Jump to content

Microsoft to Tighten Cloud Security with Mandatory MFA for Azure Resource Management


Recommended Posts

Posted

Is anyone concerned about this?

 

How can we ensure none of our services / accounts will be affected?

 

 

Microsoft will soon begin enforcing Multi-Factor Authentication (MFA) for all Azure resource management actions. The company has announced that this change will go into effect on October 1, 2025.

In a support document, Microsoft detailed that the mandatory MFA enforcement will apply to Azure CLI, PowerShell, SDKs, REST APIs, Infrastructure as Code (IaC) tools, and the Azure mobile app. This enforcement is a part of Microsoft’s Secure Future Initiative (SFI) that launched in November 2023.

SFI is a multi-year strategy aimed at embedding security into every aspect of how the company designs, builds, and operates its technologies. It is built on three core principles: Secure by Design, Secure by Default, and Secure in Operations. SFI spans six engineering pillars, including identity protection, network security, threat detection, and rapid vulnerability remediation.

“Starting October 1, 2025, MFA enforcement will gradually begin for accounts that sign in to Azure CLI, Azure PowerShell, Azure mobile app, IaC tools, and REST API endpoints to perform any Create, Update, or Delete operation,” the company explained on the Microsoft 365 Admin Center. “Enforcement applies to all Azure tenants in the public cloud and all users. This includes automation and scripts using user identities (instead of application IDs).”

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...