Enable Authenticator app

Aran Billen 956 Reputation points
2023-12-13T12:46:53.49+00:00

Hi all,

If I set this policy to enable and set to all users will they require signing up to Authenticator app even though they have no policy to state that MFA is enabled?

Screenshot 2023-12-13 at 12.43.59

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Answer accepted by question author
  1. Domooney-MSFT 2,606 Reputation points Microsoft Employee Moderator
    2023-12-13T13:35:32.9433333+00:00

    Hi @Aran Billen

    Thank you for posting your query on Microsoft Q&A!

    The answer is No, the configuration you shared will allow users to use the Microsoft Authenticator app if they are prompted to setup MFA. But if you do not have anything configured to require MFA then they will not be prompted. So you would need to also configure a Conditional Access policy, or enable Security Defaults before users will get prompted.

    If you have a license which includes Identity Protection you can configure a "Registration Policy" which will prompt users to setup MFA without any Conditional Access or MFA enforcement, this also can allow users to temporarily skip registration - https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-mfa-policy

    We have a guide here on planning for MFA registration - https://learn.microsoft.com/en-gb/entra/identity/authentication/howto-mfa-getstarted#plan-user-registration

    Let me know if you have any further queries.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.