How to disable O365 MFA for the initial login at a new device?

Aljoscha 0 Reputation points
2023-02-10T08:07:10.27+00:00

I recently migrated my client to O365 and we are discovering device enrollment via Intune.

When onboarding a new device and the user logs in for the first time, the user needs to configure an MFA device or leave their mobile number. We do not want to rollout the MFA immediately, but later on. Is there any way to disable this requirement for an MFA registration when logging into a newly onboarded device?

Bests,

Aljoscha

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,664 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,351 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Aljoscha 0 Reputation points
    2023-02-10T08:19:18.1666667+00:00

    Some additonal informations:

    • Windows Hello is disabled in the Intune "Windows-Enrollment" Settings
    • Windows Hello is also disabled by a Intune "Configuration Policy"

    But still the user has to setup an MFA device or SMS verification.

    0 comments No comments

  2. Andy David - MVP 144.2K Reputation points MVP
    2023-02-10T12:25:19.77+00:00

    Hi, Only if you disable the MFA requirement.

    You could also use the temporary access pass:

    https://video2.skills-academy.com/en-us/azure/active-directory/authentication/howto-authentication-temporary-access-pass

    then the user can register MFA .

    Why the need to not require MFA here? If you aren't ready for MFA, then really you should disable it for now (Security Defaults or conditional access policy that is enforcing it)

    0 comments No comments