System-preferred authentication
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit 37b9016 · +1 −1 lines · also on GitHub
⋯ 20 unchanged lines
2121
System-preferred authentication is a Microsoft managed setting, which is a [three-state policy](#authentication-method-feature-configuration-properties) (enabled, disabled, or Microsoft managed). If you don't want to enable system-preferred authentication, change the state from **Microsoft managed** to **Disabled**, or exclude users and groups from the policy.
2222
2323
> [!NOTE]
24
−> The **Microsoft managed** state behavior affects both first-factor and multifactor authentication and is being gradually deployed to tenants through July 2026. If your tenant or users aren't experiencing system-preferred authentication as the first factor when the **State** is **Microsoft managed**, the rollout isn't deployed yet for your tenant.
24
+> The **Microsoft managed** state behavior affects both first-factor and multifactor authentication and is being gradually deployed to tenants through July 2026. If your tenant or users don't experience system-preferred authentication as the first factor when the **State** is **Microsoft managed**, the rollout isn't deployed yet for your tenant.
2525
2626
After system-preferred authentication is enabled, the authentication system does all the work. Users don't need to set any authentication method as their default because the system always determines and presents the most secure method they registered.
2727
⋯ 138 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.