Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft to Require Multi-Factor Authentication on Azure Portal Logins

Microsoft has announced the implementation of mandatory multi-factor authentication (MFA) for all sign-in attempts to the Azure portal and other administrative interfaces. This measure aims to enhance security by adding an additional layer of…

Microsoft has announced the implementation of mandatory multi-factor authentication (MFA) for all sign-in attempts to the Azure portal and other administrative interfaces. This measure aims to enhance security by adding an additional layer of verification beyond passwords, effectively blocking unauthorized access to high-value cloud resources.

Research conducted by Microsoft indicates that enabling MFA can prevent over 99.2% of account compromise attacks. Based on this data, a two-phase rollout plan has been developed to provide organizations with sufficient time to comply and prepare.

Starting in October 2024, accounts accessing the Azure portal, Microsoft Entra admin center, or Microsoft Intune admin center for operations such as create, read, update, or delete must utilize MFA. This update will be gradually implemented across all global tenants.

From February 2025, MFA enforcement will be extended to the Microsoft 365 admin center. Administrators currently enforcing MFA or using passwordless methods, such as passkeys or FIDO2, will not experience any changes in their sign-in process.

From October 1, 2025, MFA will be required for operations executed through tools like Azure CLI, Azure PowerShell, the Azure mobile app, infrastructure-as-code (IaC) tools, and Control Plane REST API endpoints when creating, updating, or deleting resources. Read-only commands will remain unaffected. This phase ensures that automation and scripting workflows, authenticated with user credentials, also benefit from MFA's protection.

Research conducted by Microsoft indicates that enabling MFA can prevent over 99.2% of account compromise attacks.
Paige Monroe · Thehackingpost

A detailed list of application names, IDs, and enforcement start dates is included in Microsoft's announcement.

Key targets for Phase 1 include the Azure portal (App ID: c44b4083-3bb0-49c1-b47d-974e53cbdf3c) and Microsoft Entra admin center, with a kickoff in the second half of 2024. For Phase 2, applications such as Azure PowerShell (App ID: 1950a258-227b-4e31-a9cf-717495945fc2) and Azure CLI (App ID: 04b07795-8ddb-461a-bbee-02f9e1bf7b46) will enforce MFA starting October 1, 2025.

Microsoft advises against the use of user accounts for automated tasks. It recommends transitioning to secure, cloud-based workload identities such as managed identities or service principals, which are exempt from the MFA enforcement phases and offer a safer option for scripts and automation.

Advertisement

Administrators should review existing Conditional Access policies or enable security defaults to require MFA. For organizations needing extra time, Microsoft allows postponement of Phase 1 until September 30, 2025, and Phase 2 until July 1, 2026, via designated management portals. However, Microsoft warns that delaying MFA increases risk, as administrative sign-ins remain prime targets for attackers.

This MFA requirement is a part of Microsoft's zero-trust security strategy, aiming to safeguard customer workloads and ensure the integrity of cloud environments worldwide.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories