Users are being forced to use Microsoft Authenticator app

Zack Anderson 95 Reputation points
2023-07-28T15:35:30.4933333+00:00

I have users that are being FORCED to setup the MS Authenticator app to sign into cloud apps in a browser.

This is Microsoft's example screen and next to it is what my users are seeing. The Not now button is missing.

I do NOT have security defaults enabled.

I do NOT have conditional access policies enabled.

I can't force users to use a smartphone app if I don't pay for them to have a smart phone.

MFA setup missing Not Now.png

MFA Microsoft's example.png

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,086 questions
Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
5,823 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,094 questions
{count} votes

Accepted answer
  1. Dillon Silzer 54,926 Reputation points
    2023-07-28T16:43:38.43+00:00

    Hello Zack,

    Please go to Entra > Protection > Authentication methods > Registration campaign

    Check whether Microsoft Authenticator is applied for All users. If so, you can change who it is applied to by clicking All users.

    User's image


    If this is helpful please accept answer.

    32 people found this answer helpful.

16 additional answers

Sort by: Most helpful
  1. Keith Jasinski 60 Reputation points
    2023-09-01T22:34:05.9666667+00:00

    Hey all - OK, this fixed this for me today (01SE23). I did NOT have MFA/2FA enabled nor was Authenticator selected. So, like others here I have been DUMBFOUNDED by the FORCE on setting up Authenticator. So I found this setting which defaults to "Microsoft managed" for the System-preferred MFA. When I changed this to disabled, there is now a "Not now" option on the screen that would normally only give you the option to go to enable Authenticator. So you need to go to the Azure portal (here: https://portal.azure.com/) and then go to active directory. But from there follow the path at the top of this screen shot to find the spot to change the setting.

    NOTE TO THOSE FINDING THIS, REMEMBER THIS COULD CHANGE AT ANY TIME - thanks Microsoft - sigh

    I sincerely this helps someone as it is truly ANNOYING.

    EDIT: Also, if you've already got users that want to get rid of Authenticator, you then need to go to the regular user portal where methods are selected and delete Authenticator from the list...

    Keith

    AzurePic

    11 people found this answer helpful.

  2. Sione T 30 Reputation points
    2023-08-30T16:37:18.8233333+00:00

    Hi All,

    After lots of digging and panic attacks, I found the answer to stop force enrollment of MS Authenticator app. The answer worked for me as I had an agent that was stuck in the "Use MS Authenticator app" loop and was unable to sign into anything Microsoft related.

    https://answers.microsoft.com/en-us/msoffice/forum/all/office-365-force-microsoft-authenticator-not-call/05c94986-c93c-4bf4-b7c0-c84f02b7faf2

    Update: Found the page here: Azure AD > Security > Authentication Methods
    (I'm not with Microsoft. I am an independent contractor)

    4 people found this answer helpful.

  3. Tina Maddox 15 Reputation points
    2023-08-21T19:23:04.6033333+00:00

    As an admin on our account we've used 2fa for years but not forcing the Microsoft authentication app. Now I am unable to login without using it. We as a company do not use that application at all and am looking for a way to continue using the secure method we have setup for our users.

    Does anyone have any advice on getting past this?

    3 people found this answer helpful.

  4. Paul 15 Reputation points
    2023-08-31T01:10:37.4+00:00

    So this made me pretty angry. It's the end of the day and I have mission critical emails to deal with and suddenly I'm locked out of my account because of this forced use of the authenticator app.

    I already had the app installed on my phone but with a different account. It took me about ten minutes to figure that out then another ten minutes to locate my password and login with my current account. It then took another ten minutes or so to figure out how to get the app to work. It kept telling me to contact my administrator which is me. I know other employees would never figure this out and would probably give up and go watch TV and then tell me after a couple days.

    Finally after 30 wasted minutes I can access my email and start searching online for a way to disable this which led me here. So the above technique does work but it took additional time to figure it out.

    Now I need to go in and ensure that two factor authentication is disabled across the board for all employees.

    This is not the first time I've had to deal with this type of nonsense. I've used Google G Suite in the past and while not nearly as sophisticated it just works and saves me time.

    3 people found this answer helpful.