Additional Microsoft Entra services and features related to identity, access, and network security
MFA for test accounts, and users with more than one role/account
We have some legitimate scenarios where Microsoft's restriction on the use of the same phone number for more than one account in Entra is annoying.
- I have test accounts on my tenant where I want to be able to direct any MFA/SSPR related SMS messages for all the accounts to my mobile.
- In addition to the test accounts, I have one or two system mailboxes for special purposes such as reviewing suspected SPAM where the same applies.
- Due to the nature of our organisation (a charity) we have mailboxes related to people's function - so I have a small number of users who have multiple functions and therefore multiple mailboxes - and they want SMS messages sent to one single device of theirs too.
If this is attempted, Entra reports:
"The phone number is registered by another user in this tenant. Please enter a different phone number."
I am well aware that SMS isn't that strong for MFA but the nature of our organisation also limits the authentication methods we can compel our users to adopt as we don't control the devices they use to access the service (which is a Business Basic license - i.e. online only), and we can't force them to use their personal mobiles for things like the Authenticator App either. MFA with SMS is at least something people are used to in their personal lives so there doesn't tend to be pushback on that.
I can likely work around this for myself using the Authenticator App - but that would mean my test accounts are no longer fully representative of the way my users are setup, and that is the whole point of having test users!
Just wondered how others deal with this sort of thing and/or whether it is possible to disable the restriction for certain users it affects.
Thanks!