Authentication methods and features - Microsoft Entra ID (2024)

  • Article

Microsoft recommends passwordless authentication methods such as Windows Hello, Passkeys (FIDO2), and the Microsoft Authenticator app because they provide the most secure sign-in experience. Although a user can sign-in using other common methods such as a username and password, passwords should be replaced with more secure authentication methods.

Authentication methods and features - Microsoft Entra ID (1)

Microsoft Entra multifactor authentication adds additional security over only using a password when a user signs in. The user can be prompted for additional forms of authentication, such as to respond to a push notification, enter a code from a software or hardware token, or respond to a text message or phone call.

To simplify the user on-boarding experience and register for both MFA and self-service password reset (SSPR), we recommend you enable combined security information registration. For resiliency, we recommend that you require users to register multiple authentication methods. When one method isn't available for a user during sign-in or SSPR, they can choose to authenticate with another method. For more information, see Create a resilient access control management strategy in Microsoft Entra ID.

How each authentication method works

Some authentication methods can be used as the primary factor when you sign in to an application or device, such as using a FIDO2 security key or a password. Other authentication methods are only available as a secondary factor when you use Microsoft Entra multifactor authentication or SSPR.

The following table outlines when an authentication method can be used during a sign-in event:

MethodPrimary authenticationSecondary authentication
Windows Hello for BusinessYesMFA*
Microsoft Authenticator pushNoMFA and SSPR
Microsoft Authenticator passwordlessYesNo*
Microsoft Authenticator passkey (preview)YesMFA and SSPR
Authenticator LiteNoMFA
Passkey (FIDO2)YesMFA
Certificate-based authenticationYesMFA
OATH hardware tokens (preview)NoMFA and SSPR
OATH software tokensNoMFA and SSPR
External authentication methods (preview)NoMFA
Temporary Access Pass (TAP)YesMFA
SMSYesMFA and SSPR
Voice callNoMFA and SSPR
PasswordYesNo

* Windows Hello for Business, by itself, does not serve as a step-up MFA credential. For example, an MFA Challenge from Sign-in Frequency or SAML Request containing forceAuthn=true. Windows Hello for Business can serve as a step-up MFA credential by being used in FIDO2 authentication. This requires users to be registered for FIDO2 authentication to work successfully.

* Passwordless sign-in can be used for secondary authentication only if certificate-based authentication (CBA) is used for primary authentication. For more information, see Microsoft Entra certificate-based authentication technical deep dive.

All of these authentication methods can be configured in the Microsoft Entra admin center, and increasingly using the Microsoft Graph REST API.

To learn more about how each authentication method works, see the following separate conceptual articles:

  • Windows Hello for Business
  • Microsoft Authenticator app
  • Authenticator Lite
  • Passkey (FIDO2)
  • Certificate-based authentication
  • OATH hardware tokens (preview)
  • OATH software tokens
  • External authentication methods (preview)
  • Temporary Access Pass (TAP)
  • SMS sign-in and verification
  • Voice call verification
  • Password

Note

In Microsoft Entra ID, a password is often one of the primary authentication methods. You can't disable the password authentication method. If you use a password as the primary authentication factor, increase the security of sign-in events using Microsoft Entra multifactor authentication.

The following additional verification methods can be used in certain scenarios:

  • App passwords - used for old applications that don't support modern authentication and can be configured for per-user Microsoft Entra multifactor authentication.
  • Security questions - only used for SSPR
  • Email address - only used for SSPR

Usable and non-usable methods

Administrators can view user authentication methods in the Microsoft Entra admin center. Usable methods are listed first, followed by non-usable methods.

Each authentication method can become non-usable for different reasons. For example, a Temporary Access Pass may expire, or FIDO2 security key may fail attestation. The portal will be updated to provide the reason for why the method is non-usable.

Authentication methods that are no longer available due to "Require re-register multifactor authentication" are also displayed here.

