I don't want Phone and App password as second factor when registering MFA

Alex Wilber 0 Reputation points
2024-02-25T15:26:10.31+00:00

I don't want my current users and the new created users setting up the Phone and App password as the second factor when registering for MFA.

I want the method 1 is app and method 2 is Email

Screenshot 2024-02-25 at 21.14.16

What I have done:

  • service settings > verification options: select Notification through mobile app / Verification code from mobile app or hardware token
  • security > authentication methods: enable all, but not SMS method
  • password reset >
    • registration: select No
    • authentication methods: select Mobile app code / Email

Can anyone please help me what I am missing here? Thank you so much.

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
8,384 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,728 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Navya 16,455 Reputation points Microsoft External Staff
    2024-02-26T11:33:10.3466667+00:00

    Hi @Alex Wilber

    Thank you for posting this in Microsoft Q&A.

    I understand your concern that you don't want Phone and App password as second factor when registering MFA and want the method 1 is app and method 2 is Email.

    You can use Authenticator App is for two factor authentication and password reset authentication. The email method is not suitable for two-factor authentication, only password reset is supported.

    User's image

    If you are using Legacy MFA follow below steps:

    Security > Multifactor authentication > Additional cloud-based multifactor authentication settings > Verification options > Select Notification through mobile app and another option.

    Password reset:

    1.Need to select users for SSPR.

    Protection > Password reset > Properties page, under the option Self-service password reset enabled, choose users according to your requirement.

    2.Select authentication methods.

    Password reset > Authentication methods > select two methods i.e. app and email.

    For your reference: self-service password reset

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.