Azure Portal enforces MFA for Entra ID Free users even when Security Defaults are disabled

cyber shah 0 Reputation points
2026-01-17T10:54:42.58+00:00

We are creating external lab users using automation (Python scripts) in Microsoft Entra ID (Free plan).

These users must sign in to Azure Portal only for lab usage (Virtual Machines and Blob Storage).

Security Defaults are disabled at the tenant level.

No Microsoft Entra ID P1 or P2 licenses are assigned.

However, when these lab users sign in to Azure Portal, MFA is enforced and they are required to use Microsoft Authenticator, which blocks lab access.

Questions:

  1. Is MFA enforced by Microsoft for Azure Portal sign-in even when Security Defaults are disabled?
  2. Is there any supported way to exclude specific users or groups from MFA without Entra ID P1/P2 licenses?
  3. What is the recommended approach for lab or training environments where MFA is not feasible?

Looking for official confirmation or documentation reference.

Microsoft Security | Microsoft Authenticator
0 comments No comments

Answer recommended by moderator
cyber shah 0 Reputation points
2026-01-17T11:03:02.8833333+00:00

For lab user, they don't need mfa and as an admin i need to disable it. But i have a problem without p1 p2 license i can't do anything - i cannot create group for the users

i have taken help+support but no use - with the help of microsoft azure support team i can resolve my issue

Was this answer helpful?

0 comments No comments

2 additional answers

Sort by: Newest
  1. Theodora Egburedi 0 Reputation points
    2026-06-18T20:34:11.2966667+00:00

    Yes,

    Without Microsoft Entra ID P1 or P2 licenses, there is no supported way to exclude specific users or groups from MFA.

    Switch to Workload Identities (For Automation)

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-01-17T10:54:50.9233333+00:00
    1. Yes, MFA is enforced for Azure Portal sign-in even when Security Defaults are disabled. This is part of the enforced security policies that require multifactor authentication for users accessing Azure Resource Manager services, which includes the Azure portal.
    2. Without Microsoft Entra ID P1 or P2 licenses, there is no supported way to exclude specific users or groups from MFA. The only options available are to use security defaults or per-user MFA, which does not allow for exclusions.
    3. The recommended approach for lab or training environments where MFA is not feasible would be to enable security defaults, as this provides a basic level of security without the need for complex configurations. However, if security defaults are not an option, consider using a different environment or licensing that allows for more flexible MFA configurations.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.