Disabling mandatory MS Authenticator app

Anonymous
2023-09-12T11:08:43+00:00

Good afternoon,

We have text and call authentication set up as multi factor authentication for our users.

This has worked very well up until recently, when Microsoft have started to force the option of the authenticator app on users, and made it unskippable despite our setup.

The option to skip is not present on the "improve your sign ins" screen.

Where is the setting to disable the forcing of the authenticator app for the user?

I have seen on other posts there are options to disable this. For example here: https://learn.microsoft.com/en-us/answers/questions/1338546/users-are-being-forced-to-use-microsoft-authentica

If, as in the screenshot in the "accepted answer" post we change the registration campaign status to disabled, does this remove the enforced app prompt?

At present it is currently set to "Microsoft managed".

We are fine with the app as an OPTION however it should not be mandatory as it does exclude people who do not have the latest phones, or indeed, any smart phone.

Chris

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Most helpful
  1. Anonymous
    2024-04-04T05:25:50+00:00

    Also all the fixes require a sign in which doesn’t work as I don’t want their forced app and can’t log in to azure or whatever either - totally unacceptable

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-11-13T22:49:04+00:00

    HELP. I am one person, not an organization, but I made the mistake of enabling Microsoft Authenticator. I can't remove it. I don't have Azure. How can I get rid of it?

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-11-13T18:40:52+00:00

    Hey all,

    So we actually have some users who do not use smart-phones and are unable to use the authenticator app. Some of my users are more technically inclined and prefer the method. The way that I found which seemed to work is to actually disable the have the user do it individually.

    The first thing is to disable the Microsoft security defaults. This way it will allow you to bypass the requirement for the authenticator app.

    Sign in to the Microsoft Entra admin center as least a Security Administrator.

    1. Browse to Identity > Overview > Properties.
    2. Select Manage security defaults.
    3. Set Security defaults to Disabled.
    4. Select Save.

    Once that is disabled direct the users to update their security settings by following the directions here: https://support.microsoft.com/en-us/account-billing/change-your-two-step-verification-method-and-settings-c801d5ad-e0fc-4711-94d5-33ad5d4630f7

    Make sure the default is set to the users method and if authenticator was used it can be deleted.

    I just did this as a test on my account and it seemed to work.

    Definitely not the ideal scenario since the whole point is for administrators to be able to set things up so the users can just do their job, but Microsoft doesn't seem to think like this.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-11-02T06:35:53+00:00

    The question has been misread - we do not want to disable the thing entirely, just the forcing of it onto users!!!

    At present our users are not allowed to opt out from the app download. Previously the app was an option rather than mandatory.

    You can individually configure it here:

    https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/~/Properties

    Go to Protection - Authentication Methods and you can oppt in/out of the following:

    FIDO2 security key No Microsoft AuthenticatorNo

    SMSNo

    Temporary Access PassNo

    Hardware OATH tokens (Preview)No

    Third-party software OATH tokensNo

    Voice callNo

    Email OTPYes

    Certificate-based authenticationNo

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2023-09-14T15:33:33+00:00

    Dear Chris11118

    Thanks a lot for your feedback and very sorry for late reply!

    For information on how to force all users to use MFA, please kindly refer to this official document and the following screenshot:

    WIsh you have a wonderful day!

    Sincerely

    Kerry Chen | Microsoft Community Moderator

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments