Checklist
intermediate

MFA Rollout Checklist for Microsoft 365

Step-by-step checklist for rolling out multi-factor authentication across your Microsoft 365 organization with minimal user disruption.

16 items
2-4 weeks
IT teams implementing MFA for the first time

Prerequisites

  • Microsoft Entra ID P1 or P2 license (for Conditional Access)
  • Global Admin or Security Admin access
  • Communication plan for end users

Planning Phase

Prepare for MFA rollout.

Inventory current MFA statushigh

Identify which users already have MFA registered.

Identify accounts requiring exceptionshigh

Document service accounts, shared mailboxes, etc.

Choose allowed MFA methodshigh

Decide which authentication methods to allow.

Tips:

  • Prefer Microsoft Authenticator with number matching
  • Consider FIDO2 keys for admins
  • Avoid SMS if possible (but better than nothing)
Prepare user communicationmedium

Create emails, guides, and FAQ for users.

Pilot Phase

Test MFA with a pilot group.

Create pilot grouphigh

Select 10-20 users from different departments.

Create pilot Conditional Access policyhigh

Create policy requiring MFA for pilot group only.

Related: CA-01
Provide pilot supporthigh

Help pilot users register and troubleshoot.

Collect pilot feedbackmedium

Document issues and adjust approach.

Rollout Phase

Roll out MFA to all users.

Enable registration campaignhigh

Configure registration campaign to prompt users.

Roll out in phases by departmenthigh

Gradually add departments to MFA policy.

Monitor registration progresshigh

Track registration completion rates.

Handle support requestshigh

Process user issues and exceptions.

Enforcement Phase

Enforce MFA for all users.

Enable MFA policy for all userscritical

Update policy to include all users (with approved exceptions).

Related: CA-01
Block legacy authenticationcritical

Create policy blocking protocols that bypass MFA.

Related: CA-09
Verify enforcementhigh

Test that MFA is required for all targeted users.

Document final configurationmedium

Record all policies, exceptions, and processes.

Automate this checklist with TrueConfig

TrueConfig automatically monitors your Microsoft 365 configuration against these best practices and alerts you when settings drift.