Authentication Methods Registration

Anonymous
2025-06-30T12:53:30+00:00

hello,

i working with a new client and trying to enforce MFA on all users, i am trying to make users register 2 authentication methods (Microsoft authenticator and SMS) but could not do it, i have enabled both methods from auth method and from the password reset i have on require two authentication, i know that i can make users register through registration campaign but what i want to do is to make the user register both methods the first time they log in after i have enabled the policy on them.

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-06-30T13:33:23+00:00

    Hello, 

    Good day to you! 
    Thank you for reaching out to Microsoft Community! 

    I hope you can understand that your situation is beyond my support scope. However, after researching this topic further, I’d like to share some information you can infer:       

    For your situation, please take note this point: 

    • Microsoft Entra ID (formerly Azure AD) does not currently support enforcing multiple MFA method registrations simultaneously at first login.

    However, here are some steps you can try: 

    1. Enable Combined Registration Experience 

    This merges MFA and SSPR (Self-Service Password Reset) registration into one flow. 

    • You can go to Entra Admin Center > Identity > User Settings > Manage user feature settings.
    • Enable: “Users can use combined security information registration experience”.

    For reference: Combined registration for SSPR and Microsoft Entra multifactor authentication - Microsoft Entra ID | Microsoft Learn 

    2. Configure Authentication Methods: 

    • Still Entra Admin Center > Protection > Authentication Methods.
    • Enable both Microsoft Authenticator and SMS. Then go to Password Reset > Properties, and set:

    “Number of methods required to reset” = 2.

    3. Enable MFA Registration Policy: 

    • You can go to Protection > MFA Registration Policy. Then, you assign it to all users or specific groups.
    • Set Policy enforcement to Enabled.

    This prompts users to register MFA during their next interactive sign-in. 

    More detail information via Configure the MFA registration policy - Microsoft Entra ID Protection | Microsoft Learn 

    After that, you can create a Conditional Access policy that requires MFA for sign-in. This forces users to complete registration if they haven’t already. 

    Additionally, if you're working in a smaller tenant or prefer a simpler setup: 

    • You can enable Security Defaults to enforce MFA using Microsoft Authenticator.
    • Then create a registration campaign to prompt users to add a second method (e.g., SMS).

    Note: This won’t enforce both methods at first login, but it will guide users toward having two methods over time. 

    Once again, thank you again for raising this issue; it’s helped broaden my understanding. I'm only a moderator on the forum, so I can only share my experience and research-based knowledge. I hope you understand that I want to help as much as I can within the scope of this forum.

    Please feel free to reply below if you have any update or further concern. 

    Best Regard,   

    Tina L - MSFT | Microsoft Community Support Specialist

    Was this answer helpful?

    0 comments No comments