Microsoft has made Multi-Factor Authentication (MFA) mandatory for Azure and administrative portals. This article explains how Cloudiway complies with these requirements and identifies specific migration scenarios where MFA exceptions may be necessary due to technical limitations.
Overview
Starting October 2024, Microsoft requires MFA for all users signing into Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center. Cloudiway adheres to these mandatory MFA requirements by implementing robust authentication methods that align with Microsoft's guidelines.
Microsoft's MFA Requirement
Cloudiway MFA Compliance
Cloudiway uses modern authentication methods including OAuth 2.0 and certificate-based authentication for most migration operations. These methods are fully compatible with MFA-enabled environments and represent best practices for enterprise security.
Security First Approach
Cloudiway prioritizes security and recommends keeping MFA enabled whenever possible. The exceptions listed below are only for specific technical scenarios where MFA cannot be used.
When Does MFA Need to Be Disabled?
MFA only needs to be disabled for the target connector administrator account when migrating to:
- Teams 1:1 chats
- Teams channels
For other migration workloads, MFA can remain enabled.
Important Note
Important
The MFA exception applies only to the administrator account configured in the target Microsoft 365 connector.
MFA does not need to be disabled tenant-wide, for regular users, or for other administrator accounts.
If Conditional Access policies require MFA for the target connector account, make sure the account is excluded from the applicable policies during the migration.
Target Connector Administrator Account
The account configured in the target Microsoft 365 connector is the account Cloudiway uses to perform the migration operations in the target tenant.
Recommended Configuration
For migrations that include Teams 1:1 chats or Teams channels:
- Create a dedicated Microsoft 365 SharePoint administrator account for the migration.
- Configure this account in the target Microsoft 365 connector.
- Disable MFA for this account.
- Make sure All the Condition access policy are disabled for this account.
- Verify that the account has the required permissions.
- Run the Teams migration.
- Re-enable MFA on the account once the migration requiring the MFA exception is complete.