question

akseltorgard avatar image
0 Votes"
akseltorgard asked LibbyBrown commented

MFA with Microsoft 365 Business Basic subscription

Hello,

I am trying to set up multi-factor authentication for our organization.

We do not have access to the MFA dashboard on Azure AD, as our license does not include this. Neither do we have access to Conditional Access policies.

What MFA methods are available to us?

Specifically, I would like to use either FIDO2 security keys (e.g. YubiKeys) or OATH (e.g. time-based one-time-passwords through an authenticator app). Is this possible?

Thanks,
Aksel

azure-active-directoryazure-ad-multi-factor-authentication
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

vipulsparsh-MSFT avatar image
0 Votes"
vipulsparsh-MSFT answered LibbyBrown commented

@akseltorgard FIDO 2 needs combined user experience to be enabled as pre-requisite which is a premium feature.
hardware OATH tokens also need either Azure AD P1 or P2. You would need to upgrade license in order to use them.

· 5
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thank you for clarifying.

What MFA methods are available, if we enable Security Defaults?

0 Votes 0 ·

@akseltorgard Security default will work with Authenticator App only.
All users in your tenant must register for multi-factor authentication (MFA) in the form of the Azure AD Multi-Factor Authentication. A user's 14-day period begins after their first successful interactive sign-in after enabling security defaults.
Users have 14 days to register for Azure AD Multi-Factor Authentication by using the Microsoft Authenticator app.
After the 14 days have passed, the user won't be able to sign in until registration is completed.

0 Votes 0 ·

Just to clarify, when you say Authenticator App only, what do you mean?

Is it any OATH app (e.g. Microsoft Authenticator, Google Authenticator, Yubico Authenticator), or is it Microsoft Authenticator only?

And if it is Microsoft Authenticator, what types of MFA are supported within it with Security Defaults?

0 Votes 0 ·
Show more comments