Site icon TheDailyCheck.net

Microsoft wants to take any MFA and 2FA worries out of your hands

Microsoft wants to take any MFA and 2FA worries out of your hands

Microsoft has unveiled plans to take the decision on which authentication method to use out of your hands, instead offering prompts based on security levels.

Having already written about the disadvantages of using SMS and voice-based multi-factor authentication (MFA) methods, citing social engineering, mobile operator performance, technical evolution, and more, Microsoft VP Director of Identity Security, Alex Weinert, has now alluded to more secure approaches.

Weinert explained users typically opt for less secure MFA methods despite having access to better options out of convenience, technical limitations, or simply a lack of awareness.

Microsoft MFA methods

With the change, users that have registered more than one authentication method will be prompted to sign in with the most secure. Out of SMS and a Microsoft Authenticator push notification, the system will choose the latter, though users will still be able to use the non-preferred method if their circumstances require it.

An instruction page has been set up to guide system admins to set up system-preferred multi-factor authentication via the Azure Portal and via GraphAPI.

Having rolled out to come users on an automatically disabled basis already, it will now begin to roll out more widely, and automatically enabled. At some point, Microsoft will remove the option to disable system-preferred MFA altogether, though a timeline for this isn’t expected to be publicized for a few weeks.

Weinert says: “To best secure your organization and its end users, we highly encourage you to use the rollout controls and deploy this new feature as soon as you can. It’s now available in your tenant, making it easy to ensure users always use the most secure authentication method first.”

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TheDailyCheck is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – abuse@thedailycheck.net The content will be deleted within 24 hours.
Exit mobile version