turn off mfa for 3rd party sites

Lauren K. Wolfe 0 Reputation points
2026-10-07T13:16:46.0366667+00:00

how can I turn off needing MFA on 3rd party sites through Entra? It's all shaded out so I can't make a new request

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-07T13:17:00.7833333+00:00

    MFA for third-party sites in Entra can be enforced from multiple places, so turning it off depends on where it is configured. If the controls are shaded out, the account likely does not have the required admin role.

    Check these areas:

    1. Per-user MFA
      • Sign in to Microsoft Entra admin center as at least an Authentication Policy Administrator.
      • Go to Users > All users > Per-user MFA.
      • Select the affected user and choose Disable MFA.
    2. Conditional Access
      • If MFA is required by a Conditional Access policy, per-user MFA settings do not override it.
      • Go to Protection > Conditional Access.
      • Open policies that require multifactor authentication.
      • Under Assignments > Users, exclude the affected user or group.
    3. Security Defaults
      • If Security Defaults are enabled, MFA cannot be disabled per user.
      • In Entra admin center go to Identity > Overview > Properties > Manage security defaults.
      • Set Security defaults to Disabled if appropriate.
    4. External MFA method
      • If the third-party site is using an external MFA method through Entra, go to the Authentication methods policy.
      • Select the external MFA method.
      • Either set Enable to Off, or adjust which users are included or excluded.
      • If the provider app no longer has consent or permissions, sign-in with that method fails.
    5. If the prompt is for registration rather than challenge
      • A registration prompt can also come from Self-Service Password Reset (SSPR) being enabled, because users must register at least one authentication method.

    If the options are shaded out, verify that the account has one of the required roles such as Authentication Policy Administrator or Authentication Administrator.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.