Migrate to the Authentication methods policy in Azure Active Directory by 30 September 2024

Pablo Esteban Trujillo 70 Reputation points
2023-03-31T16:17:22.2333333+00:00

On 30 September 2024, the ability to manage authentication methods in the legacy multifactor authentication (MFA) and self-service password reset (SSPR) policies will be retired. Before that date, you'll need to migrate to the Authentication methods policy in Azure AD, which provides all the same capabilities, plus it enables you to:

  • Centrally manage MFA, SSPR, and passwordless authentication methods.
  • More granularly target authentication methods to groups of users instead of all users.
  • Access more secure authentication methods that will be part of future updates of this policy.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,271 Reputation points Microsoft Employee Moderator
    2023-04-03T19:38:42.3166667+00:00

    For more information, see:

    How to migrate MFA and SSPR policy settings to the Authentication methods policy for Azure AD
    Manage authentication methods for Azure AD

    As mentioned, the unified Authentication methods policy in Azure AD consolidates multifactor authentication (MFA), SSPR, and passwordless authentication methods into one management location and allows for more granular control over authentication methods, including separate controls for each type of OATH token.

    0 comments No comments

  2. JamesTran-MSFT 37,226 Reputation points Microsoft Employee Moderator
    2023-04-05T19:24:56.1633333+00:00

    @Pablo Esteban Trujillo Thank you for your post!

    I understand that you have a question regarding the Authentication methods policy migration within Azure AD. I'll add onto what was shared by Marilee to hopefully help point you in the right direction.

    Azure Multi-Factor Authentication Server will be deprecated 30 September 2024:

    Beginning September 30, 2024, Azure Multi-Factor Authentication Server deployments will no longer service multi-factor authentication (MFA) requests, which could cause authentications to fail for your organization.

    Required action:

    To ensure uninterrupted authentication services and to remain in a supported state, organizations should migrate their users’ authentication data to the cloud-based Azure MFA service using the latest Migration Utility included in the most recent Azure MFA Server update. Learn more at Azure MFA Server Migration.  

    I hope this helps!

    If you have any other questions, please let us know.


    Additional links:


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.