How to Fix: Require MFA for All Administrators
Step-by-step guide to implement require mfa for all administrators in your Microsoft 365 environment.
5-10 minutes
Estimated Time
4
Steps
critical
Severity
Recommended Secure
Baseline Level
Why This Matters
Administrator accounts are prime targets for attackers. Even if MFA is required for all users, a dedicated policy for admins ensures they cannot bypass MFA under any condition and provides visibility into admin authentication.
Prerequisites
- 1Global Administrator or appropriate admin role in Microsoft Entra ID
- 2Access to Microsoft Entra admin center (entra.microsoft.com)
- 3Microsoft Entra ID P1 or higher license
- 4Conditional Access Administrator role (minimum)
Expected Configuration
- A Conditional Access policy targets the Directory Roles condition
- Policy includes all privileged administrator roles
- MFA is required on every sign-in (not just from untrusted locations)
Remediation Steps
Review Existing Policies
Examine your current Conditional Access policies.
- •Navigate to Microsoft Entra admin center
- •Go to Protection > Conditional Access
- •Review existing policies and their configurations
Design Policy Configuration
Plan the Conditional Access policy that addresses this control.
- •Define target users and groups
- •Determine target applications
- •Plan grant and session controls
Create or Update Policy
Implement the Conditional Access policy.
- •Create new policy or modify existing one
- •Configure assignments (users, apps, conditions)
- •Set appropriate grant and session controls
- •Start in Report-only mode for testing
Test and Enable
Validate the policy works correctly before full enforcement.
- •Monitor Report-only results
- •Test with pilot group
- •Switch to On when confident
- •Run TrueConfig scan to verify compliance
Auto-Remediation Available
TrueConfig can automatically fix this control for you. Enable auto-remediation to have this configuration applied and maintained automatically.
Learn about auto-remediationRelated Resources
Automate Your Security Configuration
TrueConfig continuously monitors your Microsoft 365 environment and can automatically fix configuration drift. Start your free trial today.
Start Free Trial