Mar 24 2023 03:16 AM
Hi everyone,
is it possible to phase out SMS in rings? We still have too many users using text message as their first auth method.
We are "nudging" and we are sending campaings "how to change", but we want to get the last ones to change.
Is there any way to just restrict the usage of SMS in ring - so the first ring is 500 employees. The next one 1000 etc. Instead of just switching it to off? We would expect a high amount of service desk calls if we just switch it off.
Best regards
Stephan
Mar 24 2023 03:42 AM
Mar 24 2023 03:50 AM
Mar 24 2023 04:03 AM
Solutionyou can run through this scenario .
is that way you are asking the users to user Microsoft authenticator push notification or password code to validate their MFA . make sure to exclude from any other policy for MFA
Please click Mark as Best Response & Like if my post helped you to solve your issue. This will help others to find the correct solution easily.
Mar 24 2023 04:45 AM
Mar 24 2023 04:48 AM
Mar 28 2023 02:54 AM
Hi @eliekarkafy, i'm a colleague of @StephanGee,
I tried what you provided and it seems to work for existing SMS user(in scope),
but if you create a CA for a specific app with "Password + MS Authenticator (Push Notification) for all users (including users that already use MFA with MS App)
existing MFA App users gets the following error:
it should be this: A user is asked to sign in with another method, but they don't see a method they expect
it would be a pain to manually track SMS users and add them to a group /remove them if initial MFA App registration is done.
If this is correct, sadly "Authentication strength" isn't a solution for our scenario.
Hopefully I'm wrong. ;)
Do you have any tipps regarding this?
Thanks a lot.
Regards Patrick
Mar 28 2023 03:05 AM
Try to use the below default combination that include all the MFA options. Well, the transition phase will take time and we cant avoid some manual work I know but we have to deal with it.
please let me know if its work
Mar 28 2023 04:58 AM
sadly not, because the built-in "Multifactor authentication" includes SMS:
so everything works like before.
Mar 28 2023 05:51 AM
@PatrickEl Well, I think for the time being you have to use the method I suggested before. but there is a way to identify the users with SMS by navigating to usage and insights in Azure Active Directory where you can filter and download the list.
Mar 28 2023 06:18 AM