ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 04:19 UTC Customize Public modeDiscuss ChangeIntel on Discord

System-preferred authentication

This page's changes and edits · All guidance changes

Microsoft's edit ·

Add note about Microsoft managed rollout timeline

Microsoft's commit message in MicrosoftDocs/entra-docs · commit b7e1719 · +3 −0 lines · also on GitHub

⋯ 15 unchanged lines
1616
1717 System-preferred authentication prompts users to sign in by using the most secure method they registered. It's an important security enhancement for users who authenticate by using less secure methods like passwords or SMS.
1818
19 +> [!NOTE]
20 +> Microsoft managed behavior affects both first-factor and multifactor authentication and is being gradually deployed to tenants through July 2026. If your tenant or users aren't experiencing system-preferred authentication as the first factor when the **State** is **Microsoft managed**, the rollout isn't deployed yet for your tenant.
21 +
1922 For example, if a user registered both a password and a passkey, system-preferred authentication prompts the user to sign in with the passkey instead of the password. The user can still choose to sign in by using another method, but they're first prompted to try the most secure method they registered.
2023
2124 System-preferred authentication is a Microsoft managed setting, which is a [three-state policy](#authentication-method-feature-configuration-properties) (enabled, disabled, or Microsoft managed). If you don't want to enable system-preferred authentication, change the state from **Microsoft managed** to **Disabled**, or exclude users and groups from the policy.
⋯ 141 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 04:19 UTC · 252 of 253 readable · documentation 391/391 current