Jump to content


Knut

Enforce Number Matching MFA

Recommended Posts

Hi, I have enabled this for a few users - and it works good. However, when users change to "use login and password" for some apps, this authentication method is remembered after.

Is there a way to enforce users to always use Number Matching, meaning reverting the users mfa back from username/password?

Share this post


Link to post
Share on other sites

was this question related to Windows 365 or Azure AD ?

number matching will be the default method come february 2023, so how can users choose something else ?

Can I opt out of number matching?

Yes, currently you can disable number matching. We highly recommend that you enable number matching for all users in your tenant to protect yourself from MFA fatigue attacks. Microsoft will enable number matching for all tenants by Feb 27, 2023. After protection is enabled by default, users can't opt out of number matching in Microsoft Authenticator push notifications.

Share this post


Link to post
Share on other sites

11 hours ago, anyweb said:

was this question related to Windows 365 or Azure AD ?

number matching will be the default method come february 2023, so how can users choose something else ?

Can I opt out of number matching?

Yes, currently you can disable number matching. We highly recommend that you enable number matching for all users in your tenant to protect yourself from MFA fatigue attacks. Microsoft will enable number matching for all tenants by Feb 27, 2023. After protection is enabled by default, users can't opt out of number matching in Microsoft Authenticator push notifications.

I know this will be the default method, but when users change the logon-option to username and password, it won't go back to Number Matching as default. The user have to manually change this back to Number Matching, and this can cause confusion. 

Share this post


Link to post
Share on other sites

i'm not sure which app you mean, but perhaps you mean this ? https://aka.ms/mfasetup

 

and in there the USER can change to whatever default method they want, this is a user setting and we cannot enforce it (that I am aware of)

  • Like 1

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.