Knut Posted December 14, 2022 Report post Posted December 14, 2022 Hi, I have enabled this for a few users - and it works good. However, when users change to "use login and password" for some apps, this authentication method is remembered after. Is there a way to enforce users to always use Number Matching, meaning reverting the users mfa back from username/password? Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted December 14, 2022 Report post Posted December 14, 2022 was this question related to Windows 365 or Azure AD ? number matching will be the default method come february 2023, so how can users choose something else ? Can I opt out of number matching? Yes, currently you can disable number matching. We highly recommend that you enable number matching for all users in your tenant to protect yourself from MFA fatigue attacks. Microsoft will enable number matching for all tenants by Feb 27, 2023. After protection is enabled by default, users can't opt out of number matching in Microsoft Authenticator push notifications. Quote Share this post Link to post Share on other sites More sharing options...
Knut Posted December 15, 2022 Report post Posted December 15, 2022 11 hours ago, anyweb said: was this question related to Windows 365 or Azure AD ? number matching will be the default method come february 2023, so how can users choose something else ? Can I opt out of number matching? Yes, currently you can disable number matching. We highly recommend that you enable number matching for all users in your tenant to protect yourself from MFA fatigue attacks. Microsoft will enable number matching for all tenants by Feb 27, 2023. After protection is enabled by default, users can't opt out of number matching in Microsoft Authenticator push notifications. I know this will be the default method, but when users change the logon-option to username and password, it won't go back to Number Matching as default. The user have to manually change this back to Number Matching, and this can cause confusion. Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted December 15, 2022 Report post Posted December 15, 2022 where did they change the option, at the login to windows screen or somewhere else ? Quote Share this post Link to post Share on other sites More sharing options...
Knut Posted December 15, 2022 Report post Posted December 15, 2022 When they log in to the app in azure, they can change the authentication method. Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted December 15, 2022 Report post Posted December 15, 2022 i'm not sure which app you mean, but perhaps you mean this ? https://aka.ms/mfasetup and in there the USER can change to whatever default method they want, this is a user setting and we cannot enforce it (that I am aware of) 1 Quote Share this post Link to post Share on other sites More sharing options...