M365: Managing MFA for users in the Microsoft Admin Console (ETS Internal)

Summary

This documentation provides guidance for ET&S support staff to reset a user’s Microsoft MFA authentication methods within the Microsoft Admin Console.

Body

Summary

This documentation provides guidance for support staff to reset a user’s Microsoft MFA authentication methods within the Microsoft Admin Console. 

These steps will require you to use your AD ADM_username and password.  It is best practice to do these actions in a dedicated browser, one you do not use for accessing your regular M365 accounts.  Although a private browser window (Incognito) may be used, it does not always provide desirable results.

The process consists of three important actions:

Note: You must be on the campus network or on the VPN to sign in with ADM_ credentials (as of Oct. 2, 2024).

 

Action 1:  PIM (Activate your ability to administer Microsoft’s MFA authentication Methods) 

Task: To activate your ability to administer Microsoft’s MFA authentication Methods

Instructions

In a new (not used to sign into M365 as your regular user account) web-browser visit the following site: 

https://entra.microsoft.com/#blade/Microsoft_Azure_PIMCommon/CommonMenuBlade

Step 1 - Enter your ADM_ account username then click Next:

Example:  adm_username@unh.edu 

Microsoft sign-in screen with "adm_username@usnh.edu" in the box - Uploaded Image (Thumbnail)Click for full-size images

 

Step 2 - type in your ADM_ account password and click Sign in 

USNH password screen - Uploaded Image (Thumbnail)

 

Step 3 - Complete required MFA

Step 4 - Choose whether to "Stay signed in?" as you prefer

Step 5 - Once you’ve successfully signed in… click on "My roles" under Tasks. *If this option is not present, click again on this Entra admin center link (same as at the beginning of the article above) to reload the page in a new tab.

Uploaded Image (Thumbnail)

 

Step 6 - Then click on the "Activate" link

Uploaded Image (Thumbnail)

 

Step 7 - Enter a "Reason" for Activating the Authentication Administrator

Example Reason:  MFA Administration 

Step 8 - then click the "Activate" button at the bottom of the page.

Uploaded Image (Thumbnail)

 

Step 9 - Now wait for the three-stage activation to complete (Look for the 3 green checks).  When the final stage completes your browser will automatically refresh.  

Uploaded Image (Thumbnail)

 

Outcome

You are now "PIMed" into the Microsoft Admin Panel and have the necessary elevated access to manage MFA Methods. You may move to Action 2.

Back to top

 

Action 2:  Search for a user’s account to manage

Task: To search for a user’s account to manage

Instructions

Step 1 - Start by selecting "Users" from the left sidebar menu

Uploaded Image (Thumbnail)Click for full size images

 

Step 2- You may now search for your intended user

Example: search for "test" 

Uploaded Image (Thumbnail)

 

Step 3 - Double left-click on the intended user account to bring up their profile.

Once their profile page loads, click on "Authentication methods" in the left sidebar menu.

Uploaded Image (Thumbnail)
 

Outcome

You have identifed the correct user in the Microsoft Admin Panel. You may move to Action 3.

Back to top

 

Action 3:  Administer the desired action in the Selected Account

Task: To administer the desired action in the Selected Account

Once you have identified the correct user, there are only two options you may perform in this area.  It is important to understand the differences to get the desired outcome and to ensure that we do not inconvenience the customer unnecessarily.  DO NOT USE the Reset Password Option. Scroll down to see the available options.

  • Option A - Require re-register Multifactor Authentication - this action will reset the users MFA back to scratch.  All previous information and options will be erased and the user must then be stepped through the MFA registration process as outlined in this Public KB (#4431):  Setting up Multi Factor Authentication (MFA) for M365 
     
  • Option B - Issue a Temporary Token for One-time Use:  The temporary token will allow the user to MFA into M365 services within a limited window of time - default is set at 1 hour.  Once performed the user must then be directed to the appropriate location to input the token.

   

Option A - Require re-register Multifactor Authentication

In order to enable the user to re-register thier MFA methods, click  "Require re-register multifactor authentication" option as indicated below:

IMPORTANT:  selecting this method will completely clear out all the user's saved MFA options 

Uploaded Image (Thumbnail)Click for full-size image

 

Walk the user through the MFA set up process as outlined in this Public KB (#4431):  Setting up Multi Factor Authentication (MFA) for M365 

  

Option B - Issue a Temporary Token for One-time Use

Step 1 - In order to issue a temporary token for one-time access to M365 tools, click on the "+Add Authentication Method" option as indicated below (NOTE:  this option is only present if you click the purple bar that states "switch to the new user authentication experience").

Uploaded Image (Thumbnail)Click for full-size images

 

Step 2 - A second window open.  Under the Pull-down to select "Temporary Access Pass". Leave the other options set as Default, and click the "Add" button at the bottom of the window.

Uploaded Image (Thumbnail)

 

Step 3 - Provide the User with the CASE SENSITIVE Temporary Access Pass as indicated below, (you might jot it down on a scratch paper) and Click OK. 

Uploaded Image (Thumbnail)

 

Step 4 - Direct the user to enter the Temporary Access Pass when Prompted:

Uploaded Image (Thumbnail)

 

Outcome

You have executed the desired action in the selected account.

Back to top

 

Further Reading

Entra admin center link  - https://entra.microsoft.com/#blade/Microsoft_Azure_PIMCommon/CommonMenuBlade

FLS Internal: Troubleshooting MFA for the M365 Environment

 

Public Articles

MFA: Setting up Multi-Factor Authentication (MFA) for M365

MFA: Installing the Microsoft Authenticator App 

MFA: Choosing a preferred method of Multi-Factor Authentication (MFA) for M365 

MyAccount: Managing Account Verification Methods 

 

Need additional help?

If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.

Details

Details

Article ID: 4469
Created
Fri 7/29/22 6:22 PM
Modified
Fri 5/29/26 9:02 AM
Applicable Institution(s):
Keene State College (KSC)
Plymouth State University (PSU)
University of New Hampshire (UNH)
USNH System Office