Allow Use of Microsoft Authenticator OTP in Azure AD


Hi All,


We wanted to enabled number matching and Passwordless with Microsoft Authenticator app and when I go to there I could see the below setting under configurations. But I wanted to make sure what that setting is and what it the recommended configurations for this "Allow Use of Microsoft Authenticator OTP" before configure in production environment.


appreciate if anyone could help me on this.








I believe the settings is about the possibility to use the Authenticator app when you happen to be "offline" for some reason, i.e. like a hardware token generating a code.
It basically allows the use of 6-digit one-time passcodes as part of the login process. It's not needed for either passwordless or number matching scenarios.
Its all to do with the migration from the Legacy MFA methods. Legacy MFA methods (and SSPR Methods) will be removed as configurable options Jan 2024 (14 months from writing this). Before you migrate the option you have highlighted above is taken from the old and new settings, so the legacy setting "Verification code from mobile app or hardware token" will work even if the above is set to "No" as the legacy settings are accepted. Once you complete migration or Jan 2024 happens (see the legacy methods stop working, so you have the time between now and then to update all the settings under Authentication Methods to match your current settings, including this one.