Skip to content

Commit 55b7c29

Browse files
committed
[AzureAD-MFA] Incorporating PM feedback
1 parent 6f7861b commit 55b7c29

File tree

1 file changed

+7
-10
lines changed

1 file changed

+7
-10
lines changed

articles/active-directory/authentication/concept-mfa-licensing.md

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: multi-factor-authentication
66
ms.service: active-directory
77
ms.subservice: authentication
88
ms.topic: conceptual
9-
ms.date: 12/18/2019
9+
ms.date: 01/24/2020
1010

1111
ms.author: iainfou
1212
author: iainfoulds
@@ -16,7 +16,7 @@ ms.collection: M365-identity-device-management
1616
---
1717
# Features and licenses for Azure Multi-Factor Authentication
1818

19-
To protect user accounts in your organization, two-step verification should be used. This feature is especially important for accounts that have privileged access to resources. Basic two-step verification features are available to Office 365 and Azure Active Directory (Azure AD) administrators for no extra cost. If you want to upgrade the features for your admins or extend two-step verification to the rest of your users, you can purchase Azure Multi-Factor Authentication in several ways.
19+
To protect user accounts in your organization, multi-factor authentication should be used. This feature is especially important for accounts that have privileged access to resources. Basic multi-factor authentication features are available to Office 365 and Azure Active Directory (Azure AD) administrators for no extra cost. If you want to upgrade the features for your admins or extend multi-factor authentication to the rest of your users, you can purchase Azure Multi-Factor Authentication in several ways.
2020

2121
> [!IMPORTANT]
2222
> This article details the different ways that Azure Multi-Factor Authentication can be licensed and used. For specific details about pricing and billing, see the [Azure Multi-Factor Authentication pricing page](https://azure.microsoft.com/pricing/details/multi-factor-authentication/).
@@ -27,10 +27,11 @@ Azure Multi-Factor Authentication can be used, and licensed, in a few different
2727

2828
| If you're a user of | Capabilities and use cases |
2929
| --- | --- |
30-
| Azure AD Premium P1 | You can enable multi-factor authentication for select individual users, or use [Azure AD Conditional Access](../conditional-access/overview.md) to generate multi-factor authentication events for certain scenarios or events. |
31-
| Azure AD Premium P2 | Provides the Azure AD Premium P1 Multi-Factor Authentication features, but also adds [risk-based Conditional Access](../conditional-access/howto-conditional-access-policy-risk.md) that adapts to user's patterns and minimizes multi-factor authentication prompts. |
32-
| Office Premium, E3, or E5 | Enable multi-factor authentication on a per-user basis for every authentication request. There's no ability to control what events prompt for multi-factor authentication. Management is through the Office 365 or Microsoft 365 portal. For more information, see [secure Office 365 resources with two-step verification](https://support.office.com/article/Set-up-multi-factor-authentication-for-Office-365-users-8f0454b2-f51a-4d9c-bcde-2c48e41621c6). |
33-
| Azure AD free | Users assigned the *Azure AD Global Administrator* role can use two-step verification. This feature of the free tier makes sure the critical administrator accounts are protected by multi-factor authentication.<br />You can also use [security defaults](../fundamentals/concept-fundamentals-security-defaults.md) to enable multi-factor authentication for all users, every time an authentication request is made. You don't have granular control of enabled users or scenarios, but it does provide that additional security step. |
30+
| Azure AD Premium P1 | You can use [Azure AD Conditional Access](../conditional-access/overview.md) to prompt users for multi-factor authentication during certain scenarios or events to fit your business requirements. |
31+
| Azure AD Premium P2 | Provides the strongest security position and improved user experience. Adds [risk-based Conditional Access](../conditional-access/howto-conditional-access-policy-risk.md) to the Azure AD Premium P1 features that adapts to user's patterns and minimizes multi-factor authentication prompts. |
32+
| Office Premium, E3, or E5 | Limited ability to control what events prompt for multi-factor authentication. Azure Multi-Factor Authentication is either enabled or disabled for all users, for all sign-in events. Management is through the Office 365 portal. For more information, see [secure Office 365 resources with multi-factor authentication](https://support.office.com/article/Set-up-multi-factor-authentication-for-Office-365-users-8f0454b2-f51a-4d9c-bcde-2c48e41621c6). |
33+
| EMS E3 or E5, and Microsoft 365 E3 or E5 | EMS E3 or Microsoft 365 E3 (that includes EMS and Office 365), include Azure AD Premium P1. EMS E5 or Microsoft 365 E5 include Azure AD Premium P2. You can use the same Conditional Access features to provide multi-factor authentication to users. |
34+
| Azure AD free | You can use [security defaults](../fundamentals/concept-fundamentals-security-defaults.md) to enable multi-factor authentication for all users, every time an authentication request is made. You don't have granular control of enabled users or scenarios, but it does provide that additional security step.<br /> Even when security defaults aren't used to enable multi-factor authentication for everyone, users assigned the *Azure AD Global Administrator* role can be configured to use multi-factor authentication. This feature of the free tier makes sure the critical administrator accounts are protected by multi-factor authentication. |
3435

3536
## Feature comparison of versions
3637

@@ -42,13 +43,9 @@ The following table provides a list of the features that are available in the va
4243
| Mobile app as a second factor |||||
4344
| Phone call as a second factor | ||||
4445
| SMS as a second factor | ||||
45-
| App passwords for clients that don't support MFA | ||||
4646
| Admin control over verification methods | ||||
47-
| Protect non-admin accounts with MFA || |||
48-
| PIN mode | | | ||
4947
| Fraud alert | | | ||
5048
| MFA Reports | | | ||
51-
| One-Time Bypass | | | ||
5249
| Custom greetings for phone calls | | | ||
5350
| Custom caller ID for phone calls | | | ||
5451
| Trusted IPs | | | ||

0 commit comments

Comments
 (0)