Disabling mandatory MS Authenticator app

Anonymous
2023-09-12T11:08:43+00:00

Good afternoon,

We have text and call authentication set up as multi factor authentication for our users.

This has worked very well up until recently, when Microsoft have started to force the option of the authenticator app on users, and made it unskippable despite our setup.

The option to skip is not present on the "improve your sign ins" screen.

Where is the setting to disable the forcing of the authenticator app for the user?

I have seen on other posts there are options to disable this. For example here: https://learn.microsoft.com/en-us/answers/questions/1338546/users-are-being-forced-to-use-microsoft-authentica

If, as in the screenshot in the "accepted answer" post we change the registration campaign status to disabled, does this remove the enforced app prompt?

At present it is currently set to "Microsoft managed".

We are fine with the app as an OPTION however it should not be mandatory as it does exclude people who do not have the latest phones, or indeed, any smart phone.

Chris

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Oldest
  1. Anonymous
    2024-02-07T21:12:42+00:00

    Still struggling with this. I've tried only allowing the app for a select security group and disabling it altogether, and its still the giant default option when new staff go to the registration link.

    I disabled the campaign, I can't go into security defaults because that screen isn't accessible if you use conditional access.

    Any other thoughts?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-02-13T16:26:05+00:00

    Still struggling with this. I've tried only allowing the app for a select security group and disabling it altogether, and its still the giant default option when new staff go to the registration link.

    I disabled the campaign, I can't go into security defaults because that screen isn't accessible if you use conditional access.

    Any other thoughts?

    If you have any location-based Conditional Access Policies, Microsoft now uses Microsoft Authenticator to verify locations; even if the policy is "Report-Only". Check ALL of your Conditional Access Policies; it will be one of these causing the Authenticator requirement. We learned this the hard way.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-02-13T16:33:05+00:00

    This is interesting, I do have location based conditional access (we don't require MFA if someone is in one of our physical offices). Not sure why they would require authenticator for that when its the device's IP that should be reporting it. I will test this and see if it removes the Authenticator from the registration screen.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-02-13T17:39:39+00:00

    Your MS Authenticator does not work with all versions of Android devices. How do log in to the Azure Portal to disable the Authenticator, when I need the MS Authenticator to log in to Azure

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-02-20T15:20:36+00:00

    We run a school district with multiple staff being locked out because of this app enforcement. With no help from Microsoft on this, what we have been doing is turning off MFA, logging into their account and setting it to forward to their Google accounts, and then turning MFA back on. This keeps the original accounts, but they only need to deal with Google's MFA, which doesn't lock them out of their accounts. It's not ideal, but it has been very effective. So if you're in a workplace with multiple domains, consider switching which one is your primary.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments