ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 13:50 UTC Customize Public modeDiscuss ChangeIntel on Discord

System-preferred authentication

This page's changes and edits · All guidance changes

Microsoft's edit ·

Use first-factor and second-factor consistently

Microsoft's commit message in MicrosoftDocs/entra-docs · commit d60b306 · +7 −7 lines · also on GitHub

11 ---
22 title: System-preferred authentication in Microsoft Entra ID
3 −description: Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both primary and multifactor authentication.
3 +description: Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both first-factor and second-factor authentication.
44 ms.topic: overview
55 ms.date: 04/15/2026
66 ms.reviewer: msft-poulomi
⋯ 21 unchanged lines
2828
2929 - **Disabled** - No change to sign-in logic.
3030 - **Enabled** - System-preferred authentication applies to second-factor (MFA) only. The existing sign-in behavior continues to apply for first-factor authentication.
31 −- **Microsoft managed** - System-preferred authentication applies to both primary and secondary authentication. The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step.
31 +- **Microsoft managed** - System-preferred authentication applies to both first-factor and second-factor authentication. The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step.
3232
3333 Both **Enabled** and **Microsoft managed** modes allow administrators to include or exclude specific users or groups.
3434
3535 > [!TIP]
36 −> If you don't want system-preferred authentication to apply to primary authentication, switch from **Microsoft managed** to **Enabled**. The **Enabled** state applies system-preferred logic to second-factor only.
36 +> If you don't want system-preferred authentication to apply to first-factor authentication, switch from **Microsoft managed** to **Enabled**. The **Enabled** state applies system-preferred logic to second-factor only.
3737
3838 > [!NOTE]
3939 > System-preferred authentication is scoped to users, not devices. Administrators include or exclude users or groups but can't assign the feature to specific devices or device groups.
⋯ 82 unchanged lines
122122
123123 When a user signs in, the authentication process checks which methods are registered. The user is prompted to sign in with the most secure method according to the following order. The method order is dynamic and updates as the security landscape changes. Users can always cancel and choose a different available sign-in method. If your organization has Conditional Access policies that require specific authentication methods, those policies continue to take priority over the system-preferred authentication order.
124124
125 −When in the **Microsoft managed** state, the system evaluates available credentials and selects the highest-ranked method for both primary and secondary authentication.
125 +When in the **Microsoft managed** state, the system evaluates available credentials and selects the highest-ranked method for both first-factor and second-factor authentication.
126126
127127 | Rank | Credential | Category | Meets requirement for |
128128 |------|-----------|----------|----------------------|
⋯ 26 unchanged lines
155155
156156 :::image type="content" border="true" source="./media/how-to-mfa-number-match/legacy-settings.png" alt-text="Screenshot of legacy MFA settings.":::
157157
158 −### How does system-preferred authentication affect primary sign-in?
158 +### How does system-preferred authentication affect first-factor sign-in?
159159
160 −When set to **Microsoft managed**, the system applies the credential ranking to both primary and secondary authentication. For example, if a user has both a password and a passkey registered, they're prompted with the passkey at first-factor sign-in instead of the password. The user can still select other sign-in options.
160 +When set to **Microsoft managed**, the system applies the credential ranking to both first-factor and second-factor authentication. For example, if a user has both a password and a passkey registered, they're prompted with the passkey at first-factor sign-in instead of the password. The user can still select other sign-in options.
161161
162 −When set to **Enabled**, the credential ranking applies only to second-factor authentication. Primary sign-in behavior remains unchanged.
162 +When set to **Enabled**, the credential ranking applies only to second-factor authentication. First-factor sign-in behavior remains unchanged.
163163
164164 ### Can users still choose a different sign-in method?
165165
⋯ 6 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 13:50 UTC · 252 of 253 readable · documentation 391/391 current