Authentication methods and features - Microsoft Entra ID (2024)

  • Article

Microsoft recommends passwordless authentication methods such as Windows Hello, Passkeys (FIDO2), and the Microsoft Authenticator app because they provide the most secure sign-in experience. Although a user can sign-in using other common methods such as a username and password, passwords should be replaced with more secure authentication methods.

Authentication methods and features - Microsoft Entra ID (1)

Microsoft Entra multifactor authentication adds additional security over only using a password when a user signs in. The user can be prompted for additional forms of authentication, such as to respond to a push notification, enter a code from a software or hardware token, or respond to a text message or phone call.

To simplify the user on-boarding experience and register for both MFA and self-service password reset (SSPR), we recommend you enable combined security information registration. For resiliency, we recommend that you require users to register multiple authentication methods. When one method isn't available for a user during sign-in or SSPR, they can choose to authenticate with another method. For more information, see Create a resilient access control management strategy in Microsoft Entra ID.

How each authentication method works

Some authentication methods can be used as the primary factor when you sign in to an application or device, such as using a FIDO2 security key or a password. Other authentication methods are only available as a secondary factor when you use Microsoft Entra multifactor authentication or SSPR.

The following table outlines when an authentication method can be used during a sign-in event:

MethodPrimary authenticationSecondary authentication
Windows Hello for BusinessYesMFA*
Microsoft Authenticator pushNoMFA and SSPR
Microsoft Authenticator passwordlessYesNo*
Microsoft Authenticator passkey (preview)YesMFA and SSPR
Authenticator LiteNoMFA
Passkey (FIDO2)YesMFA
Certificate-based authenticationYesMFA
OATH hardware tokens (preview)NoMFA and SSPR
OATH software tokensNoMFA and SSPR
External authentication methods (preview)NoMFA
Temporary Access Pass (TAP)YesMFA
SMSYesMFA and SSPR
Voice callNoMFA and SSPR
PasswordYesNo

* Windows Hello for Business, by itself, does not serve as a step-up MFA credential. For example, an MFA Challenge from Sign-in Frequency or SAML Request containing forceAuthn=true. Windows Hello for Business can serve as a step-up MFA credential by being used in FIDO2 authentication. This requires users to be registered for FIDO2 authentication to work successfully.

* Passwordless sign-in can be used for secondary authentication only if certificate-based authentication (CBA) is used for primary authentication. For more information, see Microsoft Entra certificate-based authentication technical deep dive.

All of these authentication methods can be configured in the Microsoft Entra admin center, and increasingly using the Microsoft Graph REST API.

To learn more about how each authentication method works, see the following separate conceptual articles:

  • Windows Hello for Business
  • Microsoft Authenticator app
  • Authenticator Lite
  • Passkey (FIDO2)
  • Certificate-based authentication
  • OATH hardware tokens (preview)
  • OATH software tokens
  • External authentication methods (preview)
  • Temporary Access Pass (TAP)
  • SMS sign-in and verification
  • Voice call verification
  • Password

Note

In Microsoft Entra ID, a password is often one of the primary authentication methods. You can't disable the password authentication method. If you use a password as the primary authentication factor, increase the security of sign-in events using Microsoft Entra multifactor authentication.

The following additional verification methods can be used in certain scenarios:

  • App passwords - used for old applications that don't support modern authentication and can be configured for per-user Microsoft Entra multifactor authentication.
  • Security questions - only used for SSPR
  • Email address - only used for SSPR

Usable and non-usable methods

Administrators can view user authentication methods in the Microsoft Entra admin center. Usable methods are listed first, followed by non-usable methods.

Each authentication method can become non-usable for different reasons. For example, a Temporary Access Pass may expire, or FIDO2 security key may fail attestation. The portal will be updated to provide the reason for why the method is non-usable.

Authentication methods that are no longer available due to "Require re-register multifactor authentication" are also displayed here.

Authentication methods and features - Microsoft Entra ID (2)

Next steps

To get started, see the tutorial for self-service password reset (SSPR) and Microsoft Entra multifactor authentication.

To learn more about SSPR concepts, see How Microsoft Entra self-service password reset works.

To learn more about MFA concepts, see How Microsoft Entra multifactor authentication works.

Learn more about configuring authentication methods using the Microsoft Graph REST API.

To review what authentication methods are in use, see Microsoft Entra multifactor authentication authentication method analysis with PowerShell.

Authentication methods and features - Microsoft Entra ID (2024)
Top Articles
PM says targets of $25b IT exports, $20b funding one thing doable
6 Small Ways You Can Save Money - International Bloggers’ Association
Woodward Avenue (M-1) - Automotive Heritage Trail - National Scenic Byway Foundation
Walgreens Boots Alliance, Inc. (WBA) Stock Price, News, Quote & History - Yahoo Finance
Wordscapes Level 6030
Live Basketball Scores Flashscore
Craigslist Cars Augusta Ga
Klustron 9
10000 Divided By 5
Big Y Digital Coupon App
Vocabulario A Level 2 Pp 36 40 Answers Key
Cvs Appointment For Booster Shot
Panorama Charter Portal
Walmart Double Point Days 2022
Sam's Club La Habra Gas Prices
"Une héroïne" : les funérailles de Rebecca Cheptegei, athlète olympique immolée par son compagnon | TF1 INFO
Spider-Man: Across The Spider-Verse Showtimes Near Marcus Bay Park Cinema
Rondom Ajax: ME grijpt in tijdens protest Ajax-fans bij hoofdbureau politie
Vintage Stock Edmond Ok
Wbiw Weather Watchers
Violent Night Showtimes Near Century 14 Vallejo
Ivegore Machete Mutolation
yuba-sutter apartments / housing for rent - craigslist
Xfinity Cup Race Today
BJ 이름 찾는다 꼭 도와줘라 | 짤방 | 일베저장소
Sofia the baddie dog
Rubmaps H
O'reilly's Wrens Georgia
Xfinity Outage Map Lacey Wa
Gideon Nicole Riddley Read Online Free
Gyeon Jahee
Beth Moore 2023
Unlock The Secrets Of "Skip The Game" Greensboro North Carolina
Whitehall Preparatory And Fitness Academy Calendar
Wisconsin Women's Volleyball Team Leaked Pictures
Let's co-sleep on it: How I became the mom I swore I'd never be
Restored Republic June 6 2023
Discover Things To Do In Lubbock
Torrid Rn Number Lookup
Greg Steube Height
Large Pawn Shops Near Me
Jigidi Free Jigsaw
Greatpeople.me Login Schedule
News & Events | Pi Recordings
18 Seriously Good Camping Meals (healthy, easy, minimal prep! )
Craigslist Indpls Free
Estes4Me Payroll
OSF OnCall Urgent Care treats minor illnesses and injuries
Emmi-Sellers
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 6087

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.