A cloud-based identity and access management service for securing user authentication and resource access
Azure MFA enforcement will affect service accounts that are set up as user identities. Specifically, any service accounts that are not using managed identities or service principals will be subject to MFA enforcement. This means that if your service accounts are synced to Azure via Entra Connect and are set up as user accounts, they will be impacted by the MFA enforcement starting in Phase 2, which begins on October 1, 2025.
Regarding Microsoft Graph APIs, the enforcement applies primarily to requests sent to https://management.azure.com/, and Microsoft Graph APIs are generally not under the scope for Azure MFA enforcement. Therefore, queries made through Microsoft Graph APIs should not be directly affected by the MFA enforcement.
To conduct an impact analysis and ensure a smooth transition, you can utilize Azure Policy. By deploying the Azure Policy related to MFA enforcement in Audit mode, you can assess how the enforcement will impact your tenant before it goes into effect. This allows you to identify any potential issues and address them proactively.
References: