Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Sometimes changes I make in Entra, or Identify as it is now, take overnight to happen. I do not know why.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Good afternoon,
We have text and call authentication set up as multi factor authentication for our users.
This has worked very well up until recently, when Microsoft have started to force the option of the authenticator app on users, and made it unskippable despite our setup.
The option to skip is not present on the "improve your sign ins" screen.
Where is the setting to disable the forcing of the authenticator app for the user?
I have seen on other posts there are options to disable this. For example here: https://learn.microsoft.com/en-us/answers/questions/1338546/users-are-being-forced-to-use-microsoft-authentica
If, as in the screenshot in the "accepted answer" post we change the registration campaign status to disabled, does this remove the enforced app prompt?
At present it is currently set to "Microsoft managed".
We are fine with the app as an OPTION however it should not be mandatory as it does exclude people who do not have the latest phones, or indeed, any smart phone.
Chris
Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Sometimes changes I make in Entra, or Identify as it is now, take overnight to happen. I do not know why.
Some of our users in China are using smartphone without Google services, they can't install and run Auth app. We're not allow to disable MFA which advised by auditor, so they can't access email right now.
Microsoft please do something (or try not to do something evil).
Google has an authenticator and there is another popular one, Authy, I think.
Why Microsoft HAD to make their own is silly.
People get pissed when they have to use on in the first place, let alone a new one, if they already use one of the two listed above.
My client is P.O.'d and wants that feature removed altogether and I don't blame him.
I mean really. It's not a money maker for MS. They should let people use any one they want.
There's literally 0 reason to do that.
Go to entra portal and create an access pass pin. This overrides all authentication methods.
Also disable the option to "reconfirm" mfa for users every X days.
That horrible setting is to blame.
We run a school district with multiple staff being locked out because of this app enforcement. With no help from Microsoft on this, what we have been doing is turning off MFA, logging into their account and setting it to forward to their Google accounts, and then turning MFA back on. This keeps the original accounts, but they only need to deal with Google's MFA, which doesn't lock them out of their accounts. It's not ideal, but it has been very effective. So if you're in a workplace with multiple domains, consider switching which one is your primary.