Microsoft Authenticator for AD Password Reset (2024)

Authentication » Microsoft Authenticator for AD Password Reset

Configuring Microsoft Authenticator for Active Directory-based actions

Microsoft Authenticator is an authentication method, developed by Microsoft, that uses a time-based one-time-password (TOTP) to verify users identities. It is often used in combination with authentication methods for multi-factor authentication (MFA) to secure the login process of critical services.

You need Microsoft Authenticator app to authenticate using this method. While logging in once the user enters the credential, the service asks the user to validate themselves using the the 6-digit TOTP generated on the MS Authenticator app.

Using Microsoft Authenticator for AD-based authentication:

Often administrators provide Active Directory domain users with the ability to self-service password resets. With this,

  • Users need not wait for admin or help-desk intervention and can have seamless access to their machines.
  • The help-desk or admin will not be tasked with hundreds of password reset requests and can instead attend to other crucial tasks.

However, it can be risky for admins to allow this option as it might increase the security risk. Since users are often not asked the details about the old credentials, their identities must be verified in some other form before they can proceed with self-service password reset. Using an authentication method like Microsoft Authenticator is a secure way to verify a user's identity before permitting them to proceed with a password reset.

ADSelfService Plus, an Active Directory self-service password management and single sign-on solution, offers a self-service password reset option secured by MFA. The solution supports 18 authentication methods including Microsoft Authenticator, security questions and answers, TOTP, and YubiKey Authenticator to verify users' identities during:

  1. Windows, macOS, and Linux logins.
  2. Active Directory self-service password reset or account unlock actions via the ADSelfService portal, ADSelfService Plus mobile app, and native Windows/macOS/Linux login screen.
  3. Enterprise application logins through single sign-on (SSO).
  4. Self-update of Active Directory profile information, subscription to mail groups, and employee search using ADSelfService Plus.

Enabling Microsoft Authenticator for MFA can be done using minimal steps in ADSelfService Plus:

  • Navigate to Configuration → Self-Service → Multi-factor Authentication → Authenticators Setup.
  • From the Choose the Policy drop-down, select a policy.

    Note: ADSelfService Plus allows you to create OU and group-based policies. To create a policy, go to Configuration → Self-Service → Policy Configuration → Add New Policy. Click Select OUs/Groups, and make the selection based on your requirements. You need to select at least one self-service feature. Finally, click Save Policy. Only users belonging to OUs and groups included in the policy can perform the self-service feature(s) selected.

  • Click Microsoft Authenticator section.
  • Click the Enable Microsoft Authenticator button.

Microsoft Authenticator for AD Password Reset (1)

Enable Microsoft Authenticator for Active Directory password resets

  1. Go to Configuration → Self-Service → Multi-factor Authentication → MFA/TFA Settings. In the MFA for Reset/Unlock section, enter the number of authentication factors to be enforced, and select Microsoft Authenticator along with the other authentication techniques to be used.
  2. Click Save Settings.

Microsoft Authenticator for AD Password Reset (2)

Enable Microsoft Authenticator for Active Directory domain logins

  1. Go to Configuration → Self-Service → Multi-factor Authentication → MFA for Endpoints.
  2. Select a policy from the Choose the Policy drop-down. This will determine which authentication methods are enabled for which sets of users.

    Note: ADSelfService Plus allows you to create OU and group-based policies. To create a policy, go to Configuration → Self-Service → Policy Configuration → Add New Policy. Click Select OUs/Groups, and make the selection based on your requirements. You need to select at least one self-service feature. Finally, click Save Policy.

  3. In the MFA for Machine Login section, check the Enable _ authentication factors box and select the Microsoft Authenticator from the drop-down.
  4. Click Save Settings.

Microsoft Authenticator for AD Password Reset (3)

Note:

To enable MFA for Active Directory domain logins:

  • The ADSelfService Plus login agent must be installed on client machines. Click here for steps on login agent installation.
  • SSL must be enabled: Log in to the ADSelfService Plus web console with admin credentials. Navigate to the Admin tab → Product Settings → Connection. Select the ADSelfService Plus Port [https] option.

Microsoft Authenticator for AD Password Reset (4)

Learn more about ADSelfService Plus and its Multi-factor Authentication feature.

Simplify password management with ADSelfService Plus.

Get Your Free Trial

Self-service password management and single sign-on solution

ManageEngine ADSelfService Plus is an integrated self-service password management and single sign-on solution for Active Directory and cloud apps. Ensure endpoint security with stringent authentication controls including biometrics and advanced password policy controls.

  • Free Download
  • Know more
  • Related Products
    • ADManager Plus
    • ADAudit Plus Real-time Active Directory Auditing and UBA
    • EventLog Analyzer
    • AD360
    • Log360 Comprehensive SIEM and UEBA
    • AD Free Tools Active Directory FREE Tools
Microsoft Authenticator for AD Password Reset (2024)
Top Articles
Resources for Small Business Owners | Consumer Financial Protection Bureau
Futuristic Finance: AI's Seductive Power In Reshaping Private Equity
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 6223

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.