Skip to content

Ulysses Neves

Microsoft Entra ID, authentication, and hybrid identity troubleshooting.

Menu
  • Home
  • Microsoft Azure
  • Microsoft AD FS
  • Microsoft 365
  • Contact
  • Troubleshooting Index
Menu

Microsoft Entra Conditional Access – Enforcing passwordless sign-in with Microsoft Authenticator using authentication strengths

Posted on July 28, 2023

Summary

Hello everyone. In this article, I will cover the steps to enforce users to use passwordless sign-in with Microsoft Authenticator with Authentication Strength in Microsoft Entra Conditional Access policy. Detailed information about this feature can be found at this link: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-strengths

Step 1: Enable the user for the authenticator method

Since we want to use Authentication Strength with Authenticator App passwordless sign-in, we will enable the setting to all users under ‘Authentication methods | Policies’.

Step 2: Create the Conditional Access Policy with the authentication strengths

Policy goal: Enforce Passwordless Sign in using Authenticator App for users trying to access Azure Portal.

Create a new policy using the option ‘+ New Policy’ under Microsoft Entra Conditional Access policy blade:

Give the policy a name and follow the steps below to configure the users who should be covered by the policy:
1 – Define which users should be covered by the policy selecting Users.
2 – Select one of the options available to the type of user to be covered by the policy.
3 – In this scenario, I will select users who are members of the Microsoft Entra tenant.
4 – Click on Select and search for the user you want to cover with the policy.

Select the Cloud Apps to be covered by the policy as below:
1 – To apply a policy to a cloud App, select Cloud apps or actions.
2 – Select Cloud apps.
3 – To filter specific cloud apps, click on Select Apps.
4 – Click on Select and search for the app you want to cover with the policy. I’ve chosen Microsoft Azure Management App.

Define the access controls with steps below:
1 – Click on Grant option.
2 – Select Grant Access option.
3 – Check the Require authentication strength option and select the option you want to enforce. Since we’re looking forward to enforcing Phone Sign-in using Microsoft Authenticator app, we’ll choose the option Passwordless MFA.

User experience

To demonstrate the user experience after the policy created above is enabled, we’ll use a test account named bob@mydomain.onmicrosoft.com to access https://portal.azure.com.

After providing the username and password, we receive the prompt below, which is quite common when there is an MFA requirement. Let’s click Next.

After proceeding with the message above, I get another message below:

Additional authentication is required to complete this sign-in. Learn how to set up Microsoft Authenticator and enable phone sign-in on your device, then go to https://aka.ms/mysecurityinfo to add the authentication method to your account.

The above message is properly documented in the link below and confirms that currently, Microsoft Authenticator app can’t be registered during sign-in.

https://learn.microsoft.com/en-us/azure/active-directory/authentication/troubleshoot-authentication-strengths#a-user-cant-register-a-new-method-during-sign-in

Since my test user didn’t have PSI properly registered, I will enable it in the Microsoft Authenticator app:

Once I open my Microsoft Authenticator app, I select my test account and click on Enable phone sign-in.

Device registration and a passcode are required when enabling this option. More information on these requirements, check out this link: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-phone

Click on Continue.

I approve my MFA with number matching request.

And finally, Passwordless is enabled in the Microsoft Authenticator app.

Now, with the Passwordless Sign-in enabled in the Microsoft Authenticator app, let’s access URL https://portal.azure.com again.

During the authentication, I’m prompted to sign in using Microsoft Authenticator app.

Opening the Microsoft Authenticator app in my mobile device, I confirm the App, location and provide the code provided during the authentication.

As a result, I was successfully signed in to Azure Portal after performing the authentication using Microsoft Authenticator app.

Investigating the Sign in logs

To get more information about the sign-in performed above, I will open the Microsoft Entra sign-in logs for the test user Bob.

Looking into Authentication Details, we confirm the Passwordless MFA requirement is satisfied as a first factor.

Looking into the Conditional Access Policy Details, we find more information about the Authentication Strengths control configured in the policy.

Summary

In this article, we covered how to enforce users to use the Microsoft Authenticator App Phone Sign-in method with Authentication Strength in Microsoft Entra Conditional Access policy.

Enjoyed the article? Like and share. 🙂

Note: I do not represent the organization I work for, all the opinions expressed here, are my own. This post is provided AS IS with no warranties or guarantees and confers no rights.

In case you have any suggestions or feedback, please leave a comment.

[ ]’s
Ulysses Neves

Related guides: Browse the Microsoft Identity Troubleshooting Index or the Microsoft Entra Conditional Access topic archive.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Microsoft Defender for Identity domain investigation: six questions to ask first September 10, 2026
  • Microsoft Entra Kerberos key rotation: what changes—and what administrators should check September 6, 2026
  • Microsoft Authenticator Will Block Jailbroken Devices in 2026 — What You Need to Know March 17, 2026
  • Enhancing Azure role activation security with FIDO2/Passkeys September 23, 2024
  • Microsoft Entra ID CAP | Enforcing WHfB using Authentication Strength April 21, 2024

Archives

  • September 2026
  • March 2026
  • September 2024
  • April 2024
  • February 2024
  • December 2023
  • September 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019

Tags

#aaddownleveldevice #adfs #adfscertificate #adfscertificates #adfsmfaadapter #azureauth #azureCA #azuredevice #capolicy #cloudsummit2021 #conditionalaccess #conditionalaccesspolicy #deviceregistration #farmbehavior #gopasswordless #mfaserver #msidentity #namedlocation #securingazure #securingazuread #sslprivatekey #troubleshootingadfs #troubleshootingwaptrust #tshootadfs #waptrust #webapplicationproxy #WHFBcerttrust #whfbdeployment #WHfBhybridsetup #WHfBprovisioning #widdatabase adconnect AD FS authenticationstrength az500 azurepim Azure security cloudsecurity microsoft365 Microsoft Azure Microsoft Entra hybrid join Microsoft Entra ID Microsoft Entra MFA PowerShell WHfB
©2026 Ulysses Neves | Design: Newspaperly WordPress Theme
Ulysses Neves
Gerenciar Consentimento de Cookies
Para fornecer as melhores experiências, usamos tecnologias como cookies para armazenar e/ou acessar informações do dispositivo. O consentimento para essas tecnologias nos permitirá processar dados como comportamento de navegação ou IDs exclusivos neste site. Não consentir ou retirar o consentimento pode afetar negativamente certos recursos e funções.
Funcional Always active
O armazenamento ou acesso técnico é estritamente necessário para a finalidade legítima de permitir a utilização de um serviço específico explicitamente solicitado pelo assinante ou utilizador, ou com a finalidade exclusiva de efetuar a transmissão de uma comunicação através de uma rede de comunicações eletrónicas.
Preferências
O armazenamento ou acesso técnico é necessário para o propósito legítimo de armazenar preferências que não são solicitadas pelo assinante ou usuário.
Estatísticas
O armazenamento ou acesso técnico que é usado exclusivamente para fins estatísticos. O armazenamento técnico ou acesso que é usado exclusivamente para fins estatísticos anônimos. Sem uma intimação, conformidade voluntária por parte de seu provedor de serviços de Internet ou registros adicionais de terceiros, as informações armazenadas ou recuperadas apenas para esse fim geralmente não podem ser usadas para identificá-lo.
Marketing
O armazenamento ou acesso técnico é necessário para criar perfis de usuário para enviar publicidade ou para rastrear o usuário em um site ou em vários sites para fins de marketing semelhantes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Ver preferências
  • {title}
  • {title}
  • {title}