Permissions to reset MFA on a user account - Microsoft Q&A (2024)

Hi there

I was wondering if anyone can help me figure out the permissions needed to access and reset a users MFA details in Azure/ Entra? I can only see that a Global Administrator has access to do this at the moment, but I can't give this level of access to all members of my IT Support Team. Attached is the a screenshot of what I mean.

Found an article that suggested either Conditional Access Administrator and Security Administrator would allow this, but it didn't though when I asked a colleague to test.

If someone can help and advise, then that would be great.

Many thanks

NickPermissions to reset MFA on a user account - Microsoft Q&A (1)

Permissions to reset MFA on a user account - Microsoft Q&A (2024)

FAQs

What permissions are needed to reset MFA? ›

Apart from the Global administrator, the Privileged Authentication Administrator role have access to perform the reset MFA on all users account and Authentication Administrator role have access to perform the reset MFA on some user's account. Hope this helps.

How do I reset a Microsoft authenticator account? ›

Resetting Microsoft Authenticator
  1. Open Microsoft Authenticator on your device.
  2. In the “Settings” menu, usually found at the top right corner of the screen, scroll down and select “Accounts”.
  3. Choose the account you want to reset by tapping it.
  4. Then tap “Remove account” or a similar option.
  5. Follow the prompts to confirm.

How do I remove MFA from Microsoft account as administrator? ›

The global admin can use the following steps to disable multi-factor authentication for an account: Go to Office 365 Admin Center > Users > Active users > Click More next to +Add a user > Multifactor Authentication setup. Check an account>click Disable under quick steps on the right.

What is reset permissions? ›

Permissions Reset can reset the owner, group, access permissions, Access Control Lists (ACLS), Extended Attributes (including Quarantine) to default settings, simply by dragging an app, folder or file into Permissions Reset, selecting what you'd like reset, then clicking on "Reset".

What permissions does Microsoft authenticator have? ›

List of permissions
  • Camera. Used to scan QR codes when you add a work, school, or non-Microsoft account.
  • Contacts and phone. ...
  • SMS. ...
  • Draw over other apps. ...
  • Receive data from the internet. ...
  • Prevent phone from sleeping. ...
  • Control vibration. ...
  • Use fingerprint hardware.

What is MFA factor reset? ›

This action is equivalent to removing or deleting the user's MFA registration. The MFA settings associated with the user will be removed, which allows them to set up MFA as if they were a new user on their next login attempt.

How to reset root user MFA? ›

How do I reset my AWS root user account MFA device?
  1. Sign in using your AWS account root user email address.
  2. On the Root user sign in page, enter the password of your root account.
  3. On the Amazon Web Services Sign In With Authentication Device page, choose Troubleshoot MFA?

How do I remove MFA from a user? ›

To disable MFA for a user, Sign in to the Azure portal with your admin credentials > Go to Azure Active Directory > Select Users > Select the user you want to disable MFA for > Select Authentication methods > Under MFA, select Disable > Select Save.

How do I reset my Microsoft account without the authenticator app? ›

Go to the Microsoft account recovery page (https://account.live.com/password/reset) and try to reset your password by providing information about your account, such as the email address or phone number associated with it.

How do I fix Microsoft Authenticator problem? ›

If you're using mobile data, try switching to Wi-Fi and vice-versa. Make sure Airplane mode is off. Make sure you're using the latest version of Authenticator - Microsoft does not support any app versions more than 12 months old. Tap Settings and make sure App updates is turned on.

How do I change my Microsoft Authenticator authentication? ›

Important: If you already set up your work or school account in the Microsoft Authenticator app, you don't need to do it again.
  1. Go to the Security info page using the steps above.
  2. Select Add sign-in method.
  3. Select Choose a method and then Authenticator app. ...
  4. Select Save.

How do I reset my Microsoft MFA? ›

Resetting a user's MFA details requires the user to re-register at next log-on. Proceed as follows. Go to https://portal.azure.com, and sign into the Microsoft Azure portal using an account with administrative privileges. From the left-hand menu, click Azure Active Directory and, from the options given, click Users.

How do I remove authentication in my Microsoft account? ›

2 answers
  1. Sign in to the Azure portal as a global administrator or security administrator.
  2. Go to Azure Active Directory > Security > MFA.
  3. Under MFA settings, select Additional cloud-based MFA settings.
  4. Under service settings, select Microsoft Authenticator app.
  5. Change the setting to Disabled.
Mar 20, 2024

How do I disable Microsoft MFA per user? ›

2 answers
  1. Select the user from the list.
  2. In the “Manage” section of the left menu for the user, select “Authentication methods”
  3. From the toolbar above the resulting pane, click “Revoke multifactor authentication sessions”. You may need to click the ellipsis (three dots) on the toolbar to view that choice.
Sep 26, 2023

Who can enable MFA delete? ›

The bucket owner, the AWS account that created the bucket (root account), and all authorized users can enable versioning. However, only the bucket owner (root account) can enable MFA delete.

How to reset MFA for a user in Salesforce? ›

Reset Two-Factor Authentication for Your User Account
  1. Log in to Personalization with your credentials.
  2. Complete 2FA authentication.
  3. Click the person icon.
  4. To open the Edit User window, select your name.
  5. Under Two-Factor Authentication Configuration, select Reset and then select Enable.

How do I fix my MFA? ›

MFA Setup issues
  1. Retry. ...
  2. Clear your browser's cookies and cache by deleting temporary internet files or cached files.
  3. After clearing your browser's cache, update the password associated with your account.
  4. Using your new password, sign in to your account and complete the steps in Multi-factor authentication setup.

Top Articles
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 5668

Rating: 4 / 5 (41 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.