There is no way currently to configure a default method, as long as multiple methods are enabled the user can select/use any of them. The preference for Authenticator is due to Security defaults, and similarly we now have the "system-preferred" policy as detailed here: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-system-preferred-multifactor-authentication
Change default MFA verification method for new users
Stavros
40
Reputation points
Ever since combined registration for MFA and SSPR was enabled for our tenant, Microsoft Authenticator has become the default verification method for new users. I was wondering if there is a way to change this and make Phone being the default verification method, while allowing Microsoft Authenticator as an alternative.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Microsoft Entra ID
A cloud-based identity and access management service for securing user authentication and resource access
Microsoft Security | Microsoft Authenticator
Microsoft Security | Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Answer accepted by question author
-
Vasil Michev 123.7K Reputation points MVP Volunteer Moderator2023-03-28T07:23:58.4833333+00:00