Disabling mandatory MS Authenticator app

Anonymous
2023-09-12T11:08:43+00:00

Good afternoon,

We have text and call authentication set up as multi factor authentication for our users.

This has worked very well up until recently, when Microsoft have started to force the option of the authenticator app on users, and made it unskippable despite our setup.

The option to skip is not present on the "improve your sign ins" screen.

Where is the setting to disable the forcing of the authenticator app for the user?

I have seen on other posts there are options to disable this. For example here: https://learn.microsoft.com/en-us/answers/questions/1338546/users-are-being-forced-to-use-microsoft-authentica

If, as in the screenshot in the "accepted answer" post we change the registration campaign status to disabled, does this remove the enforced app prompt?

At present it is currently set to "Microsoft managed".

We are fine with the app as an OPTION however it should not be mandatory as it does exclude people who do not have the latest phones, or indeed, any smart phone.

Chris

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Most helpful
  1. Anonymous
    2024-05-08T13:33:01+00:00

    Sometimes changes I make in Entra, or Identify as it is now, take overnight to happen. I do not know why.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-04-08T09:39:10+00:00

    Some of our users in China are using smartphone without Google services, they can't install and run Auth app. We're not allow to disable MFA which advised by auditor, so they can't access email right now.

    Microsoft please do something (or try not to do something evil).

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-03-12T23:07:17+00:00

    Google has an authenticator and there is another popular one, Authy, I think.

    Why Microsoft HAD to make their own is silly.

    People get pissed when they have to use on in the first place, let alone a new one, if they already use one of the two listed above.

    My client is P.O.'d and wants that feature removed altogether and I don't blame him.

    I mean really. It's not a money maker for MS. They should let people use any one they want.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-02-20T23:22:43+00:00

    There's literally 0 reason to do that.

    Go to entra portal and create an access pass pin. This overrides all authentication methods.

    Also disable the option to "reconfirm" mfa for users every X days.

    That horrible setting is to blame.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-02-20T15:20:36+00:00

    We run a school district with multiple staff being locked out because of this app enforcement. With no help from Microsoft on this, what we have been doing is turning off MFA, logging into their account and setting it to forward to their Google accounts, and then turning MFA back on. This keeps the original accounts, but they only need to deal with Google's MFA, which doesn't lock them out of their accounts. It's not ideal, but it has been very effective. So if you're in a workplace with multiple domains, consider switching which one is your primary.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments