Enable MFA for All Users — Microsoft 365 Account Security
Enable MFA for All Users is a 7-day implementation service for organizations using Microsoft 365 services that want to require multi-factor authentication for all users. IT Partner provides informational letters for users, configures MFA policies and authentication methods, enables mandatory MFA usage policies, monitors implementation results, and provides a project closeout report.
What this engagement is
Multi-factor authentication adds a second authorization factor when users sign in, such as receiving a code via SMS, getting a phone call, or confirming sign-in with a mobile application. This significantly reduces the possibility of illegitimate account use because even if attackers learn a username and password, they cannot bypass the second confirmation factor. IT Partner strongly recommends setting up this feature for all accounts.
Success criteria
What you receive
How the work unfolds
Start the engagement with a kickoff meeting.
Review the tenant's authentication methods configuration and design the mandatory MFA policy and rollout order.
Inform users as part of the MFA rollout plan.
Enable the MFA usage policy.
Users complete MFA setup for their own accounts.
Verify the implementation and fix issues, if any.
Prerequisites
Who does what
IT Partner
- Provide informational letters for users
- Configure MFA policies and authentication methods
- Enable policies of mandatory MFA usage
- Monitor MFA implementation results
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Employees have to complete the MFA setup for their accounts on their own
- Coordinate any outside vendor resources and schedules
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
What's not included
Limitations & technical notes
Frequently asked questions
What is the Enable MFA for All Users service?
Enable MFA for All Users is a 7-day implementation service for organizations using Microsoft 365 services that want to require multi-factor authentication for all users. IT Partner provides user informational letters, configures MFA policies and authentication methods, enables mandatory MFA usage policies, monitors results, and delivers a project closeout report.
Who is this MFA implementation service designed for?
This service is designed for organizations using Microsoft 365 services that want to make multi-factor authentication mandatory for all users. It is appropriate when the organization has, or can provide, a subscription such as Microsoft Entra ID P1 or P2, or another plan with the ability to use MFA.
What is included in the Enable MFA for All Users service?
The service includes informational letters for users, configuration of MFA policies and authentication methods, enabled policies for mandatory MFA usage, monitoring of MFA implementation results, and a project closeout report. The closeout report indicates the final project status, including any users who have not completed second-factor setup. Application-by-application MFA readiness assessment is not part of the scope.
What is not included in this MFA service?
This service does not include direct informing of users about upcoming changes, customer team training, desktop software settings, or extensive documentation beyond the stated deliverables. Customer team training and more extensive documentation may be available as additional services, but they are not part of the standard scope.
How long does the MFA implementation take?
The stated duration for the Enable MFA for All Users service is 7 days. The plan may vary depending on the organization’s needs, application environment, user readiness, and any issues found during verification.
How much does the Enable MFA for All Users service cost?
The listed price is $700 per project, quoted fixed-price in writing before work begins. The project closeout report includes the final budget, and any additional services or scope changes are quoted separately.
What prerequisites are required before starting the MFA rollout?
The prerequisites are any Microsoft 365 service and Microsoft Entra ID P1 or P2, or another subscription with the ability to use MFA. These prerequisites matter because the service enables MFA policies for Microsoft 365 identities and requires licensing that supports multi-factor authentication.
Does IT Partner enable MFA for every user in the organization?
Yes, the service is intended to require multi-factor authentication for all users by enabling mandatory MFA usage policies. A success criterion is that the MFA policy is enabled and users have completed setup of a second authorization factor for their accounts.
What MFA methods can users use after the service is implemented?
Multi-factor authentication can use a second authorization factor such as an SMS code, a phone call, or confirmation through a mobile application. The exact available methods depend on the organization’s Microsoft 365 and Entra ID configuration, so method availability should be confirmed during the engagement.
Will enabling MFA cause downtime for Microsoft 365 users?
No planned downtime is involved. The main business impact is that users must complete MFA registration and start approving sign-in prompts — communication and a staged rollout keep that transition smooth.
Who is responsible for user communication during the MFA rollout?
IT Partner provides informational letters for users, but direct informing of users about upcoming changes is listed as not included in the standard service. The client should therefore expect to coordinate user communications and schedules unless a separate arrangement is made with IT Partner.
What happens after the MFA implementation is completed?
After implementation, IT Partner provides a project closeout report showing final project status, acceptance criteria matching, outstanding issues if any, and the final budget. The acceptance criteria are that the MFA policy is enabled and users have completed second authorization factor setup for their accounts.