Microsoft Azure Blog Announcements 09月25日 18:02
Azure强制多因素认证:第二阶段将于2025年10月开始
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

微软宣布,Azure公共云的登录将强制要求多因素认证(MFA),此举旨在提升安全性。自2025年3月起,Azure门户的MFA强制执行已覆盖所有租户。接下来,从2025年10月1日起,Azure将启动第二阶段MFA强制执行,应用于资源管理器层。用户在执行资源管理操作前需进行MFA验证。微软已向全球管理员发送通知,建议用户在10月1日前启用MFA,并了解潜在影响,更新Azure CLI和PowerShell客户端以获得最佳兼容性。

🔒 Azure公共云登录将强制要求多因素认证(MFA),自2025年10月1日起应用于资源管理器层,旨在提升安全性。

📅 Azure门户的MFA强制执行已于2025年3月起覆盖所有租户,此次是第二阶段的扩展。

👤 用户在执行资源管理操作前必须进行MFA验证,包括使用Azure CLI、PowerShell、API等客户端。

📌 微软已向全球管理员发送通知,告知强制执行日期及准备方法,建议用户在10月1日前完成MFA配置。

🛠️ 为确保最佳兼容性,建议用户更新至Azure CLI 2.76及以上版本,以及Azure PowerShell 14.3及以上版本。

As cyberattacks become increasingly frequent, sophisticated, and damaging, safeguarding your digital assets has never been more critical, and at Microsoft, your security is our top priority. Microsoft research shows that multifactor authentication (MFA) can block more than 99.2% of account compromise attacks, making it one of the most effective security measures available.

As announced in August 2024, Azure started to implement mandatory MFA for Azure Public Cloud sign-ins. By enforcing MFA for Azure sign-ins, we aim to provide you with the best protection against cyber threats as part of Microsoft’s commitment to enhance security for all customers, taking one step closer to a more secure future.

As previously announced, Azure MFA enforcement was rolled out gradually in phases to provide customers with enough time to plan and execute their implementations:

We are proud to announce that multifactor enforcement for Azure Portal sign-ins was rolled out for 100% of Azure tenants in March 2025. Now, Azure is announcing the start of Phase 2 MFA enforcement at the Azure Resource Manager layer, starting October 1, 2025. Phase 2 enforcement will be gradually applied across Azure tenants through Azure Policy, following Microsoft safe deployment practices.

Starting this week, Microsoft sent notices to all Microsoft Entra Global Administrators by email and through Azure Service Health notifications to notify the start date of enforcement and how to prepare for upcoming MFA enforcement.

Customer impact

Users will be required to authenticate with MFA before performing resource management operations. Workload identities, such as managed identities and service principals, aren’t impacted by either phase of this MFA enforcement.

Learn more about the scope of enforcement.

How to prepare

1. Enable MFA for your users

To ensure your users can perform resource management actions, enable MFA for your users by October 1, 2025. To identify which users in your environment are set up for mandatory MFA, follow these steps

2. Understand potential impact

To understand potential impact ahead of Phase 2 enforcement, assign built-in Azure Policy definitions to block resource management operations if the user has not authenticated with MFA.

Customers can gradually apply this enforcement across different resource hierarchy scopes, resource types, or regions.

3. Update your Azure CLI and PowerShell clients

For the best compatibility experience, users in your tenant should use Azure CLI version 2.76 and Azure PowerShell version 14.3 or later.

Next steps for multifactor authentication for Azure sign-in

The post Azure mandatory multifactor authentication: Phase 2 starting in October 2025 appeared first on Microsoft Azure Blog.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Azure 多因素认证 MFA 网络安全 Microsoft
相关文章