Ready to migrate?
Multi-Factor Authentication for Microsoft 365
Security

MFA Enforcement in Microsoft 365

Where the Cloudiway Platform Stands: Full MFA Support, Two Remaining Prerequisites

Microsoft's mandatory Multi-Factor Authentication (MFA) rollout across Azure and Microsoft 365 administrative surfaces is now complete. The question customers ask us is no longer whether MFA is coming, but whether they have to weaken their security posture to run a migration. For all but two narrow cases, the answer is no.

In short

The Cloudiway platform fully accommodates Microsoft's MFA requirements. Keep your MFA and Conditional Access policies exactly as they are, with two remaining exceptions on the target connector for Microsoft Teams, described below.

Cloudiway Platform Status

Cloudiway migrations run on application permissions and app-only authentication. An Entra ID application (Microsoft 365) or a service account with domain-wide delegation (Google Workspace) authenticates the application itself, without any interactive user sign-in. Because no user signs in, no MFA challenge is ever raised, and the MFA policies applied to your accounts have no effect on the migration.

This applies across the platform. You do not need to disable MFA, create a Conditional Access exclusion, or provision a weakened service account for:

  • Mailbox and archive migration - Microsoft 365, Google Workspace, IMAP, Exchange
  • File migration - OneDrive, SharePoint, Google Drive, Google Shared Drives, Box, Dropbox
  • Teams and Google Chat migration - teams, channels, channel messages, files and tabs
  • SaaS Backup - backup and restore of mailboxes, files and sites
  • GALSync, cloud provisioning and Calendar Free/Busy coexistence
  • Intune and device migration
  • AI Readiness Assessment

Your end users are equally unaffected. They can keep using MFA throughout the migration, with no impact on the data being moved.

Two Remaining Prerequisites

Two operations still depend on delegated permissions, which require an interactive sign-in of the migration account. An MFA policy blocks that sign-in. Both concern the migration account configured in the target connector only. The source connector is never impacted.

1. Teams 1-1 chat messages

Writing one-to-one chat messages into the target tenant requires MFA to be removed on the migration account of the target connector.

2. Delta passes with import mode closed

Teams channels are migrated in import mode, which preserves original authorship and timestamps. Once import mode has been closed on the target team, a subsequent delta pass also requires MFA to be removed on that same account.

Actively being worked on

Both prerequisites are actively being worked on by the Cloudiway development teams, and an upcoming release will close these last two points. There is no ETA at this stage.

In the meantime, the recommended approach is the one we have always advised: create a dedicated migration account in the target tenant, used only for the migration, excluded from your MFA policy for the duration of the project, and deleted once the migration is complete. Scope the exclusion to that single account rather than relaxing a tenant-wide policy, and run your channel delta passes before closing import mode wherever the project allows it.

Enforcement Timeline

Microsoft rolled out MFA enforcement in phases. All of them are now in effect:

  • Phase 1 - October 15, 2024 - Azure Portal, Microsoft Entra Admin Center, Microsoft Intune Admin Center
  • M365 Admin - February 3, 2025 - Microsoft 365 Admin Center for all users
  • Phase 2 - October 1, 2025 - Azure CLI, Azure PowerShell, REST APIs, Terraform, ARM, Bicep

The temporary extension Microsoft offered expired on September 30, 2025. Enforcement now applies to every tenant, including test and development environments. There are no permanent exemptions.

What's Affected (and What's Not)

Affected by MFA Enforcement

  • Azure Portal
  • Microsoft Entra Admin Center
  • Microsoft Intune Admin Center
  • Microsoft 365 Admin Center
  • Azure CLI, PowerShell, REST APIs

NOT Affected

  • Microsoft Teams
  • Outlook (all versions)
  • Exchange Online
  • SharePoint Online
  • OneDrive for Business
  • All end-user Office 365 access

How to Prepare

If you are planning a migration under an enforced MFA policy, here is what actually matters:

1

Keep Your Policies

Leave your MFA and Conditional Access policies in place. No platform-wide exception is needed for a Cloudiway migration.

2

Check Your Scope

Confirm whether your project includes Teams 1-1 chat messages, or channel delta passes after import mode has been closed.

3

Scope the Exception

If it does, exclude only the dedicated migration account of the target connector, never a whole group or the entire tenant.

4

Clean Up

Remove the exclusion and delete the migration account as soon as the migration is signed off.

Need Help with Your Migration?

Our team can review your MFA and Conditional Access setup against your migration scope, and tell you exactly which prerequisites apply to your project.

Frequently Asked Questions

Does the Cloudiway platform support Microsoft's MFA requirements?

Yes. The Cloudiway platform fully supports Microsoft's MFA requirements. Migrations run on application permissions and app-only authentication, so MFA policies on your user accounts have no impact on our connectors. Two narrow exceptions remain, both on the target connector for Microsoft Teams.

Do I still need to disable MFA on my migration account?

Only in two cases, and only on the migration account configured in the target connector: the migration of Teams 1-1 chat messages, and delta passes into Teams channels once import mode has been closed. Every other workload - mail, files, SharePoint, OneDrive, Google Workspace, backup, provisioning - requires no change to your MFA policies.

Why do Teams 1-1 chat messages still require MFA to be removed?

The Microsoft Graph operations involved in writing 1-1 chat messages into the target tenant rely on delegated permissions. Delegated permissions require an interactive sign-in of the migration account, which an MFA policy blocks. This is a Microsoft API constraint, not a Cloudiway design choice.

What is a delta pass into a Teams channel with import mode closed?

Teams channels are migrated in import mode, which preserves original authorship and timestamps. Once import mode has been closed on the target team, a subsequent delta pass has to write through a different path that currently relies on the migration account of the target connector, and therefore requires MFA to be removed on that account.

Are these two prerequisites going to be removed?

Yes. Both are actively being worked on by the Cloudiway development teams and an upcoming release will close them. There is no ETA at this stage.

Does MFA enforcement affect regular Microsoft 365 users?

No. Microsoft's enforcement targets administrative access to Azure and Microsoft 365 admin portals, along with CLI tools and management APIs. Regular end-user services such as Teams, Outlook, Exchange Online, SharePoint and OneDrive are not affected.