Forum Discussion

lance-aughey's avatar
lance-aughey
Iron Contributor
Aug 23, 2019
Solved

Modern Authentication - managing, supporting and deploying systems/devices is a nightmare

I wholeheartedly agree with modern authentication (and it's mild association with MFA) - we use MA throughout our environment and, from a security perspective, it works great. HOWEVER, am I the only ...
  • PBeiler1's avatar
    Aug 25, 2019

    lance-aughey, In my office 365 tenant, I (a global admin) go to Portal.Azure.com \ Azure Active Directory \ Users \ Go to their ID \  Authentication Methods tab \ change the phone number to my cell.  The MFA prompts now come to my cell.  When finished, I put their phone number back in.   

    Three quarters of my force (49 IDs, small shop). is on the road, in multiple states throughout the US.  This has worked well for me.  I have not done the password-less-MFA (works with Microsoft Authenticator) for anyone but me, so haven't figured that one out.  All my users do the sms text, which has worked out well, even when rebuilding devices for an existing account.  Our devices are Azure-AD-Joined, thus requiring the text when logging on with their ID.

    MFA is enforced for all IDs in my tenant.  We have the E5 license and the EMS-5 license.

    There is also a temporary override switch on the MFA, but haven's played with that so can't give an opinion here.  

Resources