Forum Discussion
Entra MFA for seniors using W365 Biz Basic
You are trying to keep senior users productive on Microsoft 365 Business Basic without an Authenticator app or hardware token. If the tenant uses Microsoft Entra security defaults, there is no supported per-user bypass: security defaults apply tenant-wide, require all users to register for MFA, and provide no customization. Calling these accounts “zero risk” does not remove exposure because email accounts remain attack targets. The safest path is assisted enrollment: install Authenticator on each user’s device, complete number matching together, and document recovery and replacement-phone procedures. A non-Microsoft OATH app can generate codes, but security-default registration still begins with Authenticator notifications. If individual exceptions are required, license Microsoft Entra ID P1 and replace security defaults with Conditional Access policies. Do not disable security defaults without replacement controls. If users accept no second factor, there is no secure Microsoft-supported solution; record and escalate that residual risk rather than bypassing MFA.