

It turns out that there has been a change in underlying Azure AD policy which needs to be disabled as well. Users can select “skip for now (XX days until is required)” but it will finally require all users to provide it.

“Your organization needs more information to keep your account secure” The users continue to see following message on a fresh login to Office 365 portal. I have been contacted by few Office 365 admins who struggled disabling MFA in Office 365 even though they enabled support for legacy authentication in Office 365 and disabled MFA for each user. We recommend keeping Multi Factor enabled for security but there are times when you wish not to enable it during trial. Support Multi Factor Authentication for Office 365 Access Token

With Multi Factor Authentication enabled, the way you can create an access token for Office 365 is a bit different which I had covered in my other blog post. This means that every user will have to set up MFA and install the Microsoft Authenticator app on their mobile device. Starting October 21st, 2019, every new Office 365 for business or Microsoft 365 Business subscription will automatically have security defaults turned on.
