If you want to enroll for Azure MFA the users need to go through these steps. When you enforce or enable MFA the user will be prompted for MFA enrollment. This is best done in a browser.
Note on these settings, I have 3 users in the CA Exchange Online Mobile group. Rest of my users are in the NO CA group and that group is set to Except. I do this to ensure that nothing is enforced globally to all users. The 3 users in the first group have not had Azure MFA Enabled or Enforced but is set to Disabled.
You do not have to enable MFA globaly for this to work
I always add an Except group with the remaining users.
This is what the user will see now.
He will see the normal login but be required to enter a second factor. If he navigates to outlook og Onedrive there will be no such requirement.
You must be logged in to post a comment.