



A recap of the steps as I understand them: 1) Turn off Legacy per-user MFA, 2) From Azure Admin Center turn on Security Defaults 3) In 365 admin center turn on modern auth under Org settings, 4) have users register devices and continue happily being fully protected.Having heard that MFA was moved to the Azure admin console, I looked for MS current doc on this and found this:.In the past, I used the per-user MFA inside of the Exchange admin console for just administrators. I was setting up MFA for a clients entire tenant.Answers as I'm getting conflicting information from official MS documentation and a MSO support technician.
