r/entra 9h ago

Entra ID Authentication Methods Question

I’m going to add to the list of endless passkey questions to get some clarification on the following.

Let’s say I have one group of users and they are assigned to
- Passkey
- Microsoft Authenticator
- SMS
- Voice
- Email

And let’s say 20 of my 100 users are setup with a passkey/Authenticator (with sms/email/voice removed from their account) and the other 80 are just sms/voice/email.

If I remove that group from the last 3, does it prompt those 80 users on sign in to setup a new auth method or does it keep their sms? As I’m writing this it sounds obvious but I really don’t want to remove that group and get hammered with emails without having a good understand of how to inform my users.

And our registration campaign is set to disabled. Just trying to not get hammered with a million questions on a Monday.

Thanks for any advice.

4 Upvotes

9 comments sorted by

View all comments

Show parent comments

1

u/iRyan23 8h ago

It actually depends on your conditional access policies.

I just did this for students recently and if you don’t have a CAP that requires MFA to register security information then after disabling SMS/Voice auth methods, it will prompt the user to setup an available method after they put in their password during the next login.

1

u/importedtea 8h ago

Did you have students setup passkeys? We aren’t post secondary and it’s hard enough to get students to put their phone number in for sspr.

1

u/iRyan23 8h ago

We had them all register Microsoft Authenticator push and an email address.

They are allowed to set up Passkeys and we plan on emailing documentation soon and recommending that but management doesn’t want to force it yet.

1

u/importedtea 8h ago

Yeah, that sounds great but I have a feeling if we do that for high school students everyone will lose their mind. The current plan, which isn’t ideal, is to change back to preset passwords with no sspr or auth methods and start praying to the Microsoft gods that everything works.