Thank you for posting your question in Microsoft Q&A.
As per your requirement you want to enable authenticator app for few users and SMS for few users as MFA option.
Yes, this is possible. You can follow below steps to configure the same,
- Browse to https://portal.azure.com/ and login with Global admin credentials.
- Now browse to Microsoft Entra ID.
- Click on "Security" option on the left side.
- Now click on "authentication methods".
- once you click on policies you will be able to see all the MFA policies which are enabled.
- You can Click on "Microsoft authenticator" and add all users or groups in which directors and other senior staff are members. Note: Create a group and add all the directors and other senior staff as members of this groups. You can use this group while trying to manage authentication methods.
- Once you save the configuration you will be redirected back to previous page.
- Now click on SMS and add all users or groups in which directors and other senior staff are members in the exclusion list.
- This will not allow SMS as MFA option to excluded users and groups.
If you are using Entra portal, follow below steps to access this option,
- Login to Entra.microsoft.com with global admin credentials.
- Expand option “protection” and then click on “Authentication methods”.
- You will be routed to the same page which is same as mentioned above steps.
Let me know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.