previous IT staff or a past employee often still have that person’s phone number or email registered as the MFA recovery method. The account exists, MFA is technically enabled, but no one at the current organization can complete the authentication.

Shared Admin Credentials

A shared admin account — one username and password used by multiple people — creates an MFA problem even before enforcement: whose phone does the code go to? Shared credentials are also a security liability independent of MFA, because there is no way to audit who took what action, and no clean way to revoke access when one person leaves.

MFA Set Up but Never Tested

This is more common than it should be. MFA is configured, the settings look correct in the portal, but no one has actually walked through the complete admin sign-in flow to verify it works end to end. The first time it is tested is during an emergency or after enforcement blocks access.

How to Review and Fix Your Admin MFA Setup

If you have admin access right now, use it to audit your setup before something changes. Here is what to check.

Step 1 — Identify Every Admin Account in Your Tenant

In the Microsoft 365 admin center, go to Users > Active Users and filter by admin roles. In the Microsoft Entra portal, go to Roles and Administrators. List every account that holds a privileged role: Global Admin, Security Admin, Exchange Admin, SharePoint Admin, Teams Admin, Billing Admin, and Helpdesk Admin.

If you find shared accounts — generic email addresses not tied to a specific person — flag those immediately. They need to be replaced with individual accounts.

Step 2 — Verify MFA Is Enabled and Has Backup Methods

For each admin account, confirm that MFA is enabled and that at least two authentication methods are registered — not just one. The Microsoft Authenticator app is the preferred primary method. A backup method (a second phone, a hardware key, or backup codes stored securely offline) should also be in place. Check that the registered phone numbers and email addresses belong to people who are currently at the organization.

Step 3 — Create a Break Glass Emergency Account

A break glass account is a global admin account held in reserve specifically for emergency access — if all other admin accounts fail or become inaccessible. It should be a cloud-only account (not synced from on-premises Active Directory), use a complex password stored securely offline, have MFA registered to a dedicated device not used for anything else, and be excluded from Conditional Access policies that could block access during an emergency. Microsoft explicitly recommends this in its admin security guidance. Most small businesses do not have one.

Step 4 — Check Whether You Are Using Security Defaults or Conditional Access

Microsoft enforces admin MFA in one of two ways. Security Defaults is a free, baseline policy that enforces MFA for all admin accounts and is on by default in newer tenants. Conditional Access is a more granular system available in Microsoft 365 Business Premium and higher plans that allows you to define exactly when and how MFA is required.

You need to know which is active in your tenant and whether it is correctly configured. Tenants with older configurations may have Security Defaults turned off and no Conditional Access policy in place — meaning MFA enforcement may not be functioning at all, regardless of what the individual account settings show.

Step 5 — Test the Login Flow

Actually log in using each admin account through the standard sign-in portal and complete MFA. Do not assume it works. If a backup method is registered, test that too. Document the results.

A Note on MFA Methods: Not All Are Equal

If your admin accounts are using SMS text messages as the MFA method, that needs to change.

SMS-based MFA is considered the weakest form of multi-factor authentication. Attackers can intercept it through SIM swapping — convincing a mobile carrier to transfer your phone number to their SIM card — or through real-time phishing kits that prompt you to enter a code and immediately replay it to complete an unauthorized login. Microsoft, CISA, and NIST have all issued guidance recommending against SMS as an MFA method for privileged accounts.

For admin accounts, the recommended methods in order of strength are:

  • FIDO2 hardware security keys (strongest — phishing-resistant by design, cannot be intercepted)
  • Microsoft Authenticator passkeys or number-matching push notifications
  • Certificate-based authentication
  • Microsoft Authenticator app with number matching (acceptable for most SMBs)
  • TOTP authenticator apps (Google Authenticator, Authy)
  • SMS or voice call (weakest — avoid for admin accounts specifically)

If your Microsoft 365 plan includes Conditional Access — available in Business Premium — you can enforce phishing-resistant MFA methods specifically for admin roles while allowing standard methods for regular users.

Source: Microsoft Learn — Protect Microsoft 365 from on-premises attacks

If You Are Already Locked Out

⚠  If you are completely locked out of your Microsoft 365 admin center with no accessible admin account, you will need to contact Microsoft Support directly. Have your organization’s billing information and domain verification details ready. Recovery without an accessible account is possible but requires working through Microsoft’s identity verification process, which can take time.

Before escalating to Microsoft, check these things first:

  • Are there other admin accounts in the tenant? Even one accessible admin account can reset MFA settings for others.
  • Does the blocked account have a registered backup email or phone that is still accessible? If so, you may be able to complete MFA registration through the self-service portal at aka.ms/mfasetup.
  • Is there a partner or IT provider relationship attached to the tenant? Partners with delegated admin access may be able to assist with recovery.

