what role is now required to enable/enforce MFA on user by user basis?

Posted by ubihelp702@reddit | sysadmin | View on Reddit | 14 comments

Our company has some lower level technicians that only have certain roles (not global admin, will list the roles we provided to lower techs below) and they used to be able to enable and enforce multifactor authentication on a user by user basis. Recently Microsoft migrated these pages to entry and and I guess broke the permissions/roles as my techs are reporting they can no longer do this anymore (failed to enable multifactor authentication, unexpected error when enabling multifactor authentication).

I attempted a microsoft support request and the first question he asked me was "you want help enabling mfa globally?" to which I replied no, and restated everything i put in the ticket which is basically the above. He replied with ok they need global admin. So i'm not sure if he fully understood or not and would not budge past telling me I now have to give all my lower level techs global admin which seems insane to me.

Does anyone know how i can fix this without giving global admin?

Heres the roles my techs have:

Admin center access:

Authentication Administrator

Exchange Administrator

License Administrator

Privileged Authentication Administrator

Security Reader

Sharepoint Administrator

Teams Administrator

User Administrator

Collaboration:

Exchange Administrator

Sharepoint Administrator

Teams Administrator

Identity:

Authentication Administrator

License Administrator

Privileged Authentication

User Administrator

Read-only:

Security Reader