Share via

Keep getting Let's keep your account secure, even though I have multiple methods that are more secure

Kristoffer Lilliestrand 0 Reputation points
2026-03-11T09:18:20.57+00:00

Hi,

I keep getting below every time I login.
User's image

I have mfa solutions and I don't want to add a phone or email, that it suggests. Every article I find says contact your administrator (as they might've added a setting for you). I am said admin and have not added a setting for this. I'm happy with my mfa options and don't want to add an email och phone number, as they're easier to spoof than for example, a hardware token.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. VEMULA SRISAI 13,135 Reputation points Microsoft External Staff Moderator
    2026-03-11T12:07:18.69+00:00

    Hello Kristoffer Rothstein,

    This prompt is expected behavior and not related to the strength of your MFA methods.

    “Let’s keep your account secure” is triggered by Security Information / SSPR enforcement, not by sign‑in MFA. Even if you use strong methods like FIDO2 or hardware security keys, Entra ID still requires at least one recovery method (phone or alternate email) for account recovery and self‑service password reset.

    Hardware tokens are authentication methods, but they do not satisfy recovery requirements, which is why the prompt keeps appearing. Conditional Access or MFA policies cannot suppress this screen.

    The only way to stop the prompt is to disable SSPR or exclude the user from SSPR, otherwise at least one recovery method is required by design.

    https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined

    https://learn.microsoft.com/en-us/entra/identity/authentication/overview-authentication

    SSPR behavior: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.