Skip to main content

Authenticator number matching to be enabled for all Microsoft Authenticator users

 

View the description of the update.                                                                                                                                                                                                                                                                         

Microsoft

 

Authenticator number matching to be enabled for all Microsoft Authenticator users

MC468492 · HCS COMPANY MICROSOFT SERVICES B.V.

Microsoft Authenticator App’s number matching is Generally Available! Microsoft will start enabling this critical security feature for all users of the Microsoft Authenticator app.

When this will happen:

Beginning February 27, 2023

How this affects your organization:

To prevent accidental approvals, admins can require users to enter a number displayed on the sign-in screen when approving an MFA request in the Microsoft Authenticator app. This feature is critical to protecting against MFA fatigue attacks which are on the rise.

Another way to reduce accidental approvals is to show users additional context in Authenticator notifications. Admins can now selectively choose to enable the following:

·    Application context: Show users which application they are signing into.

·    Geographic location context: Show users their sign-in location based on the IP address of the device they are signing into.

Authenticator number matching

Number match behavior in different scenarios after 27-February 2023:

1.  Authentication flows will require users to do number match when using the Microsoft Authenticator app. If the user is using a version of the Authenticator app that doesn’t support number match, their authentication will fail. Please make sure upgrade to the latest version of Microsoft Authenticator (App Store and Google Play Store) to use it for sign-in.

2.  Self Service Password Reset (SSPR) and combined registration flows will also require number match when users are using the Microsoft Authenticator app.

3.  ADFS adapter will require number matching on versions of Windows Server that support number matching. On earlier versions, users will continue to see the “Approve/Deny” experience and won’t see number matching till you upgrade.

o  Windows Server 2022 October 26, 2021—KB5006745 (OS Build 20348.320)

o  Windows Server 2019 October 19, 2021—KB5006744 (OS Build 17763.2268)

o  Windows Server 2016 October 12, 2021—KB5006669 (OS Build 14393.4704)

4.  NPS extension versions beginning 1.2.2131.2 will require users to do number matching after 27-February 2023. Because the NPS extension can’t show a number, the user will be asked to enter a One-Time Passcode (OTP). The user must have an OTP authentication method (e.g. Microsoft Authenticator app, software tokens etc.) registered to see this behavior. If the user doesn’t have an OTP method registered, they’ll continue to get the Approve/Deny experience. You can create a registry key that overrides this behavior and prompts users with Approve/Deny. More information can be found in the number matching documentation. 

5.  Apple Watch – Apple Watch will remain unsupported for number matching. We recommend you uninstall the Microsoft Authenticator Apple Watch app because you have to approve notifications on your phone.

What you can do to prepare:

We highly recommend that you leverage the rollout controls (via Azure Portal Admin UX and MSGraph APIs) to smoothly deploy these features (number match and additional context) for users of the Microsoft Authenticator app.

Learn more at: 

·    Number match documentation

·    Defend your users from MFA fatigue attacks - Microsoft Community Hub 

·    Advanced Microsoft Authenticator security features are now generally available! - Microsoft Community Hub

Additional Information

View in the Microsoft 365 admin center

 

 

Privacy Statement

Microsoft Corporation, One Microsoft Way, ​Redmond, WA 98052​

Microsoft

Comments

Popular posts from this blog

FW: Message Center Major Change Update Notification

  Organization: HCS COMPANY MICROSOFT SERVICES Feature Update: Auto-Attendant     Major update: General Availability rollout started Applied to: All customers     We are updating our services with new features and fixes, the first of which is a migration to the Microsoft Teams and Skype for Business Admin Center (Teams Admin Center). The rollout of the Teams Admin Center migration will begin soon for both Teams and Skype for Business Online tenants. This message is associated with Microsoft 365 Roadmap ID 46094 . [How does this affect me?] The administration of new and existing Auto-Attendants or Call Queues for your organization will be migrated to the Teams Admin Center. A new experience will also be introduced for creating Resource Accounts. We will be gradually rolling this out starting on F

Message center announcements, May 15, 2023 - May 21, 2023

Note: HCS-Company Microsoft Services is now Eden Akers Digital   View a summary of the updates.                                                                                                                                                                                                                                                                                 Message center announcements May 15, 2023 - May 21, 2023 HCS COMPANY MICROSOFT SERVICES B.V.   Major updates        (Updated) Microsoft Authenticator Lite in Outlook MC532607 | May 17 - Updated May 17, 2023: Today we are starting rollout for Authenticator Lite (in Outlook) to enter GA! The Microsoft managed value of this feature will be changed from ‘disabled’ to ‘enabled’ on June 9th. We have made some changes to the feature configuration, so if you made an update before GA (5/17), please validate that the feature is in the correct state for your tenant prior to June 9th. If you do not wish for this feature to be enabled

June 19, 2023 - June 25, 2023 Message center announcements

View a summary of the updates.                                                                                                                                                                                                                                                                                 Message center announcements June 19, 2023 - June 25, 2023   Major updates        (Updated) SharedWith and SharedWithDetails column in OneDrive and SharePoint will no longer be updated MC545906 | June 20 - Updated June 20, 2023: We have updated the rollout timeline below. Thank you for your feedback.We will be retiring the SharedWith and SharedWithDetails columns from OneDrive and SharePoint starting in early June. These columns have been hidden by default in OneDrive and SharePoint for several years and were replaced by the Manage Access experience and the "Shared With" section of the Share dialog. View more        (Updated) PDF Tools app retirement MC584834 | June 20 - Updat