Going forward, the break glass account described above is specifically designed to prevent this situation from ever happening again.

Best Practice Admin Account Structure for Small Businesses

Here is what a well-configured Microsoft 365 admin setup looks like for a small business:

  • A minimum of two individual global admin accounts — each tied to a named person, not a shared mailbox
  • One break glass emergency account — stored securely offline, tested quarterly
  • All admin accounts using authenticator app MFA with at least one registered backup method
  • Role-based access — not everyone needs Global Admin; use the least-privileged role that gets the job done
  • Regular review of admin role assignments — former employees and stale accounts removed promptly
  • Conditional Access policy requiring MFA for all admin sign-ins (if on Business Premium or higher)
  • Admin accounts not used for day-to-day email or web browsing — separate daily-use accounts for those activities

The last point deserves emphasis. Using an admin account as your regular work account for email, document editing, and general browsing dramatically increases the attack surface. Every phishing email, every malicious link, every compromised website your admin account browses is a potential entry point to full tenant control. Administrators should have a separate, unprivileged account for daily work.

What Is Coming Next: Phase 2 Is Already in Effect

If you manage Microsoft 365 and also use Azure CLI, Azure PowerShell, SDKs, or REST APIs for scripting and automation, Phase 2 of Microsoft’s mandatory MFA enforcement began in October 2025. Any script or automation tool that uses a standard user account with a password to authenticate to Azure must now complete MFA — which breaks most legacy automation workflows.

If you have automated tasks, backup jobs, or deployments that authenticate using a username and password against Azure services, they likely broke in October 2025 or will break soon. The fix is to migrate those workflows to use service principals or managed identities — cloud-based service accounts that use certificate or token-based authentication rather than passwords. This is more technical than admin portal MFA, and if your environment uses Azure automation, it warrants a review now.

Microsoft is also signaling that mandatory MFA requirements will eventually extend to all Microsoft 365 users — not just admins. The current mandate covers admin center access only, but the direction is clear. Organizations that build the infrastructure for broad MFA deployment now will be ahead of the next enforcement wave.

Source: BleepingComputer — Microsoft to enforce MFA for Microsoft 365 admin center sign-ins

Admin MFA Review Checklist

  • List all admin accounts and identify which roles each holds
  • Verify each account has MFA enabled with at least two registered methods
  • Replace SMS-based MFA on admin accounts with an authenticator app
  • Check that all registered phone numbers and emails belong to current staff
  • Remove admin roles from former employees immediately
  • Create or verify a break glass emergency account
  • Test the complete MFA login flow for each admin account
  • Confirm whether Security Defaults or Conditional Access is managing MFA enforcement
  • Replace any shared admin accounts with individual named accounts
  • If using Azure automation, audit service account authentication for Phase 2 compliance

The February 9 enforcement date means this is no longer a future concern to plan around — it is current policy. Admin accounts without properly configured MFA are now blocked from the Microsoft 365 admin center entirely, and the threat environment that drove Microsoft to this enforcement has only intensified.

Getting admin MFA right is not complicated once you know what to check, but it is easy to overlook in the day-to-day of running a business. The consequences of overlooking it — either a lockout at a critical moment or a full tenant compromise with 14 minutes of warning — make it worth doing properly.

If you’re not certain right now how many global admin accounts exist in your tenant, whether they all have working MFA, or whether anyone could recover admin access if the primary account failed — those are the gaps to close.

The DaytonABS Care Plan includes a Microsoft 365 admin account audit, role cleanup, MFA configuration and testing, break glass account setup, and ongoing security checks. It is significantly easier to get this right proactively than during an access emergency. Reach out any time.

Dayton Allied Business Solutions  ·  daytonabs.com

Filed under: All Posts

About the Author

David Pfiffner is the owner of Dayton Allied Business Solutions, a managed IT and web solutions company serving businesses in the Huber Heights and Dayton, Ohio area. Nearly two decades of hands-on technology experience.

Need IT Help?

Proactive IT management, cybersecurity, backup, and web solutions for Dayton businesses. Flat monthly pricing. Local support.

Explore the Blog

Browse all posts for practical technology tips, IT advice, and web strategy for small businesses in the Dayton area.

Ready to Put This Into Practice?

If something in this post resonated, let’s talk. We work with small businesses in the Dayton area on exactly these kinds of problems.

Special Offer!

Get a free 30-minute review of your IT setup. We look at what you have, tell you what is at risk, and give you one thing you can do today at no cost and no obligation.

Grab the Offer!