Forum Discussion
Conditional Access enforces MFA but Service Account still ask to secure account
Excluding the group from an MFA Conditional Access policy does not exclude it from separate registration controls. Also exclude it from Authentication methods > Registration campaign, ID Protection > Multifactor authentication registration policy, and any Conditional Access policy targeting Register security information; confirm Security defaults is disabled, then use the affected account’s sign-in logs to identify every applied policy.
Do not enable interactive sign-in for shared mailboxes. Block their sign-in and grant named users mailbox delegation instead. For actual unattended services, replace user accounts with managed identities or service principals where supported, because a regular account that must use the Microsoft sign-in page is an interactive user account and cannot safely be guaranteed permanent MFA exemption. MStack360 covers exactly this work. Learn more here: https://mstack360.com/enterprise-microsoft-365-security-implementation/