Default MFA Auth Providers Wizard

Philipp Kretschmer 80 Reputation points
2023-10-24T11:22:03.2466667+00:00

In my company, we want to introduce MFA.

The requirements are:

  1. Being able to chose (only) between an Authenticator App and a Hardware Token when setting up the MFA (Wizard)
  2. Being able to set up an App Password afterwards, however not being forced to do so while initially setting up the MFA

I enabled the policies that I want, however it doesn't seem to effect the process of setting up the MFA:Authentication Policies

In the following picture I have used an account where I enforced the MFA. As you can see, the only two options available are the Authenticator App and Phone. How can I get the other options to appear (e.g. the Hardware Token)? User's image

After that I am always forced in a second step to create an App password. Is it possible to skip this part, while still being able to create an App password afterwards? User's image

Thanks

Philipp

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
8,670 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,276 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 155.4K Reputation points MVP
    2023-10-24T12:03:15.81+00:00

    Why are you using app passwords? Thats a legacy thing and do not work with modern auth methods.

    https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-app-passwords

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.