You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/how-to-mfa-number-match.md
+17-7Lines changed: 17 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: Learn how to use number matching in MFA notifications
4
4
ms.service: active-directory
5
5
ms.subservice: authentication
6
6
ms.topic: conceptual
7
-
ms.date: 02/15/2023
7
+
ms.date: 02/16/2023
8
8
ms.author: justinha
9
9
author: justinha
10
10
ms.collection: M365-identity-device-management
@@ -87,12 +87,12 @@ Prior to the release of NPS extension version 1.2.2216.1 after May 8, 2023, orga
87
87
>[!NOTE]
88
88
>NPS extensions versions earlier than 1.0.1.40 don't support OTP enforced by number matching. These versions will continue to present users with **Approve**/**Deny**.
89
89
90
-
To create the registry key to override the **Approve**/**Deny** options in push notifications and require an OTP instead:
90
+
To create the registry entry to override the **Approve**/**Deny** options in push notifications and require an OTP instead:
91
91
92
92
1. On the NPS Server, open the Registry Editor.
93
93
1. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AzureMfa.
94
-
1.Set the following Key Value Pair:
95
-
Key: OVERRIDE_NUMBER_MATCHING_WITH_OTP
94
+
1.Create the following String/Value pair:
95
+
Name: OVERRIDE_NUMBER_MATCHING_WITH_OTP
96
96
Value = TRUE
97
97
1. Restart the NPS Service.
98
98
@@ -330,12 +330,12 @@ Here are differences in sign-in scenarios that Microsoft Authenticator users wil
330
330
- AD FS adapter will require number matching on [supported versions of Windows Server](#ad-fs-adapter). On earlier versions, users will continue to see the **Approve**/**Deny** experience and won’t see number matching until you upgrade.
331
331
- NPS extension versions beginning 1.2.2131.2 will require users to do number matching. Because the NPS extension can’t show a number, the user will be asked to enter a One-Time Passcode (OTP). The user must have an OTP authentication method such as Microsoft Authenticator or software OATH tokens registered to see this behavior. If the user doesn’t have an OTP method registered, they’ll continue to get the **Approve**/**Deny** experience.
332
332
333
-
To create a registry key that overrides this behavior and prompts users with **Approve**/**Deny**:
333
+
To create a registry entry that overrides this behavior and prompts users with **Approve**/**Deny**:
334
334
335
335
1. On the NPS Server, open the Registry Editor.
336
336
1. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AzureMfa.
337
-
1.Set the following Key Value Pair:
338
-
Key: OVERRIDE_NUMBER_MATCHING_WITH_OTP
337
+
1.Create the following String/Value:
338
+
Name: OVERRIDE_NUMBER_MATCHING_WITH_OTP
339
339
Value = FALSE
340
340
1. Restart the NPS Service.
341
341
@@ -376,6 +376,16 @@ If a user is running an older version of Microsoft Authenticator that doesn't su
376
376
377
377
Older versions of Microsoft Authenticator prompt users to tap and select a number rather than enter the number in Microsoft Authenticator. These authentications won't fail, but Microsoft highly recommends that users upgrade to the latest version of Microsoft Authenticator if they use Android versions prior to 6.2108.5654, or iOS versions prior to 6.5.82, so they can use number match.
378
378
379
+
Minimum Microsoft Authenticator version supporting number matching:
380
+
381
+
- Android: 6.2006.4198
382
+
- iOS: 6.4.12
383
+
384
+
Minimum Microsoft Authenticator version for number matching which prompts to enter a number:
385
+
386
+
- Android 6.2111.7701
387
+
- iOS 6.5.85
388
+
379
389
## Next steps
380
390
381
391
[Authentication methods in Azure Active Directory](concept-authentication-authenticator-app.md)
0 commit comments