What is the difference between Microsoft Authenticator settings and MFA Registration under Identity Protection

Rizwan Assad 341 Reputation points
2022-11-30T12:25:17.96+00:00

What difference is there between "Microsoft Authenticator settings" under Security > Authentication Methods > Authentication Methods Policies and "MFA Registration" Under Identity Protection are they both required or only 1 of them is enough there are some enhanced capabilities under Auth methods policies e.g., Show geographic location in push and passwordless notifications which is not available in MFA Registration" Under Identity Protection

please advise

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2022-12-02T00:46:48.947+00:00

    Hi @Rizwan Assad ,

    The registration enforcement is done through Identity Protection (Reference: Configure MFA registration policy). So if MFA is enforced through Identity Protection, users are asked to register during sign-in. They register multifactor authentication methods and SSPR methods (if the user is enabled for SSPR).

    https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/howto-identity-protection-configure-mfa-policy

    266290-registrationpolicy.jpg

    Users will be asked to register additional information allowed by the Authentication methods policy settings when the registration is required.

    The Authentication Methods Policy experience also consolidates the configuration of MFA and SSPR methods into Authentication Methods Policies. Like you said, the Authentication Methods policies also have more enhanced configurations.
    266378-image.png

    So you still need Identity Protection for enforcing the MFA registration, but you need to allow or disallow MFA options through Authentication Methods Policies (as opposed to the previous legacy experience).

    Let me know if this is what you were asking, if I understood your concern, and if you have further questions. I'm happy to help improve the document and get clarity from product groups if anything is unclear or inconsistent.

    -

    If the information helped you, please Accept the answer. This will help us and other community members as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.