How does Azure MFA work?
Azure Active Directory (AD) MFA works by the user requiring two or more authentication methods to complete a sign-in process. The first method is typically a password. Trusted devices such as a phone or hardware key or biometrics such as a fingerprint or face scan can be used as a second method.
Important Note
Azure AD MFA also offers a feature known as secure password reset. This can be enabled when users register for Azure AD MFA, which appears as an additional step.
You can use the following forms of authentication when using Azure MFA:
- Microsoft Authenticator app
- OATH hardware token (preview)
- OATH software token
- SMS
- Voice call
The verification when using Azure MFA looks similar to the following screenshot:
You have the option of configuring the security defaults to enable Authenticator for all users or choosing conditional...