Disabling mandatory MS Authenticator app

Anonymous
2023-09-12T11:08:43+00:00

Good afternoon,

We have text and call authentication set up as multi factor authentication for our users.

This has worked very well up until recently, when Microsoft have started to force the option of the authenticator app on users, and made it unskippable despite our setup.

The option to skip is not present on the "improve your sign ins" screen.

Where is the setting to disable the forcing of the authenticator app for the user?

I have seen on other posts there are options to disable this. For example here: https://learn.microsoft.com/en-us/answers/questions/1338546/users-are-being-forced-to-use-microsoft-authentica

If, as in the screenshot in the "accepted answer" post we change the registration campaign status to disabled, does this remove the enforced app prompt?

At present it is currently set to "Microsoft managed".

We are fine with the app as an OPTION however it should not be mandatory as it does exclude people who do not have the latest phones, or indeed, any smart phone.

Chris

Microsoft 365 and Office | Subscription, account, billing | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Most helpful
  1. Anonymous
    2023-11-23T00:14:10+00:00

    MS is so concerned and obsessed with security that it is almost impossible to login to any website using a windows device with a Chrome instead of a windows browser. Two step verification prevents me from accessing almost any website. I have been a windowd OS user since the 80s Thinking of changing to Mac.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-10-16T15:50:34+00:00

    It Seems that its very hard for Microsoft to understand the question at hand.

    Let me simplify.

    1: The Administrator DOES want to enforce MFA

    BUT does not want to enforce Microsoft Authenticator.

    Having MFA is important, but Microsoft deciding that all users should use Microsoft Auth as the standard is not correct.

    Extra: how to exclude specific users from MFA in Microsoft 365?

    What I was able to find: How to migrate to the Authentication methods policy - Microsoft Entra | Microsoft Learn

    I was able to "uncheck" the Notification through mobile app and the Verification code from mobile app or hardware token. Hopefully this works.

    Note: this is for ALL Users (not specific).

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-05-17T16:48:33+00:00

    Disable Authentication app for select users

    1) In Microsoft Entra, (https://entra.microsoft.com/) open the "Protection" tab in the left menu.

    2) Select "Authentication methods."

    3) Go to "Registration campaign."

    4) If the campaign is set to "Microsoft managed," click "Edit." 

    5) Now click "Add users and groups" to select who to exclude.

    1. Save

    Had to call Microsoft support for help and this is what worked.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-11-16T06:49:01+00:00

    Thank you ADynes.

    No thanks to you Microsoft!

    This is the solution that actually works to eliminate the forced use of Microsoft Authenticator app.
    What a pain.

    Per Joseph Happe's reply from October 20th 2023, you can enable the methods you want for MFA and life is back to normal.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2023-11-01T14:27:43+00:00

    So if you disable the enrollment and use of Microsofts authenticator you do need to make sure others are enabled which I mentioned. So at https://entra.microsoft.com/ go to Protection -> Authentication Methods -> Polices: Turn ON the ones you want to use for all users. So "SMS" is text codes (which is going away next year fyi). "Third-party software OATH tokens" is things like Google Authenticator. Click each one you want, click Enable, then click All Users and save.

    I personally am using Google Authenticator because it backs up my codes to Google and if my phone dies I can replace it and get all my codes back easily. And my phone is through work so what if I get let go and they keep my number? At least with Google I will be able to get back into all my accounts. SMS is a dying option.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments