Multifactor authentication (MFA) requires two or more of: something you know (password or PIN), something you have (phone, security key) and something you are (fingerprint, face). A stolen password alone is then not enough. In Microsoft Entra ID you can require MFA through security defaults (a free, all-or-nothing baseline) or, for finer control, through Conditional Access policies. The old per-user MFA setting is legacy and should be avoided in favor of Conditional Access.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.