Older MFA model with per-user states of Disabled, Enabled or Enforced, administered outside Conditional Access. Conditional Access can demand MFA regardless of these states.
Also called legacy per-user multifactor authentication.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Per-user MFA in context, with comparison tables and the common traps.
Terms in this definition
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- App passwords
When per-user MFA is enforced, older apps that cannot show a browser prompt can sign in with these generated passwords instead, so MFA is skipped. An administrator has to permit their use, and they survive a reset of the user's own password unless removed separately.