azureazure-active-directorymicrosoft-entra-id

Cannot add MFA in the Entra Admin Center


I have a very small Azure subscription with only two users. This is not a big enterprise.

In the Entra admin center, I have the following authentication methods available:

enter image description here

However, I am not able to add them to my user, the pointed button is disabled:

enter image description here

What is the easiest way to add some basic MFA to my admin users?


Solution

  • Note that: To configure MFA for all users including admin users, you must have Privileged Authentication Administrator role assigned.

    I got the same issue:

    enter image description here

    Hence to resolve the error, assign active Privileged Authentication Administrator role to your user account like below:

    Go to Azure Portal -> Microsoft Entra ID roles and administrators -> Privileged Authentication Administrator role -> Select -> Add assignments -> Select member -> Next -> Select Active -> Enter justification -> Assign

    enter image description here

    After assigning the role wait for few minutes to get it effected.

    Now I am able to successfully add authentication methods:

    enter image description here

    If still issue persists, refer this MsDoc for more information about which role must be assigned based on the scenario

    Reference:

    Admin permission for MFA - Microsoft Q&A by AmanpreetSingh-MSFT