Can conditional access policy be used to limit the MFA method available to a target domain?

Mark P 0 Reputation points
2024-10-25T15:14:44.64+00:00

The customer wants to allow the MFA options for one guest domain so they use SMS and Microsoft Authenticator. The rest of the users in the tenant will have access to ONLY Microsoft Authenticator.

Is this level of control possible with a conditional access policy?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Akhilesh Vallamkonda 15,340 Reputation points Moderator
    2024-10-25T21:01:11.16+00:00

    Hi @Mark P

    Thank you for reaching Microsoft Q&A Forum!

    I understand that you would like to limit the MFA method for set of users.

    You can achieve this by configuring the Authentication methods policy in your tenant. Administrators can specifically configure each method to meet their goals for user experience and security.

    For more information, please read Manage authentication methods for Microsoft Entra ID

    Hope this helps. Do let us know if you any further queries by responding in the comments section.

    Thanks,

    Akhilesh.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.