I am happy Microsoft is embracing security. I think we need more details to effectively prepare for this change. What is the enforcement mechanism Microsoft will use to enforce this? What specific portals and tools will now require MFA?
And perhaps most importantly, what about 3rd party MFA providers? We do not use Microsoft Entra ID MFA and utilize a third party for our MFA. So, we need to know how this enforcement will take this into account and let us bypass Microsoft's MFA in favor of a 3rd party MFA system.
EDIT: As a follow up, I have begun testing external authentication methods, and they are being honored as MFA methods. However, it is defaulting to Microsoft's MFA methods. Before you make this mandatory, please follow through on this statement...
"We're actively working to support system-preferred MFA with EAMs."
Quoted from https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-external-method-manage