Files
Scripting/Powershell/PowerShell-Office365Admin/MSOnline/BulkChangeMFASetting.ps1
DistractADD cfddd4fad2 Added Files
2021-07-06 13:16:46 +10:00

43 lines
1.6 KiB
PowerShell

# Bulk enable or disable MFA for all users in a tenant
#
# Enable or disable MFA?
$enableMFA = $true
# Import MSOnline module and connect
Import-Module MSOnline
Connect-MsolService
# Enable or disable MFA
if ($enableMFA) {
# Create an object containing the authentication requirements
$authReq = New-Object -TypeName Microsoft.Online.Administration.StrongAuthenticationRequirement
# Include all relying parties
$authReq.RelyingParty = '*'
# Set MFA state to enabled
# Enabled allows connected apps to keep working until the user completes MFA set up.
# This can also be set to enforced which would disconnect everything immediately.
$authReq.State = 'Enabled'
# Set the cut off date before which registered devices should require re-connecting with MFA.
# Using the current date is recommended so that all previously connected devices have to be reconnected.
$authReq.RememberDevicesNotIssuedBefore = (Get-Date)
# Find all licenced users who do not currently have MFA enabled or enforced
$usersToChange = Get-MsolUser | Where-Object {$_.StrongAuthenticationRequirements.State -notmatch 'Enabled|Enforced' -and $_.isLicensed -eq $true}
# Enable MFA for those users
$usersToChange | Set-MsolUser -StrongAuthenticationRequirements $authReq
}
else {
# Find all licenced users who currently have MFA enabled or enforced
$usersToChange = Get-MsolUser | Where-Object {$_.StrongAuthenticationRequirements.State -match 'Enabled|Enforced' -and $_.isLicensed -eq $true}
# Disable MFA for those users
$usersToChange | Set-MsolUser -StrongAuthenticationRequirements @()
}