System-preferred authentication
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit ffc2690 · +2 −8 lines · also on GitHub
⋯ 26 unchanged lines
2727
System-preferred authentication has three modes:
2828
2929
- **Disabled** - No change to sign-in logic.
30
−- **Enabled** - System-preferred authentication applies to second-factor (MFA) only. The existing sign-in behavior continues to apply for first-factor authentication.
30
+- **Enabled** - System-preferred authentication applies to second-factor only. The existing sign-in behavior continues to apply for first-factor authentication.
3131
- **Microsoft managed** - System-preferred authentication applies to both first-factor and second-factor authentication. The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step.
3232
3333
Both **Enabled** and **Microsoft managed** modes allow administrators to include or exclude specific users or groups.
⋯ 7 unchanged lines
4141
### Known limitations
4242
4343
- When you change the policy for a target group, the change might not take effect on the user's very next sign-in. It applies to all subsequent sign-ins after that.
44
−- Conditional Access policy is validated only for MFA and doesn't apply to first-factor authentication. Authentication happens first, and then Conditional Access evaluates authorization. System-preferred authentication doesn't override Conditional Access policies or authentication strength requirements.
44
+- Conditional Access policy is validated only for second-factor authentication and doesn't apply to first-factor authentication. Authentication happens first, and then Conditional Access evaluates authorization. System-preferred authentication doesn't override Conditional Access policies or authentication strength requirements.
4545
4646
## Enable system-preferred authentication in the Microsoft Entra admin center
4747
⋯ 98 unchanged lines
146146
### How does system-preferred authentication affect the NPS extension?
147147
148148
System-preferred authentication doesn't affect users who sign in by using the Network Policy Server (NPS) extension. Those users don't see any change to their sign-in experience.
149
−
150
−### What happens for users who aren't specified in the Authentication methods policy but enabled in the legacy MFA tenant-wide policy?
151
−
152
−System-preferred authentication also applies for users who are enabled for MFA in the legacy MFA policy.
153
−
154
−:::image type="content" border="true" source="./media/how-to-mfa-number-match/legacy-settings.png" alt-text="Screenshot of legacy MFA settings.":::
155149
156150
### How does system-preferred authentication affect first-factor sign-in?
157151
⋯ 12 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.