Enable Additional context together with Number matching in Microsoft Authenticator Notifications using Entra



"We will remove the admin controls and enforce the number match experience tenant-wide for all users of Microsoft Authenticator push notifications starting May 8, 2023.
We highly recommend enabling number matching in the near term for improved sign-in security. Relevant services will begin deploying these changes after May 8, 2023 and users will start to see number match in approval requests. As services deploy, some may see number match while others don't. To ensure consistent behavior for all users, we highly recommend you enable number match for Microsoft Authenticator push notifications in advance."

Number matching is a key security upgrade to traditional second factor notifications in Microsoft Authenticator. So it is a no brainer to have this enabled by default for all users. However, I will recommend enabling additional context together with number matching to improve sign-in security and protect against MFA fatigue based attacks.

There are some pre-requisites for both number matching and additional context.

- Your organization needs to enable Microsoft Authenticator passwordless and push notifications for some users or groups by using the new Authentication methods policy.

- If your organization is using AD FS adapter or NPS extensions, upgrade to the latest versions for a consistent experience.

If you haven't enabled  number matching and additional context as yet, then you can do it through Entra which is Microsoft's latest modern identity and access management solution.

1. In the Entra portal, click Protect & secure > Authentication methods > Microsoft Authenticator.

2. On the Enable and Target tab, click Yes and All users to enable the policy for everyone or add selected users and groups. Set the Authentication mode for these users/groups to Any or Push.


Note: Only users who are enabled for Microsoft Authenticator here can be included in the policy to require number matching for sign-in, or excluded from it. Users who aren't enabled for Microsoft Authenticator can't see the feature.

3. On the Configure tab, for Require number matching for push notifications, change Status to Enabled and choose who to include or exclude from number matching.


4. Next up is to configure for Show application name in push and passwordless notifications. To do this change Status to Enabled and choose who to include or exclude from the policy.



5. Do the same for Show geographic location in push and passwordless notifications and then save.



End user experience

When user is challenged with MFA, they will be asked to enter a number and additional context details will be shown.


Conclusion

That's it. Admin control for number matching will be removing based on Microsoft's recent communication. However, admin control around additional context is available now and it is a good time to test the functionality and plan out the rollout in production.

Comments

Popular posts from this blog

How to force escrowing of BitLocker recovery keys using Intune

Intune: Configure Printers for Non-Administrative Users

Intune: UAC Elevation Prompt Behavior for Standard Users