How to enable two-factor authentication (2FA) for Microsoft 365 accounts
Summary
This guide helps you troubleshoot and resolve: How to enable two-factor authentication (2FA) for Microsoft 365 accounts. Follow the steps below to fix the issue.
Quick Tip: Need immediate assistance? 💻 Open a Ticket
Common Causes
Two‑factor authentication (2FA) adds an extra layer of protection to your Microsoft 365 account by requiring a second verification step when you sign in. This guide walks you through enabling 2FA for both administrators and end users, helping you keep business email and data secure.
Quick Fix Steps
- Sign in to the Microsoft 365 portal at
https://portal.office.comwith your work account. - Click your profile picture in the top‑right corner and select My account.
- Choose Security & privacy from the left‑hand menu.
- Select Additional security verification and then click Set up two‑step verification.
- Follow the on‑screen prompts to choose a verification method (authenticator app, text message, or phone call) and complete the setup.
Detailed Instructions
Prerequisites
- Active Microsoft 365 licence that includes Azure AD (most Business and Enterprise plans).
- Access to the account’s security info page – either as an admin or as the user themselves.
- Smartphone with a compatible authenticator app (Microsoft Authenticator, Google Authenticator, etc.) or a mobile phone capable of receiving SMS/calls.
Enable 2FA for the organisation (admin)
- Log in to the Microsoft 365 admin centre at
https://admin.microsoft.comusing an admin account. - In the left navigation, expand Settings and click Org settings.
- Choose the Security & privacy tab.
- Under Multi‑factor authentication, click Manage multi‑factor authentication. This opens the Azure AD MFA portal.
- On the Users tab, select the users you want to enforce 2FA for, then click Enable in the right‑hand pane.
- Confirm the action when prompted. Users will be required to set up 2FA the next time they sign in.
- Optionally, configure Conditional Access policies to require MFA for specific apps or locations.
Enable 2FA for an individual user (self‑service)
- Sign in to My Microsoft account at
https://myaccount.microsoft.com. - From the left menu, select Security > More security options.
- Under Two‑step verification, click Set up two‑step verification.
- Choose your preferred verification method:
- Authenticator app – Scan the QR code with your app and enter the generated code.
- Phone number – Receive a text message or voice call with a code.
- Enter the verification code to confirm the method works, then click Finish.
- Make a note of the app passwords you may need for legacy applications that don’t support MFA.
Tip: Encourage users to install the Microsoft Authenticator app – it provides push notifications that are quicker than entering a code.
Troubleshooting
Common issues
- Can't locate the security info page – Ensure you are signed in with the correct work account, not a personal Microsoft account.
- Authenticator app won’t scan QR code – Check that your device camera is clean and that you have granted the app permission to use the camera.
- SMS not received – Verify the phone number is entered correctly and that your carrier isn’t blocking short‑code messages.
- App passwords not working – Remember that app passwords are only needed for apps that don’t support modern authentication; they cannot be used for web sign‑ins.
Important: Disabling 2FA for an account reduces its security. Only turn it off temporarily for troubleshooting, and re‑enable it as soon as possible.
When you need further assistance
If you’ve tried the steps above and still encounter problems, please Open a Ticket through our support portal. Include details such as the user’s email address, the exact error message, and any screenshots that show where the process stops.
Still Having Issues?
Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.
💻 Open a Ticket
💻 Open a Ticket