Compliance with Mandatory MFA for Microsoft 365 Migrations

4 min read Updated on September 9, 2026 Cloudiway Team

Microsoft has made Multi-Factor Authentication (MFA) mandatory for Azure and administrative portals. This article explains how Cloudiway complies with these requirements and identifies specific migration scenarios where MFA exceptions may be necessary due to technical limitations.

Overview

Starting October 2024, Microsoft requires MFA for all users signing into Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center. Cloudiway adheres to these mandatory MFA requirements by implementing robust authentication methods that align with Microsoft's guidelines.

Microsoft's MFA Requirement

For more information about Microsoft's MFA requirements, refer to the official Microsoft documentation on mandatory MFA.

Cloudiway MFA Compliance

Cloudiway uses modern authentication methods including OAuth 2.0 and certificate-based authentication for most migration operations. These methods are fully compatible with MFA-enabled environments and represent best practices for enterprise security.

Security First Approach

Cloudiway prioritizes security and recommends keeping MFA enabled whenever possible. The exceptions listed below are only for specific technical scenarios where MFA cannot be used.

When Does MFA Need to Be Disabled?

MFA only needs to be disabled for the target connector administrator account when migrating to:

  • Teams 1:1 chats
  • Teams channels

For other migration workloads, MFA can remain enabled.

Important Note

The Cloudiway team is currently working on this improvement, and MFA will soon no longer be required for either of these two migration scenarios.

Important

The MFA exception applies only to the administrator account configured in the target Microsoft 365 connector.

MFA does not need to be disabled tenant-wide, for regular users, or for other administrator accounts.

If Conditional Access policies require MFA for the target connector account, make sure the account is excluded from the applicable policies during the migration.

Target Connector Administrator Account

The account configured in the target Microsoft 365 connector is the account Cloudiway uses to perform the migration operations in the target tenant.

For migrations that include Teams 1:1 chats or Teams channels:

  1. Create a dedicated Microsoft 365 SharePoint administrator account for the migration.
  2. Configure this account in the target Microsoft 365 connector.
  3. Disable MFA for this account.
  4. Make sure All the Condition access policy are disabled for this account.
  5. Verify that the account has the required permissions.
  6. Run the Teams migration.
  7. Re-enable MFA on the account once the migration requiring the MFA exception is complete.

Was this article helpful?

Need more help? Contact our support

We value your feedback

Help us improve your experience

What would you like to share with us?

Need direct support? Open a ticket