Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Thanks
There is no "Service Settings" in the MFA section only App passwords, Trusted IP's and remember MFA on trusted devices...
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Good afternoon,
We have text and call authentication set up as multi factor authentication for our users.
This has worked very well up until recently, when Microsoft have started to force the option of the authenticator app on users, and made it unskippable despite our setup.
The option to skip is not present on the "improve your sign ins" screen.
Where is the setting to disable the forcing of the authenticator app for the user?
I have seen on other posts there are options to disable this. For example here: https://learn.microsoft.com/en-us/answers/questions/1338546/users-are-being-forced-to-use-microsoft-authentica
If, as in the screenshot in the "accepted answer" post we change the registration campaign status to disabled, does this remove the enforced app prompt?
At present it is currently set to "Microsoft managed".
We are fine with the app as an OPTION however it should not be mandatory as it does exclude people who do not have the latest phones, or indeed, any smart phone.
Chris
Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Thanks
There is no "Service Settings" in the MFA section only App passwords, Trusted IP's and remember MFA on trusted devices...
On the flip side, who's fault is it for leaving it at default settings of "Microsoft-managed" and not reading any updates for soon to be released changes?
It's more then just this it seems. Why they are forcing their second rate authenticator is beyond me but it's annoying. In Entra (old Azure) at https://entra.microsoft.com/ :
Protection -> Authentication Methods -> Settings -> System-preferred multifactor authentication: Disabled
Protection -> Authentication Methods -> Registration Campaign: Edit then Disabled and Save
Protection -> Authentication Methods -> Policies: Click Microsoft Authenticator and switch it to Disabled (if you want) then go to the others you do want and make sure they are enabled for all users (or whatever users you want). We have SMS, Voice Call, and Email OTP personally.
This is the answer. Thank you, ADynes!
Forcing us to use the Microsoft Authenticator is a mistake, Microsoft. Most of your users don;t have faith in your products. We'd rather use anything else to authenticate.
There's literally 0 reason to do that.
Go to entra portal and create an access pass pin. This overrides all authentication methods.
Also disable the option to "reconfirm" mfa for users every X days.
That horrible setting is to blame.
We run a school district with multiple staff being locked out because of this app enforcement. With no help from Microsoft on this, what we have been doing is turning off MFA, logging into their account and setting it to forward to their Google accounts, and then turning MFA back on. This keeps the original accounts, but they only need to deal with Google's MFA, which doesn't lock them out of their accounts. It's not ideal, but it has been very effective. So if you're in a workplace with multiple domains, consider switching which one is your primary.