AADSTS50079: the user must register for multifactor authentication
Likely causes
- A new account that hasn't registered MFA methods.
- A new policy now requires MFA for this user.
- The user's methods were removed, for example after a phone change.
- Federated users: the MFA claim isn't coming from the federation provider.
How to fix it
- Have the user sign in and follow the More information required prompts to register a method, such as the Microsoft Authenticator app.
- They can also register at
https://aka.ms/mysecurityinfo. - If they can’t complete registration (no phone, lost access), an admin can issue a Temporary Access Pass if your organization uses them, or help set up another method.
- Federated tenants: an admin checks that the federation provider performs MFA and passes the MFA claim.
Checked against: learn.microsoft.com, learn.microsoft.com