How to disable SMS authenticator for certain users?

Nick Matthews 0 Reputation points
2023-10-03T08:45:17.1666667+00:00

Is there a way to Disable SMS authentication for SPECIFIC USERS in a Tenant?

We want to force directors and other senior staff to have to use MS Authenticator whilst keeping SMS authentication as an option for other staff.

There doesn't appear to be a way to disable SMS for specific users, only for the whole tenant.

So to clarify, we don't want to disable MFA all together, we don't want to disable SMS MFA all together. We are just wanting to force MS Authenticator for some users, and have SMS and MS Authenticator available for everyone else.

Thanks,

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 20,906 Reputation points Microsoft Employee Moderator
    2023-10-04T04:31:08.6433333+00:00

    @Nick Matthews

    Thank you for posting your question in Microsoft Q&A.

    As per your requirement you want to enable authenticator app for few users and SMS for few users as MFA option.

    Yes, this is possible. You can follow below steps to configure the same,

    • Browse to https://portal.azure.com/ and login with Global admin credentials.
    • Now browse to Microsoft Entra ID.
    • Click on "Security" option on the left side.
    • Now click on "authentication methods".
    • once you click on policies you will be able to see all the MFA policies which are enabled.
    • You can Click on "Microsoft authenticator" and add all users or groups in which directors and other senior staff are members. Note: Create a group and add all the directors and other senior staff as members of this groups. You can use this group while trying to manage authentication methods.

    User's image

    • Once you save the configuration you will be redirected back to previous page.
    • Now click on SMS and add all users or groups in which directors and other senior staff are members in the exclusion list.
    • This will not allow SMS as MFA option to excluded users and groups.

    If you are using Entra portal, follow below steps to access this option,

    • Login to Entra.microsoft.com with global admin credentials.
    • Expand option “protection” and then click on “Authentication methods”.
    • You will be routed to the same page which is same as mentioned above steps.

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.