Authentication methods and features - Microsoft Entra ID (2)

Next steps

To get started, see the tutorial for self-service password reset (SSPR) and Microsoft Entra multifactor authentication.

To learn more about SSPR concepts, see How Microsoft Entra self-service password reset works.

To learn more about MFA concepts, see How Microsoft Entra multifactor authentication works.

Learn more about configuring authentication methods using the Microsoft Graph REST API.

To review what authentication methods are in use, see Microsoft Entra multifactor authentication authentication method analysis with PowerShell.

Authentication methods and features - Microsoft Entra ID (2024)
Top Articles
How Not to Pay Taxes: Four Legal Ways to Not Pay US Income Tax
B&Q is the cheapest place to buy a kitchen for the third year running
Swimgs Yuzzle Wuzzle Yups Wits Sadie Plant Tune 3 Tabs Winnie The Pooh Halloween Bob The Builder Christmas Autumns Cow Dog Pig Tim Cook’s Birthday Buff Work It Out Wombats Pineview Playtime Chronicles Day Of The Dead The Alpha Baa Baa Twinkle
Chambersburg star athlete JJ Kelly makes his college decision, and he’s going DI
Crossed Eyes (Strabismus): Symptoms, Causes, and Diagnosis
Craigslist Free Stuff Appleton Wisconsin
EY – все про компанію - Happy Monday
Sunday World Northern Ireland
Moe Gangat Age
Housing Intranet Unt
LeBron James comes out on fire, scores first 16 points for Cavaliers in Game 2 vs. Pacers
Maxpreps Field Hockey
Washington, D.C. - Capital, Founding, Monumental
Craigslist Edmond Oklahoma
Suffix With Pent Crossword Clue
Aberration Surface Entrances
Kürtçe Doğum Günü Sözleri
Craigslist In Visalia California
Nearest Walgreens Or Cvs Near Me
Tu Pulga Online Utah
What Time Does Walmart Auto Center Open
UMvC3 OTT: Welcome to 2013!
Jcp Meevo Com
Gilchrist Verband - Lumedis - Ihre Schulterspezialisten
Beaufort 72 Hour
Kirk Franklin Mother Debra Jones Age
Weathervane Broken Monorail
Keyn Car Shows
Ticket To Paradise Showtimes Near Cinemark Mall Del Norte
13301 South Orange Blossom Trail
Gma' Deals & Steals Today
Biografie - Geertjan Lassche
Rural King Credit Card Minimum Credit Score
The Clapping Song Lyrics by Belle Stars
What does wym mean?
3 Bedroom 1 Bath House For Sale
Whitehall Preparatory And Fitness Academy Calendar
Latest Nigerian Music (Next 2020)
Dollar Tree's 1,000 store closure tells the perils of poor acquisitions
Captain Billy's Whiz Bang, Vol 1, No. 11, August, 1920
America's Magazine of Wit, Humor and Filosophy
Noaa Marine Weather Forecast By Zone
Verizon Outage Cuyahoga Falls Ohio
Craigs List Hartford
All-New Webkinz FAQ | WKN: Webkinz Newz
Dragon Ball Super Super Hero 123Movies
Lucifer Morningstar Wiki
Coffee County Tag Office Douglas Ga
Jeep Forum Cj
Joe Bartosik Ms
4015 Ballinger Rd Martinsville In 46151
Scholar Dollar Nmsu
Ranking 134 college football teams after Week 1, from Georgia to Temple
Latest Posts
Article information

Author: Jerrold Considine

Last Updated:

Views: 6033

Rating: 4.8 / 5 (58 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Jerrold Considine

Birthday: 1993-11-03

Address: Suite 447 3463 Marybelle Circles, New Marlin, AL 20765

Phone: +5816749283868

Job: Sales Executive

Hobby: Air sports, Sand art, Electronics, LARPing, Baseball, Book restoration, Puzzles

Introduction: My name is Jerrold Considine, I am a combative, cheerful, encouraging, happy, enthusiastic, funny, kind person who loves writing and wants to share my knowledge and understanding with you.