Problem:
You disable MFA (or dual factor) for the user but it still prompts you to authenticate via phone number or other means.
Solution:
There are three places to check for MFA, it could very well be that you have to go to all 3 solutions.
- Solution 1:
- In Admin console, go to Active users
- Click on the user
- Click on Manage multifactor authentication at the bottom right
- Disable the user’s MFA status
- Solution 2:
- Under Admin Center, click on Azure Active Directory
- On the far left, click on Azure Active Directory
- Click on Properties (bottom of Manage)
- You should be under Tenant properties
- At the bottom, click on Manage Security Defaults
- Set Enable Security Defaults to No
- Solution 3:
- Staying in Azure Active Directory, click on Password reset (about 4 options above Properties)
- Set the Self service password reset enabled to either None or Selected (and deselect the user)