robintech Posted September 15, 2023 Posted September 15, 2023 https://learn.microsoft.com/en-gb/azure/active-directory/authentication/how-to-mfa-registration-campaign You’re receiving this email because you have a Microsoft Entra ID tenant. On September 15, 2023, we’ll begin prompting your users who authenticate using SMS and voice methods to set up the Microsoft Authenticator app when they sign in to their work or school account. This change will take place on a rolling basis over six weeks as part of ongoing efforts to improve security...... ..You can also define how many days a user can postpone, or "snooze," the nudge. If a user taps Not now to postpone the app setup, they get nudged again on the next MFA attempt after the snooze duration has elapsed. Users with free and trial subscriptions can postpone the app setup up to three times. Without judgement what are people doing with this?, I've set it the nudge/enforce to disabled until I can filter who is using Voice/SMS and make them aware of the changes and see if they can use tokens or another method if they don't have a work phone and don't want to install an App. Especially on a Friday
snagrat Posted September 15, 2023 Posted September 15, 2023 I’ve disabled the Microsoft Managed campaign so we can still use SMS until, like you, we can put some proper comms out to people. How does it work with people who do not have smart phones…..?
StevieM Posted September 15, 2023 Posted September 15, 2023 (edited) Great! Send this out the night before it goes live. Thank you SO much, Micros**t. Ironically, after finally getting my recommendation that governors are compelled to use school email address accepted, and issuing detailed instructions for setting up MFA by SMS (the path of least resistance), the option is being withdrawn at ridiculously short notice. I’ve disabled the Microsoft Managed campaign so we can still use SMS until, like you, we can put some proper comms out to people. How do you do this? That would be really helpful. How does it work with people who do not have smart phones…..? That's my question. At least the teachers and I have a school iPad, to which I've already deployed MS Authenticator, but support staff don't. (Ironically, I'm probably the only member of staff who doesn't use a smartphone.) EDIT: Found it. Protection - Authentication methods - Registration campaign. Edited September 15, 2023 by StevieM 1
midweek Posted September 15, 2023 Posted September 15, 2023 I turned the SMS & voice option off (by accident!) when migrating to Azure MFA a while back. Some people where not happy!
TRSJon Posted September 15, 2023 Posted September 15, 2023 I found this link - Get MFA Status with PowerShell (Script Included) (activedirectorypro.com) . This allows the creation of a spreadsheet showing who has MFA enabled (or not) and also what FMA methods they have, so can refine it to those that have MFA, but not APP - and contact them directly. 2
StevieM Posted September 15, 2023 Posted September 15, 2023 Log in to Entra, go to Identity Authentication methods - User registration details and you can also download the information from there.
3s-gtech Posted September 15, 2023 Posted September 15, 2023 How do you do this? That would be really helpful. Entra Admin Centre. Protection Authentication methods Registration campaign Disable I'm not sure how effective this will be at stopping them from turning off SMS, which simply isn't an option yet. My experience with Authenticator is awful - it just doesn't work in iPhone.
mavhc Posted September 15, 2023 Posted September 15, 2023 What doesn't work about it, obviously millions of people are using it fine on iOS
3s-gtech Posted September 15, 2023 Posted September 15, 2023 What doesn't work about it, obviously millions of people are using it fine on iOS So I sign in on the phone browser, get a notification at the top from Microsoft Authenticator, approve it, and absolutely nothing happens in the browser. Sometimes works if I try multiple times.
enjay Posted September 15, 2023 Posted September 15, 2023 We've delayed the change until we can communicate the change to staff, and implement it at a friendlier time than week 2 of term.
enjay Posted September 15, 2023 Posted September 15, 2023 Great! Send this out the night before it goes live. Thank you SO much, Micros**t. I received the below on 21st July: Changes to the registration campaign feature in Microsoft Entra (previously Azure Active Directory) MC650420 · Publicly switched telephone networks (PSTN) such as SMS and voice authentication are the weakest forms of MFA. To help your users move away from these less secure MFA methods we are introducing changes to the Microsoft managed state of the registration campaign (aka Nudge) feature in Microsoft Entra (previously Azure Active Directory). When this will happen: Starting September 2023 How this affects your organization: Users in your organization who are relying on PSTN (SMS and/or voice) for MFA will be prompted to use the Microsoft Authenticator app. Users can skip this prompt for a maximum of 3 times, after which registration of the app will be required by default. Note: admins can decide it they want to opt out of the “limited” 3 snooze configuration or give their end users the ability to snooze indefinitely. What you can do to prepare: We urge you to motivate your users to immediately stop using SMS and voice for MFA. You can take advantage of several new admin levers to achieve this such as system-preferred MFA and Microsoft Authenticator Lite, in addition to registration campaign. However, if some of your users require more time you can exempt them for now. Sign in as Global Administrator or Authentication Policy Administrator and go to Microsoft Entra > Identity > Protection > Authentication methods > Registration campaign and exclude these user groups. 1
aac Posted September 15, 2023 Posted September 15, 2023 This my be a stupid question or perhaps I have no read the email correctly but having disabled the campaign in Entra admin center are we saying it will still force this upon everyone after 6 weeks regardless we set it to disabled?
mavhc Posted September 15, 2023 Posted September 15, 2023 So I sign in on the phone browser, get a notification at the top from Microsoft Authenticator, approve it, and absolutely nothing happens in the browser. Sometimes works if I try multiple times. I've found some people have to register their phone device before it works 1
StevieM Posted September 15, 2023 Posted September 15, 2023 Thanks, @enjay. I may or may not have had that email on 21st July. The problem is, Microsoft send so many Major Update Notifications (the majority of which have no impact on us) that they tend to get quickly scanned and deleted. The fact that the title was 'Changes to the registration campaign feature in Microsoft Entra' (What's that when it's at home? ) would definitely have put it in the 'Nah' category. Yesterday's email headed 'We’re enabling a stronger form of multifactor authentication beginning September 15, 2023' was at least a bit more obvious. 2
gaz350b Posted September 15, 2023 Posted September 15, 2023 (edited) Entra Admin Centre. Protection Authentication methods Registration campaign Disable I'm not sure how effective this will be at stopping them from turning off SMS, which simply isn't an option yet. My experience with Authenticator is awful - it just doesn't work in iPhone. I was shocked how bad the experience was for non iPhone users who very rarely have things like touchID or Face ID. Although to be fair the people that have problems on both platforms have turned off too many notifications. Edited September 15, 2023 by gaz350b
jmak Posted September 16, 2023 Posted September 16, 2023 I was shocked how bad the experience was for non iPhone users who very rarely have things like touchID or Face ID. Although to be fair the people that have problems on both platforms have turned off too many notifications.It's fine on Android - I haven't seen an Android phone without fingerprint authentication for years and most of them have face id too - I believe the Apple implementation is more secure than most, but the unlock function works fine.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now