Is Microsoft Basic Authentication end of life January 2023?
Beginning in early 2023, Microsoft disabled Basic authentication for all tenants who had any type of extension. All other cloud environments were subject to the October 1, 2022 date.
How do I know if my MFA is enforced?
Click on a user's name and then select Manage User to check if a user has MFA enabled.
Under Security info, you can view all the multi-factor authentication methods enabled for a user. If none of the multi-factor authentication methods are enabled, then the user does not have MFA enabled.
What is new in Microsoft Authenticator February 2023?
Microsoft will be introducing a new security feature called 'number matching' to the Microsoft Authenticator app.
If you use this app for your multi-factor authentication (MFA) you will notice this change from 22 February 2023. Other authentication methods (such as the Authy app) remain unchanged.
Is Microsoft enforcing MFA May 2023?
And as of May 8, 2023, Microsoft will begin removing administrator control (over the use of Number Match) to enforce number match checking Tenant-wide for all users of Microsoft Authenticator push notifications.
Admins will always be prompted for MFA on login.
Users will be prompted for MFA "when necessary" (this is not strictly defined by Microsoft but includes when users show up on a new device or app, and for critical roles and tasks).
Access to Azure portal, Azure CLI or Azure PowerShell by anyone will always require MFA.
What happens when MFA is enforced?
The user is enrolled in MFA, but if they have not registered authentication methods, they are prompted to do so the next time they log in using modern authentication.
Is Microsoft stopping SMS for MFA?
Microsoft will no longer support SMS for certain types of sign-ins, including sign-ins from new devices and sign-ins that require multi-factor authentication.
This is being done to improve security and reduce the risk of unauthorized access.
The usual contention is employees are unwilling to use their personal mobile devices for authenticating their access.
Customers may choose to set conditional access policy to reduce the number of MFA prompts when within the trusted locations added. This will requires at least one Azure AD P1 (Microsoft Entra ID P1), Office 365 E3 Plan or Office 365 Business Premium.
The alternative is to get a FIFO2 key or FIDO2 compliant pass for each user. Clients with issues setting up MFA using these can contact us for assistance.
Is Microsoft authenticator better than SMS?
Higher speed – Authenticator apps generate codes much faster than SMS texts, which makes them more practical for those who need to authenticate frequently. More reliable – Codes generated via authenticator apps are always available even when users experience network issues.
Why is SMS-based MFA not secure?
SMS-based MFA has been a widely used method for providing an additional layer of security, but it has significant vulnerabilities that can be exploited by attackers. Lack of encryption, network outages, SS7 attacks, social engineering, and SIM-swapping are all risks associated with SMS-based MFA.
Will Outlook constantly prompt for MFA?
The frequency of which users are prompted for MFA in Microsoft 365 varies depending on the organisation's settings, but typically, users are prompted when they:
Sign in to their account from a new device.
Sign in to their device from a new location.
Change a password.