Push Notifications via Microsoft Authenticator Check [CHK-1140]
This check verifies if Push notifications via Microsoft Authenticator are enabled for two-factor authentication.
Rationale
Two-factor authentication provides extra protection against leaked passwords. Microsoft Authenticator is a secure and user-friendly way to activate this feature. During a login attempt, the user will receive an additional verification notification on their mobile device to approve the attempt.
Fix
An automated fix is available through Attic.
Manual steps:
- Navigate to Entra ID portal at https://entra.microsoft.com.
- Go to Authentication methods.
- Click on "Policies".
- Click on "Microsoft Authenticator".
- Set "Enable" to "Yes".
- Under "Target", select "All users".
- Under "Configure", ensure "Allow use of Microsoft Authenticator OTP" is set to "Enabled".
- Set "Require number matching" to "Enabled" for additional security.
- Click "Save".
Impact
We advise making Microsoft Authenticator available for all employees which results in push notifications via Microsoft Authenticator when they sign-in.
More Information
For more information, visit Microsoft Authenticator.