How can I actually exclude users from requiring Authenticator?

Josh Steadman 0 Reputation points
2024-11-15T19:34:30.96+00:00

We initially had Authenticator on for all users as a policy. I've since revised the policy to target a specific group, and exclude another group. And all users are still being prompted, regardless of which group they are in. How do I fix this?Screenshot-INCLUDE

Screenshot-EXCLUDE

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2024-11-15T20:09:48.8633333+00:00

    Check what you have set for the registration campaign under that same menu

    User's image


  2. Sandeep G-MSFT 20,906 Reputation points Microsoft Employee Moderator
    2024-11-19T03:40:46.7066667+00:00

    @Josh Steadman

    Thank you for posting this in Microsoft Q&A.

    As I understand initially you had a policy configured in Azure for MFA using authenticator app for all users in your tenant. Later you revised the policy and allowed MFA for only few groups and excluded MFA for few groups. Even after these changes, all users are still getting prompted for MFA.

    To fix this issue first you will have to check who is triggering MFA. You can access any one user who is excluded for MFA and still prompted for MFA and check there sign-in logs. Check who is triggering for MFA.

    In Sign-in logs you can check due to which feature MFA is getting triggered. If conditional access policy is triggering MFA then, these logs will also show which policy is triggering MFA.

    You can check the same policy and make necessary changes.

    There is also a feature known as registration campaign in Azure. But this with feature users will only be prompted for MFA registration.

    The purpose of Microsoft launching registration campaign is to help organization users move away from SMS and Voice authentications.

    With this registration campaign users in your organization who are relying on SMS and voice for MFA will be prompted to use the Microsoft Authenticator app.

    This means this program will get applied to only those users who are using SMS and Voice method for MFA.

    Users will still be prompted for MFA depending on what authentication method you have assigned to them for registration or what method they have used while MFA registration initially.

    You can check below article to know more about registration campaign,

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/how-to-mfa-registration-campaign#enable-the-registration-campaign-policy-using-the-microsoft-entra-admin-center

    Let us know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.