Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-to-enforce-mfa-for-azure-resource-management-in-october/
ONE SENTENCE SUMMARY:
Starting October 2025, Microsoft will enforce multi-factor authentication for Azure to enhance security against unauthorized access attempts.
MAIN POINTS:
- Microsoft enforces MFA for Azure resource management starting October 2025.
- Enforcement aims to protect Azure clients from unauthorized access.
- MFA required for Azure CLI, PowerShell, SDKs, and APIs.
- Users should upgrade Azure CLI to version 2.76+ and PowerShell to 14.3+.
- Global administrators can delay compliance until July 2026.
- Enforcement applies to all Azure tenants in public cloud.
- Affected operations include Create, Update, and Delete.
- Monitoring available via authentication methods registration report.
- 99.99% of MFA-enabled accounts resist hacking.
- GitHub also enacts 2FA for active developers from January 2024.
TAKEAWAYS:
- MFA significantly enhances account security against unauthorized access.
- Upgrading tools ensures compatibility with MFA requirements.
- Administrators have until July 2026 for full compliance.
- Large-scale enforcement promises improved security for all Azure users.
- MFA adoption is part of a broader security initiative by Microsoft.