System-preferred authentication
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit d60b306 · +7 −7 lines · also on GitHub
11
---
22
title: System-preferred authentication in Microsoft Entra ID
3
−description: Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both primary and multifactor authentication.
3
+description: Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both first-factor and second-factor authentication.
44
ms.topic: overview
55
ms.date: 04/15/2026
66
ms.reviewer: msft-poulomi
⋯ 21 unchanged lines
2828
2929
- **Disabled** - No change to sign-in logic.
3030
- **Enabled** - System-preferred authentication applies to second-factor (MFA) only. The existing sign-in behavior continues to apply for first-factor authentication.
31
−- **Microsoft managed** - System-preferred authentication applies to both primary and secondary authentication. The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step.
31
+- **Microsoft managed** - System-preferred authentication applies to both first-factor and second-factor authentication. The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step.
3232
3333
Both **Enabled** and **Microsoft managed** modes allow administrators to include or exclude specific users or groups.
3434
3535
> [!TIP]
36
−> If you don't want system-preferred authentication to apply to primary authentication, switch from **Microsoft managed** to **Enabled**. The **Enabled** state applies system-preferred logic to second-factor only.
36
+> If you don't want system-preferred authentication to apply to first-factor authentication, switch from **Microsoft managed** to **Enabled**. The **Enabled** state applies system-preferred logic to second-factor only.
3737
3838
> [!NOTE]
3939
> System-preferred authentication is scoped to users, not devices. Administrators include or exclude users or groups but can't assign the feature to specific devices or device groups.
⋯ 82 unchanged lines
122122
123123
When a user signs in, the authentication process checks which methods are registered. The user is prompted to sign in with the most secure method according to the following order. The method order is dynamic and updates as the security landscape changes. Users can always cancel and choose a different available sign-in method. If your organization has Conditional Access policies that require specific authentication methods, those policies continue to take priority over the system-preferred authentication order.
124124
125
−When in the **Microsoft managed** state, the system evaluates available credentials and selects the highest-ranked method for both primary and secondary authentication.
125
+When in the **Microsoft managed** state, the system evaluates available credentials and selects the highest-ranked method for both first-factor and second-factor authentication.
126126
127127
| Rank | Credential | Category | Meets requirement for |
128128
|------|-----------|----------|----------------------|
⋯ 26 unchanged lines
155155
156156
:::image type="content" border="true" source="./media/how-to-mfa-number-match/legacy-settings.png" alt-text="Screenshot of legacy MFA settings.":::
157157
158
−### How does system-preferred authentication affect primary sign-in?
158
+### How does system-preferred authentication affect first-factor sign-in?
159159
160
−When set to **Microsoft managed**, the system applies the credential ranking to both primary and secondary authentication. For example, if a user has both a password and a passkey registered, they're prompted with the passkey at first-factor sign-in instead of the password. The user can still select other sign-in options.
160
+When set to **Microsoft managed**, the system applies the credential ranking to both first-factor and second-factor authentication. For example, if a user has both a password and a passkey registered, they're prompted with the passkey at first-factor sign-in instead of the password. The user can still select other sign-in options.
161161
162
−When set to **Enabled**, the credential ranking applies only to second-factor authentication. Primary sign-in behavior remains unchanged.
162
+When set to **Enabled**, the credential ranking applies only to second-factor authentication. First-factor sign-in behavior remains unchanged.
163163
164164
### Can users still choose a different sign-in method?
165165
⋯ 6 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.