Disabling mandatory MS Authenticator app

Anonymous
2023-09-12T11:08:43+00:00

Good afternoon,

We have text and call authentication set up as multi factor authentication for our users.

This has worked very well up until recently, when Microsoft have started to force the option of the authenticator app on users, and made it unskippable despite our setup.

The option to skip is not present on the "improve your sign ins" screen.

Where is the setting to disable the forcing of the authenticator app for the user?

I have seen on other posts there are options to disable this. For example here: https://learn.microsoft.com/en-us/answers/questions/1338546/users-are-being-forced-to-use-microsoft-authentica

If, as in the screenshot in the "accepted answer" post we change the registration campaign status to disabled, does this remove the enforced app prompt?

At present it is currently set to "Microsoft managed".

We are fine with the app as an OPTION however it should not be mandatory as it does exclude people who do not have the latest phones, or indeed, any smart phone.

Chris

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Most helpful
  1. Anonymous
    2024-02-29T22:25:26+00:00

    It's more then just this it seems. Why they are forcing their second rate authenticator is beyond me but it's annoying. In Entra (old Azure) at https://entra.microsoft.com/ :

    Protection -> Authentication Methods -> Settings -> System-preferred multifactor authentication: Disabled

    Protection -> Authentication Methods -> Registration Campaign: Edit then Disabled and Save

    Protection -> Authentication Methods -> Policies: Click Microsoft Authenticator and switch it to Disabled (if you want) then go to the others you do want and make sure they are enabled for all users (or whatever users you want). We have SMS, Voice Call, and Email OTP personally.

    This is the answer. Thank you, ADynes!

    Forcing us to use the Microsoft Authenticator is a mistake, Microsoft. Most of your users don;t have faith in your products. We'd rather use anything else to authenticate.

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-12-01T15:31:38+00:00

    I DO NOT WANT the authenticator app on my PC or on my phone. YOU are locking me out of my account that I pay money for!! I do my business on my computer. I am a Realtor not a computer geek. I do not know what Azul is or where to find it and I DON'T WANT IT!!

    I just had to change my passwords to access my account. Please don't make me become an Apple user to escape Microsoft!! There's a lot of Boomers in this society. WE don't all want or need this ****! Even those of us aware of cybersecurity and wire fraud.

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-10-21T05:38:27+00:00

    Yeah....these responses are about enabling or disabling ms auth as a whole, or per user, not the "hey user, we noticed this auth flow doesn't use ms authenticator, download it here." While this is needed capability in some rollout using soft launches, these aren't the settings to control that policy.

    I found what looks like the policy for ms forcing download setting @

    a) Entra ID > Security > Authentication Methods > settings

    b) configure the two areas to your liking, enabled with group based targeting and/or exclusions if you want to...disabled if you want an out of band method, disabled if you want 3rd party mfa.

    Saw this post when googling the config to solve it for my use case...haven't tested yet.

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-05-29T13:27:30+00:00

    Please read his question before answering. He does not want to force it bot, he wants to 'NOT" force the app, he also does not want to disable it, because some 'users' might actually want to use the app, while others, who don't have a smart phone, or the company does not pay for it, will want to use their desk phone to authenticate, 'NOT' their personal mobile phone. Despite MS delusions, most people still don't have a smart phone, or one with internet services. In my experience, no matter what you do, the app takes over. He doesn't want the app to take over. Now answer correctly, so we can all fix this. Even since MS forced MFA, this is all I do all day chasing around users who could log in one min, then can't the next. And my company would rather pay me to do something productive. users shouldn't need a personal smart phone with internet services just to read a company email. Is MS paying for this?

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2023-11-07T21:38:46+00:00

    You first need to disable security defaults then in order to remove the requirement for MFA (specifically MS Authenticator App). Here are the steps:

    1. Go to the Microsoft Entra admin center (https://entra.microsoft.com/) and sign in.
    2. Under Microsoft Entra ID (Azure AD), select Go to Microsoft Entra ID.
    3. Select Properties, scroll down, and then select the Manage security defaults link.
    4. On the right side of the screen, in the Security defaults pane, DISABLE security defaults, by using the drop-down menu to select Disable. Then select Save.
    5. Approve all the necessary warnings. This will allow other MFA options through this link: https://entra.microsoft.com/#view/Microsoft_AAD_IAM/AuthenticationMethodsMenuBlade/~/AdminAuthMethods

    Here's the link to the official help article. Microsoft tricks you by wording the article as the way to enable it, even though that's already the default. Just follow the same steps to disable.

    https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-turn-on-mfa?view=o365-worldwide&tabs=secdefaults

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments