Guess I need to read the docs further, but when turning on MFA, there are 2 well known issues, well 1, 2 is a bit more remote in nature. First, conneting to powershell is a complete fiasco that continually requires reauthentication to some random servers in Germany or something whacky. For those that have your admin with MFA enabled, you know what I'm talking about, it times out and requires re-authorization often, things just don't work. This is all over on blogs. Next, if you happen to be a Skype for Business customer, use a 3rd party hosting company for this, and use Polycom phone with Skype firmware, when you enable MFA, your phone can talk to your Skype server AND the O365 Exchange tenant. It is a flaw in the Polycom firmware they won't fix. So, what you get is a constant error, the phone won't connect properly, or it has a red exclamation mark on the top of the screen. The phone still works, but the split authentication due to MFA, and Polycom, which they refuse to fix the issue, never buying a Polycom phone again BTW, their dev teams refuse to resolve known issues and if they do, it takes them 6mo to a year...anyway, just going out and buying new $500 phones per person isn't an option. I've tested Yealink T58 phones, they have no problem with this setup. But, the fix is replacing all phones, or, moving entirely to O365 Skype/Teams for telephony, which is surely what MS wants to happen. Not opposed to this..but now we have a big problem if enhanced security and something as simple as MFA is enabled how it can mess up the organization. None the less, a bunch of 3rd party apps. So, at least thanks for now to leaving this thing disabled until we can migrate or get new phones, which during these times, good luck asking for $20K from your CFO for some phone or more depending on your user account. Thanks