How to Disable MFA
Modified on: Mon, Jun 26 2023 10:21
Prerequisites: Access to Azure Active Directory. Access to edit AD group properties for a user. AD role: Domain Administrator. Azure Active Directory Role Authentication Administrator
This guide covers how to completely disable an end user's MFA. Note that this is not recommended. Generally, we should have approval from information security before disabling a user’s MFA.
Active Directory
- With Domain admin account open
Active Directory.
- Navigate to the user.
- Open the user in AD.
- Navigate to Member Of.
- Select AADP-P1 (or P2).
- Select remove.
Azure Active Directory
- Log into Azure AD.
- On the left nav pane, select users.
- Search for user.
- Select the user.
- Within the user menu, on the left nav pane select Authentication methods.
- In the Authentication Contact Info, delete any data.
- Click Save.
Note: Please allow 5 minutes to one day for MFA to be disabled.