ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 06:21 UTC Customize Public modeDiscuss ChangeIntel on Discord

System-preferred authentication

This page's changes and edits · All guidance changes

Microsoft's edit ·

Update system-preferred authentication FAQ and terminology

Microsoft's commit message in MicrosoftDocs/entra-docs · commit ffc2690 · +2 −8 lines · also on GitHub

⋯ 26 unchanged lines
2727 System-preferred authentication has three modes:
2828
2929 - **Disabled** - No change to sign-in logic.
30 −- **Enabled** - System-preferred authentication applies to second-factor (MFA) only. The existing sign-in behavior continues to apply for first-factor authentication.
30 +- **Enabled** - System-preferred authentication applies to second-factor only. The existing sign-in behavior continues to apply for first-factor authentication.
3131 - **Microsoft managed** - System-preferred authentication applies to both first-factor and second-factor authentication. The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step.
3232
3333 Both **Enabled** and **Microsoft managed** modes allow administrators to include or exclude specific users or groups.
⋯ 7 unchanged lines
4141 ### Known limitations
4242
4343 - When you change the policy for a target group, the change might not take effect on the user's very next sign-in. It applies to all subsequent sign-ins after that.
44 −- Conditional Access policy is validated only for MFA and doesn't apply to first-factor authentication. Authentication happens first, and then Conditional Access evaluates authorization. System-preferred authentication doesn't override Conditional Access policies or authentication strength requirements.
44 +- Conditional Access policy is validated only for second-factor authentication and doesn't apply to first-factor authentication. Authentication happens first, and then Conditional Access evaluates authorization. System-preferred authentication doesn't override Conditional Access policies or authentication strength requirements.
4545
4646 ## Enable system-preferred authentication in the Microsoft Entra admin center
4747
⋯ 98 unchanged lines
146146 ### How does system-preferred authentication affect the NPS extension?
147147
148148 System-preferred authentication doesn't affect users who sign in by using the Network Policy Server (NPS) extension. Those users don't see any change to their sign-in experience.
149 −
150 −### What happens for users who aren't specified in the Authentication methods policy but enabled in the legacy MFA tenant-wide policy?
151 −
152 −System-preferred authentication also applies for users who are enabled for MFA in the legacy MFA policy.
153 −
154 −:::image type="content" border="true" source="./media/how-to-mfa-number-match/legacy-settings.png" alt-text="Screenshot of legacy MFA settings.":::
155149
156150 ### How does system-preferred authentication affect first-factor sign-in?
157151
⋯ 12 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 06:21 UTC · 252 of 253 readable · documentation 391/391 current