Share via

unified Authentication method policies

Courtney Calbert - Admin 0 Reputation points
2026-02-27T19:16:59.3366667+00:00

What changes does unified Authentication method policies make, How do I find out who is still using the legacy policies, Will MFA be a forced requirement, and Will current users be forced to re-register MFA after the unified Authentication method policies migration is complete?

Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-02-27T19:17:23.0966667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Unified Authentication methods policy changes

    The unified Authentication methods policy replaces separate, legacy MFA and SSPR tenant policies with a single place to configure which methods are allowed and how they’re used for both sign-in (MFA) and self-service password reset.

    Key changes it introduces:

    • A single Authentication methods policy controls methods for both MFA and SSPR instead of separate legacy MFA/SSPR policies.
    • Methods can be targeted to users and groups through this unified policy.
    • Once migration is set to Migration Complete, legacy MFA and SSPR method settings are ignored for authentication and SSPR, and only the Authentication methods policy is enforced.
    • Security questions remain managed only in the legacy SSPR policy until a migration control is available.

    How to see who is still using legacy policies

    The migration state determines whether legacy policies are still in effect:

    • Pre-migration: Authentication methods policy is used only for authentication; legacy MFA/SSPR policies are still respected.
    • Migration in Progress: Authentication methods policy is used for authentication and SSPR; legacy MFA/SSPR policies are still respected.
    • Migration Complete: Only the Authentication methods policy is used; legacy MFA/SSPR policies are ignored (except security questions in SSPR).

    To understand whether legacy policies are still affecting users:

    1. In the Microsoft Entra admin center, go to Entra ID → Authentication methods → Policies → Manage migration and check the migration state.
    2. If the state is Pre-migration or Migration in Progress, legacy MFA/SSPR policies are still being applied alongside the Authentication methods policy.
    3. If the state is Migration Complete, users are no longer governed by legacy MFA/SSPR method settings (again, except security questions for SSPR).

    The documentation does not provide a per-user report of “who is still using legacy policies”; instead, the migration state controls whether legacy policies are honored at all.

    Whether MFA becomes a forced requirement

    The unified Authentication methods policy itself does not automatically force MFA for users. It defines which methods are available and usable for:

    • MFA sign-in
    • SSPR

    Whether MFA is actually required is still controlled by MFA-enforcing policies (for example, Conditional Access, per-user MFA, or other tenant policies). During and after migration:

    • If MFA was required before (via existing policies), it remains required; the unified policy just centralizes which methods can be used.
    • If MFA was not previously required, enabling methods in the Authentication methods policy alone does not, by itself, force MFA.

    Whether users are forced to re-register MFA after migration

    Migration to the Authentication methods policy does not inherently force users to re-register MFA.

    From the provided content:

    • The migration guide “configures the Authentication method policy based on what your organization currently has enabled in the legacy MFA and SSPR policies,” so users can continue to sign in and reset passwords using the same methods they used previously.
    • After migration is complete, legacy methods are disabled/ignored, but existing registered methods that are valid under the new Authentication methods policy remain usable.
    • Users are only forced to re-register MFA if an admin explicitly uses controls such as Require re-register multifactor authentication on a user, or if a method becomes non-usable (for example, due to expiration or policy changes).

    So, after completing migration:

    • Existing MFA registrations continue to work as long as the corresponding methods are enabled in the Authentication methods policy.
    • Users are not globally forced to re-register just because the migration state is set to Migration Complete.

    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.