ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 22:22 UTC Customize Public modeDiscuss ChangeIntel on Discord

System-preferred authentication

This page's changes and edits · All guidance changes

Microsoft's edit ·

Update system-preferred authentication rollout date

Microsoft's commit message in MicrosoftDocs/entra-docs · commit bd00d7e · +2 −2 lines · also on GitHub

⋯ 1 unchanged line
22 title: System-preferred authentication in Microsoft Entra ID
33 description: Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both first-factor and second-factor authentication.
44 ms.topic: overview
5 −ms.date: 04/15/2026
5 +ms.date: 09/01/2026
66 ms.reviewer: msft-poulomi
77 ms.custom: msecd-doc-authoring-1012
88 ai-usage: ai-assisted
⋯ 10 unchanged lines
1919 System-preferred authentication is a Microsoft managed setting, which is a [three-state policy](#authentication-method-feature-configuration-properties) (enabled, disabled, or Microsoft managed). If you don't want to enable system-preferred authentication, change the state from **Microsoft managed** to **Disabled**, or exclude users and groups from the policy.
2020
2121 > [!NOTE]
22 −> The **Microsoft managed** state behavior affects both first-factor and multifactor authentication and is being gradually deployed to tenants through August 2026. If your tenant or users don't experience system-preferred authentication as the first factor when the **State** is **Microsoft managed**, the rollout isn't deployed yet for your tenant.
22 +> The **Microsoft managed** state behavior affects both first-factor and multifactor authentication and is being gradually deployed to tenants through September 2026. If your tenant or users don't experience system-preferred authentication as the first factor when the **State** is **Microsoft managed**, the rollout isn't deployed yet for your tenant.
2323
2424 After system-preferred authentication is enabled, the authentication system does all the work. Users don't need to set any authentication method as their default because the system always determines and presents the most secure method they registered.
2525
⋯ 154 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy today 21:19 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 9 Oct 22:22 UTC · 252 of 253 readable · documentation 391/391 current