MFA: Number matching compatibility / Google Authenticator, etc.

Anonymous
2022-11-29T08:30:10.003+00:00

Dear community, dear Microsoft support,

After the announcement that Microsoft will enforce the usage of number matching for all O365 users (using MFA) starting in Feb 2023, I asked myself if this feature will work with alternative authenticator apps like Google Authenticator, etc., as well? Or do I have to force all our users to switch to MSFT Authenticator now? Will authentication via phone call or text message still work as usual?

Some background: Using MFA is mandatory in our environment, but in some entities we cannot force users to install an app on a personal smartphone and we cannot afford procuring devices for all of them. Some of these users decided to add the MFA to their already existing Authenticator app instead of installing the MSFT Authenticator.

Many thanks for your thoughts, I hope I didn’t oversee an already existing question (search returned nothing helpful).

Tom.131

PS: I already posted that in the M365 area and received an appreciated reply from Katherine, who pointed me over here.

Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Nagappan Veerappan 651 Reputation points Microsoft Employee
    2022-11-30T14:29:28.367+00:00

    I don't know about alternative authenticator can be used "like Google authenticator".

    What Microsoft security try to put in a place is users with basic push MFA Approve or Deny in authenticator app. will be replaced with Number match soon (i.e Feb 2023). Since the Push notification is not secure enough. always have possibility of malicious users with leaked credentials attacker gets MFA with Push notification.

    Hence Number match will prevent them when they have to supply the number in authenticator app.

    If you have license to the user and want the other MFA method SMS or Voice. you can have them. Remember Voice & SMS have availability concern as it depends on mobile carrier network and its delay in processing the request

    I would recommend reviewing this chart to stay "Secure" MFA strength.
    https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods#authentication-method-strength-and-security

    FAQ -about Number match

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/how-to-mfa-number-match#faqs

    If you like my answer , please accept.

    Hope this helps

    Have a great day ahead


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.