How can I delegate permissions to help desk technicians to enable MFA for Microsoft 365 users?

How can I delegate permissions to help desk technicians to enable MFA for Microsoft 365 users?

Objective

This article explains how to delegate permissions in ADManager Plus so that help desk technicians can enable or manage multi-factor authentication (MFA) settings for Microsoft 365 users. This delegation ensures that routine MFA administration tasks can be handled by help desk staff without granting them full administrative privileges, maintaining security and improving operational efficiency.

Prerequisites 

  • Administrator access to ADManager Plus to create, modify, and assign help desk technician roles.

  • A Microsoft 365 tenant that's configured in ADManager Plus.

  • Network connectivity and valid credentials to communicate with Microsoft 365 services.

Steps to follow

Step 1: Steps to delegate MFA settings for Microsoft 365 users

  1. Log in to ADManager Plus as an administrator.

  2. Navigate to Delegation > Help Desk Delegation > Help Desk Roles.

  3. To configure permissions, either click Create New Role or select an existing role and click Edit.

  4. Go to the Microsoft 365 tab, then expand Management > User Management.

  5. Ensure the MFA Settings check box is selected. This grants technicians the ability to enable or manage MFA for Microsoft 365 users.

  6. Click Save to apply the changes.

Step 2: Assign the help desk role to technicians

  1. Navigate to Delegation > Help Desk Delegation > Help Desk Technicians.

  2. Select the technician accounts that need permission to manage MFA. If the technician is not listed, click Add New Technician.

  3. In the Select Help Desk Roles field, choose the role that includes MFA Settings under Microsoft 365.

  4. Click Save to assign the role to the technician.

Tips 

  1. Check the technician’s dashboard to ensure the Microsoft 365 MFA management options are visible.

  2. Review Audit Reports to see that technician actions on MFA are logged correctly.

  3. Optionally, disable the delegated permissions temporarily and confirm that the technician loses access, verifying that delegation is enforced.

                  New to ADSelfService Plus?

                    • Related Articles

                    • Delegating Enable MFA for Microsoft 365 users' permission to help desk technicians

                      Steps to delegate Enable MFA for Microsoft 365 users permission to help desk technicians in ADManager Plus: 1. Log in to ADManager Plus and navigate to the Delegation tab. 2. In the left pane, navigate to Help Desk Delegation > Help Desk Roles. 3. ...
                    • How to delegate Microsoft 365 tenants to help desk technicians

                      Steps to delegate Microsoft 365 tenants to help desk technicians: Go to to the Delegation tab. In the left pane, navigate to Help Desk Delegation > Help Desk Technicians. In the Help Desk Technicians page, find the technician to whom you want to ...
                    • How to granularly delegate attributes to a help desk technician

                      Steps to granularly delegate attributes to a help desk technician in ADManager Plus: 1. Log in to ADManager Plus and navigate to the Delegation tab. 2. Navigate to Help Desk Delegation > Help Desk Roles. 3. Click the Edit icon in the Actions column ...
                    • How can I delegate help desk roles to AD groups using ADManager Plus?

                      Objective Organizations often manage help desk access based on AD group membership to simplify permission management. Assigning roles to groups in ADManager Plus helps ensure that all members inherit the same delegated permissions automatically. This ...
                    • API usage limit in ADManager Plus

                      The number of user accounts that technicians can enable in a day using the EnableUser API depends on the total number of licensed help desk technicians. For every help desk technician license, an additional 50 API calls will be added to the daily API ...