A revamped Security workspace is rolling out in the Microsoft Partner Center and broad MFA enforcement across the portal and APIs, with API MFA becoming mandatory on April 1, 2026. The Security requirements UI now clearly separates mandatory versus recommended controls, and access to the Security workspace is expanding to indirect resellers on a phased schedule completing by early November.โโ
Whatโs new in the Microsoft Partner Center

The Security workspace is rolling out to all indirect resellers, with Microsoft stating full access will be in place by early November to help partners assess posture and act on requirements.โ Multifactor authentication is enforced across all Partner Center pages, the APIs are now MFAโready, and API calls without MFA will be blocked starting April 1, 2026.โ The redesigned Security requirements experience separates mandatory and recommended controls to make compliance steps unambiguous for CSP authorization.โ Microsoft is also enforcing MFA for all users signing in to the Microsoft 365 admin center, aligning admin operations with a broader Zero Trust posture.โ
Why it matters
CSP authorization eligibility is tightening, with mandatory requirements that include enabling MFA for administrative users, designating a security contact, and responding to security alerts within 24 hours for certain partner types. Annual validation of these requirements will occur during each partnerโs CSP anniversary month starting January 2026, making ongoing compliance a continuous operational responsibility. The Security requirements dashboard provides a consolidated score and actionable recommendations so partners can close gaps proactively and demonstrate alignment to best practices.โ
Timeline and key dates
-
August 30, 2025: MFA required for all pages in the Partner Center portal for signโin and use.โ
-
September 30, 2025: Partner Center APIs are MFA-enabled and ready for testing and integration.โ
-
Octoberโearly November 2025: Security workspace rollout expands to indirect resellers with completion targeted by early November.
-
April 1, 2026: Full enforcement for Partner Center API MFA; nonโMFA API calls will be blocked.โ
What changes for partners
New CSP authorization eligibility requirements effective October 1, 2025 require enabling MFA for all administrative users, designating a security contact, and responding to security alerts within 24 hours for direct bill partners and distributors. The redesigned Security requirements UI makes it clear which controls are mandatory versus recommended for CSP continuation, reducing ambiguity and audit friction.โ Appropriate roles for the Security workspace include Admin Agent, Security Administrator, and Security Reader, ensuring the right people can monitor posture and execute remediations. The Security workspace offers an overview with top actions, trends, and quickstart resources so teams can triage incidents and track security improvements over time.โ
How to prepare now
-
Audit MFA coverage across Partner Center roles and the Microsoft 365 admin center to ensure every signโin path is protected and meets enforcement.โ
-
Integrate MFA into all Partner Center API workflows, test endโtoโend authentication, and plan for April 1, 2026 enforcement to avoid service disruptions.โ
-
Set a designated security contact in Partner Center and formalize a process to respond to security alerts within 24 hours to meet eligibility requirements.
-
Use the Security requirements dashboard to identify gaps, track the consolidated score, and apply the recommended actions for measurable improvements.โ
-
Adopt the Secure Application Model and Granular Delegated Admin Privileges (GDAP) to align with Microsoftโs partner security requirements and leastโprivilege patterns.
-
Leverage the builtโin AI assistant in the Security workspace to clarify requirements, resolve common questions, and navigate training resources efficiently.โ
For indirect resellers
Access to the Security workspace is expanding now, with Microsoft targeting full availability for all indirect resellers by early November to standardize security posture across the channel.โ Once enabled, resellers should review the Security overview, top actions, and trends, and confirm appropriate roles are assigned for visibility and execution.โ Indirect resellers must enable MFA and follow the Security requirements UI guidance to complete mandatory controls and track recommended improvements.โ
Practical checklist
-
Confirm MFA enforcement is active for all Partner Center users and admins, and verify successful MFA prompts during signโin.โ
-
Assign or verify a security contact in Partner Center, document the 24โhour alert response process, and test escalation paths.โ
-
Open the Security workspace to review mandatory versus recommended controls, then address mandatory items first to protect CSP standing.โ
-
Review partner security requirements for SAM and GDAP adoption to reduce risk and meet Microsoftโs leastโprivileged access expectations.โ
-
Use the AI assistant in the Security workspace to answer howโto questions and surface relevant learning resources quickly.โ
The bottom line
Microsoft is tightening Partner Center security with mandatory MFA across the portal and APIs, culminating in an April 1, 2026 API enforcement milestone that partners must meet. The new Security workspace and redesigned requirements UI are meant to make compliance clearer and faster, while updated CSP eligibility rules raise the bar on operational readiness. Partners that act nowโenabling MFA endโtoโend, integrating API MFA, formalizing security contacts and response SLAs, and adopting SAM and GDAPโwill minimize disruption and strengthen customer trust.โ
About The Author
Discover more from Microsoft News Now
Subscribe to get the latest posts sent to your email.