Enable MFA for All Users — Microsoft 365 Account Security
Enable MFA for All Users is a 7-day implementation service for organizations using Microsoft 365 services that want to require multi-factor authentication for all users. IT Partner provides informational letters for users, analyzes applications that use AD authorization and their ability to use MFA, enables mandatory MFA usage policies, monitors implementation results, and provides a project closeout report.
What this engagement is
Multi-factor authentication adds a second authorization factor when users sign in, such as receiving a code via SMS, getting a phone call, or confirming sign-in with a mobile application. This significantly reduces the possibility of illegitimate account use because even if attackers learn a username and password, they cannot bypass the second confirmation factor. IT Partner strongly recommends setting up this feature for all accounts.
Success criteria
What you receive
How the work unfolds
Start the engagement with a kickoff meeting.
Gather information about applications that use Entra ID authorization.
Inform users as part of the MFA rollout plan.
Enable the MFA usage policy.
Users complete MFA setup for their own accounts.
Verify the implementation and fix issues, if any.
Prerequisites
Who does what
IT Partner
- Provide informational letters for users
- Analyze applications that use AD authorization and their ability to use MFA
- Enable policies of mandatory MFA usage
- Monitor MFA implementation results
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Employees have to complete the MFA setup for their accounts on their own
- Coordinate any outside vendor resources and schedules
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
What's not included
Limitations & technical notes
Frequently asked questions
What is the Enable MFA for All Users service?
Enable MFA for All Users is a 7-day implementation service for organizations using Microsoft 365 services that want to require multi-factor authentication for all users. IT Partner provides user informational letters, analyzes applications that use AD/Entra ID authorization for MFA readiness, enables mandatory MFA usage policies, monitors results, and delivers a project closeout report.
Who is this MFA implementation service designed for?
This service is designed for organizations using Microsoft 365 services that want to make multi-factor authentication mandatory for all users. It is appropriate when the organization has, or can provide, a subscription such as Entra ID Premium or another plan with the ability to use MFA.
What is included in the Enable MFA for All Users service?
The service includes informational letters for users, analysis of applications that use AD authorization and their ability to use MFA, enabled policies for mandatory MFA usage, monitoring of MFA implementation results, and a project closeout report. The closeout report indicates final project status, acceptance criteria matching, outstanding issues if any, and the final budget.
What is not included in this MFA service?
This service does not include direct informing of users about upcoming changes, customer team training, desktop software settings, or extensive documentation beyond the stated deliverables. Customer team training and more extensive documentation may be available as additional services, but they are not part of the standard scope.
How long does the MFA implementation take?
The stated duration for the Enable MFA for All Users service is 7 days. The plan may vary depending on the organization’s needs, application environment, user readiness, and any issues found during verification.
How much does the Enable MFA for All Users service cost?
The listed price for the Enable MFA for All Users implementation service is 700. The project closeout report includes the final budget, and any additional services or scope changes should be confirmed with IT Partner.
What prerequisites are required before starting the MFA rollout?
The prerequisites are any Microsoft 365 service and Entra ID Premium or another subscription with the ability to use MFA. These prerequisites matter because the service enables MFA policies for Microsoft 365 identities and requires licensing that supports multi-factor authentication.
What happens during the MFA implementation engagement?
The engagement starts with a kickoff meeting, followed by gathering information about applications that use Entra ID authorization, preparing user communications, enabling the MFA usage policy, users completing MFA setup, and verification with issue fixing if needed. This sequence is intended to make MFA mandatory while checking application readiness and monitoring adoption results.
Does IT Partner enable MFA for every user in the organization?
Yes, the service is intended to require multi-factor authentication for all users by enabling mandatory MFA usage policies. A success criterion is that the MFA policy is enabled and users have completed setup of a second authorization factor for their accounts.
What MFA methods can users use after the service is implemented?
Multi-factor authentication can use a second authorization factor such as an SMS code, a phone call, or confirmation through a mobile application. The exact available methods depend on the organization’s Microsoft 365 and Entra ID configuration, so method availability should be confirmed during the engagement.
Will enabling MFA cause downtime for Microsoft 365 users?
The service description does not specify planned downtime. The main business impact is that users must complete second-factor setup and may be prompted for an additional verification step when signing in, so scheduling and user communication are important.
How are applications that use AD or Entra ID authorization handled?
IT Partner analyzes applications that use AD/Entra ID authorization and assesses their ability to use MFA. This is included because requiring MFA can affect sign-in behavior for applications that rely on Microsoft identity services.
Who is responsible for user communication during the MFA rollout?
IT Partner provides informational letters for users, but direct informing of users about upcoming changes is listed as not included in the standard service. The client should therefore expect to coordinate user communications and schedules unless a separate arrangement is made with IT Partner.
What do users need to do during the MFA rollout?
Users must complete the MFA setup for their own accounts by registering a second authorization factor. This is a required success criterion because the MFA policy alone is not enough if users have not completed their second-factor setup.
What are IT Partner’s responsibilities in this service?
IT Partner is responsible for providing informational letters, analyzing applications that use AD authorization and their MFA capability, enabling mandatory MFA usage policies, and monitoring MFA implementation results. IT Partner also provides the project closeout report at the end of the engagement.
What are the client’s responsibilities in this service?
The client is responsible for coordinating resources and staff schedules, providing a dedicated point of contact, ensuring employees complete MFA setup, coordinating outside vendors, configuring network equipment such as load balancers, routers, firewalls, and switches, and reviewing deliverables promptly. These responsibilities are important because MFA rollout affects users, applications, and sometimes dependent infrastructure.
Is user or administrator training included?
Customer team training is not included in the standard Enable MFA for All Users service. IT Partner notes that training could be added as an additional service, so buyers should confirm scope and cost if training is required.
Are desktop software settings or network equipment changes included?
Desktop software settings are not included, and the client is responsible for configuring network equipment such as load balancers, routers, firewalls, and switches. If these areas require help, the buyer should confirm whether additional services are needed.
What happens after the MFA implementation is completed?
After implementation, IT Partner provides a project closeout report showing final project status, acceptance criteria matching, outstanding issues if any, and the final budget. The acceptance criteria are that the MFA policy is enabled and users have completed second authorization factor setup for their accounts.
Why should an organization enable MFA for all Microsoft 365 users?
Multi-factor authentication significantly reduces the risk of illegitimate account use because a stolen username and password alone are not enough to sign in. IT Partner strongly recommends enabling MFA for all accounts to add a second confirmation factor such as SMS, phone call, or mobile app approval.