Jump to content

Microsoft Enta/Azure nudge/enforce Authenticator App beginning September 15,


Recommended Posts

Posted

https://learn.microsoft.com/en-gb/azure/active-directory/authentication/how-to-mfa-registration-campaign

 

You’re receiving this email because you have a Microsoft Entra ID tenant.

 

 

On September 15, 2023, we’ll begin prompting your users who authenticate using SMS and voice methods to set up the Microsoft Authenticator app when they sign in to their work or school account. This change will take place on a rolling basis over six weeks as part of ongoing efforts to improve security......

..You can also define how many days a user can postpone, or "snooze," the nudge. If a user taps Not now to postpone the app setup, they get nudged again on the next MFA attempt after the snooze duration has elapsed. Users with free and trial subscriptions can postpone the app setup up to three times.

 

Without judgement what are people doing with this?, I've set it the nudge/enforce to disabled until I can filter who is using Voice/SMS and make them aware of the changes and see if they can use tokens or another method if they don't have a work phone and don't want to install an App. Especially on a Friday

Posted

I’ve disabled the Microsoft Managed campaign so we can still use SMS until, like you, we can put some proper comms out to people.

 

How does it work with people who do not have smart phones…..?

Posted (edited)

Great! Send this out the night before it goes live. Thank you SO much, Micros**t.

 

Ironically, after finally getting my recommendation that governors are compelled to use school email address accepted, and issuing detailed instructions for setting up MFA by SMS (the path of least resistance), the option is being withdrawn at ridiculously short notice.

 

I’ve disabled the Microsoft Managed campaign so we can still use SMS until, like you, we can put some proper comms out to people.

How do you do this? That would be really helpful.

How does it work with people who do not have smart phones…..?

That's my question. At least the teachers and I have a school iPad, to which I've already deployed MS Authenticator, but support staff don't. (Ironically, I'm probably the only member of staff who doesn't use a smartphone.)

 

EDIT: Found it. Protection - Authentication methods - Registration campaign.

Edited by StevieM
  • Thanks 1
Posted

How do you do this? That would be really helpful.

 

Entra Admin Centre.

Protection

Authentication methods

Registration campaign

Disable

 

I'm not sure how effective this will be at stopping them from turning off SMS, which simply isn't an option yet. My experience with Authenticator is awful - it just doesn't work in iPhone.

Posted
What doesn't work about it, obviously millions of people are using it fine on iOS

So I sign in on the phone browser, get a notification at the top from Microsoft Authenticator, approve it, and absolutely nothing happens in the browser. Sometimes works if I try multiple times.

Posted
Great! Send this out the night before it goes live. Thank you SO much, Micros**t.

 

I received the below on 21st July:

 

Changes to the registration campaign feature in Microsoft Entra (previously Azure Active Directory)

MC650420 ·

Publicly switched telephone networks (PSTN) such as SMS and voice authentication are the weakest forms of MFA. To help your users move away from these less secure MFA methods we are introducing changes to the Microsoft managed state of the registration campaign (aka Nudge) feature in Microsoft Entra (previously Azure Active Directory).

When this will happen:

Starting September 2023

How this affects your organization:

Users in your organization who are relying on PSTN (SMS and/or voice) for MFA will be prompted to use the Microsoft Authenticator app. Users can skip this prompt for a maximum of 3 times, after which registration of the app will be required by default. Note: admins can decide it they want to opt out of the “limited” 3 snooze configuration or give their end users the ability to snooze indefinitely.

What you can do to prepare:

We urge you to motivate your users to immediately stop using SMS and voice for MFA. You can take advantage of several new admin levers to achieve this such as system-preferred MFA and Microsoft Authenticator Lite, in addition to registration campaign. However, if some of your users require more time you can exempt them for now. Sign in as Global Administrator or Authentication Policy Administrator and go to Microsoft Entra > Identity > Protection > Authentication methods > Registration campaign and exclude these user groups.

  • Thanks 1
Posted
This my be a stupid question or perhaps I have no read the email correctly but having disabled the campaign in Entra admin center are we saying it will still force this upon everyone after 6 weeks regardless we set it to disabled?
Posted
So I sign in on the phone browser, get a notification at the top from Microsoft Authenticator, approve it, and absolutely nothing happens in the browser. Sometimes works if I try multiple times.

 

I've found some people have to register their phone device before it works

  • Thanks 1
Posted

Thanks, @enjay.

 

I may or may not have had that email on 21st July. The problem is, Microsoft send so many Major Update Notifications (the majority of which have no impact on us) that they tend to get quickly scanned and deleted. The fact that the title was 'Changes to the registration campaign feature in Microsoft Entra' (What's that when it's at home? :confused:) would definitely have put it in the 'Nah' category.

 

Yesterday's email headed 'We’re enabling a stronger form of multifactor authentication beginning September 15, 2023' was at least a bit more obvious.

  • Thanks 2
Posted (edited)
Entra Admin Centre.

Protection

Authentication methods

Registration campaign

Disable

 

I'm not sure how effective this will be at stopping them from turning off SMS, which simply isn't an option yet. My experience with Authenticator is awful - it just doesn't work in iPhone.

 

I was shocked how bad the experience was for non iPhone users who very rarely have things like touchID or Face ID.

 

Although to be fair the people that have problems on both platforms have turned off too many notifications.

Edited by gaz350b
Posted
I was shocked how bad the experience was for non iPhone users who very rarely have things like touchID or Face ID.

 

Although to be fair the people that have problems on both platforms have turned off too many notifications.

It's fine on Android - I haven't seen an Android phone without fingerprint authentication for years and most of them have face id too - I believe the Apple implementation is more secure than most, but the unlock function works fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...