← All insights
Retirement · Security
Microsoft Now Requires MFA to Sign Into Admin Portals — Don't Get Locked Out
Signing into the Azure portal, the Entra admin center, Intune, or the Microsoft 365 admin center now requires multi-factor authentication. This isn't optional, and it's a good change — admin accounts are the keys to the kingdom, and they're exactly what attackers go after. But it can catch teams off guard if an admin isn't set up for MFA yet.
Why this matters more than normal MFA
An ordinary user account being compromised is bad. An admin account being compromised is a catastrophe — it can reconfigure security, create accounts, and reach everything. That's why the admin surfaces are being locked down first and hardest.
What to do before it bites
- Make sure every admin has MFA registered — ideally a phishing-resistant method like an authenticator app or a security key, not text messages.
- Protect your break-glass (emergency) accounts carefully: they need a way in that won't be blocked by a bad policy, stored securely and monitored.
- Check automation and service accounts that sign into these portals — they need app registrations and proper authentication, not a human password.
- Confirm your own access works with MFA before you're forced to, not during an outage at 2am.
The one thing that turns this from routine to disaster: an admin who gets locked out with no break-glass account. Set that up first, then everything else is easy.
Thinking about AI for your business?
I help teams adopt AI without giving up control of their data. Let's talk about where to start.
Start a conversation →