CA-02Easy

How to Fix: Require MFA for All Administrators

Step-by-step guide to implement require mfa for all administrators in your Microsoft 365 environment.

5-10 minutes

Estimated Time

4

Steps

critical

Severity

Recommended Secure

Baseline Level

Why This Matters

Administrator accounts are prime targets for attackers. Even if MFA is required for all users, a dedicated policy for admins ensures they cannot bypass MFA under any condition and provides visibility into admin authentication.

Prerequisites

  • 1Global Administrator or appropriate admin role in Microsoft Entra ID
  • 2Access to Microsoft Entra admin center (entra.microsoft.com)
  • 3Microsoft Entra ID P1 or higher license
  • 4Conditional Access Administrator role (minimum)

Expected Configuration

  • A Conditional Access policy targets the Directory Roles condition
  • Policy includes all privileged administrator roles
  • MFA is required on every sign-in (not just from untrusted locations)

Remediation Steps

1

Review Existing Policies

Examine your current Conditional Access policies.

  • Navigate to Microsoft Entra admin center
  • Go to Protection > Conditional Access
  • Review existing policies and their configurations
2

Design Policy Configuration

Plan the Conditional Access policy that addresses this control.

  • Define target users and groups
  • Determine target applications
  • Plan grant and session controls
3

Create or Update Policy

Implement the Conditional Access policy.

  • Create new policy or modify existing one
  • Configure assignments (users, apps, conditions)
  • Set appropriate grant and session controls
  • Start in Report-only mode for testing
4

Test and Enable

Validate the policy works correctly before full enforcement.

  • Monitor Report-only results
  • Test with pilot group
  • Switch to On when confident
  • Run TrueConfig scan to verify compliance

Auto-Remediation Available

TrueConfig can automatically fix this control for you. Enable auto-remediation to have this configuration applied and maintained automatically.

Learn about auto-remediation

Related Resources

Automate Your Security Configuration

TrueConfig continuously monitors your Microsoft 365 environment and can automatically fix configuration drift. Start your free trial today.

Start Free Trial