Multifactor authentication (MFA)

MFA requires a user to provide two or more verification factors — something they know, have, or are — before access is granted.

Multifactor authentication requires verifying identity with at least two independent factors — typically a password plus a code from the Microsoft Authenticator app, an SMS, or a FIDO2 hardware key. In Microsoft 365, MFA is enforced through Microsoft Entra ID (formerly Azure Active Directory), so a single policy can protect the tenant. The key exam distinction is MFA versus passwordless: passwordless replaces the password entirely (Windows Hello for Business or a FIDO2 key), while traditional MFA keeps the password as one factor. Security Defaults enable per-user MFA on newer tenants that have no Conditional Access policies configured, so know when each applies.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Core Microsoft 365 Services & Identity