Forum Discussion
luvsql
Mar 09, 2021Steel Contributor
MFA without a Cellphone
This is becoming a bigger issue more and more. We cannot, as a company, require our Employees to use a personal cellphone to get text codes or install work apps to authenticate our work accounts. ...
pazdedav
Aug 16, 2021MVP
You could consider using hardware tokens for MFA, this feature is currently in Preview: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-oath-tokens#oath-hardware-tokens-preview
You could purchase and distribute those tokens to your users, so they don't need to use a mobile phone. They use the token instead.
You could purchase and distribute those tokens to your users, so they don't need to use a mobile phone. They use the token instead.
Jeff_Birks
Jul 24, 2024Copper Contributor
There are plenty of hardware tokens available that are compatible with Microsoft - e.g. https://deepnetsecurity.com/authenticators/one-time-password/safeid/hardware-mfa-tokens-office-365-azure-multi-factor-authentication/
You will need to ensure that they are TOTP tokens (either 30 or 60 seconds), that you upload the seed data to Microsoft (including UPN details), and activate the tokens.
You will need to ensure that they are TOTP tokens (either 30 or 60 seconds), that you upload the seed data to Microsoft (including UPN details), and activate the tokens.
- Jeff_BirksJul 24, 2024Copper ContributorUnfortunately there are not a lot of workable alternatives to using a mobile. There are desktop apps that can be used (similar to google authenticator), and FIDO keys can also be considered (but this is a more expensive option and still has limited application).
- JoshARIJul 24, 2024Copper ContributorThanks for the response. Don't see how tokens will work for us, and would have to convince a small business owner to buy them. Don't even see that as an option under our 365 MFA setup, or an option that can be added but I'm no expert so I'll take your word for it. Long story short a one solution to fit all scenarios won't work for us, we have multiple MFA logins, within our own network, within our clients networks. With multiple different MFA apps, sometimes VPN involved sometimes not. Sure when we're the admins and can control the access, tokens might work, but most times, we're not and at the mercy of our clients. Who are typically much larger than we are, and most likely provide their employees with secured company phones. it's a problem, that there seems to be no easy solution for, and is driving our employees crazy. And when you can't have mobile phones on the production floor due to PCI and SSAE compliances, and/or you're expecting your employees to use personal assets to perform a job function. it's problematic, IT folks find themselves in-between of now. Right now 'alt or desk phone' method works for us, though it does seem to get wonkie over time and needs reset now and then, but just waiting for that to go away. We also have one client that uses Cisco Duo and there seems no way around that without using the mobile app and a having a mobile number. To me not a whole lot of particle, real world thought, went into MFA. Probably shocking but nearly 40% of Americans don't have a mobile phone, and/or share a number/phone with some other family member.