Skip to content

Commit 7e3b6fd

Browse files
committed
[AzureAD] Add anchor links, updated OATH token screenshot
1 parent 22c6ba6 commit 7e3b6fd

File tree

2 files changed

+20
-18
lines changed

2 files changed

+20
-18
lines changed

articles/active-directory/authentication/concept-authentication-methods.md

Lines changed: 20 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -32,14 +32,14 @@ Many accounts in Azure AD are enabled for self-service password reset (SSPR) or
3232

3333
|Authentication Method|Usage|
3434
| --- | --- |
35-
| Password | MFA and SSPR |
36-
| Microsoft Authenticator app | MFA and SSPR |
37-
| OATH Hardware token | Public preview for MFA and SSPR |
38-
| SMS | MFA and SSPR |
39-
| Voice call | MFA and SSPR |
40-
| Security questions | SSPR Only |
41-
| Email address | SSPR Only |
42-
| App passwords | MFA only in certain cases |
35+
| [Password](#password) | MFA and SSPR |
36+
| [Microsoft Authenticator app](#microsoft-authenticator-app) | MFA and SSPR |
37+
| [OATH Hardware token](#oath-hardware-tokens-preview) | Public preview for MFA and SSPR |
38+
| [SMS](#phone-options) | MFA and SSPR |
39+
| [Voice call](#phone-options) | MFA and SSPR |
40+
| [Security questions](#security-questions) | SSPR Only |
41+
| [Email address](#email-address) | SSPR Only |
42+
| [App passwords](#app-passwords) | MFA only in certain cases |
4343

4444
This article outlines these different authentication methods and any specific limitations or restrictions, such as what can be used for security questions.
4545

@@ -49,11 +49,11 @@ This article outlines these different authentication methods and any specific li
4949

5050
An Azure AD password is often one of the primary authentication methods. You can't disable the password authentication method.
5151

52-
Even if you use an authentication methods such as SMS-based sign-in when the user doesn't use their password to sign, a password remains as an available authentication method.
52+
Even if you use an authentication method such as SMS-based sign-in when the user doesn't use their password to sign, a password remains as an available authentication method.
5353

5454
## Microsoft Authenticator app
5555

56-
With the Microsoft Authenticator app, users can authenticate passwordless during sign in, or as an additional authentication / verification option during self-service password reset of Azure Multi-Factor Authentication events.
56+
With the Microsoft Authenticator app, users can authenticate passwordless during sign-in, or as an additional authentication / verification option during self-service password reset of Azure Multi-Factor Authentication events.
5757

5858
The Authenticator app provides an additional level of security to your Azure AD work or school account or your Microsoft account and is available for [Android](https://go.microsoft.com/fwlink/?linkid=866594), [iOS](https://go.microsoft.com/fwlink/?linkid=866594), and [Windows Phone](https://www.microsoft.com/p/microsoft-authenticator/9nblgggzmcj6).
5959

@@ -80,11 +80,13 @@ Users may have a combination of up to five OATH hardware tokens or authenticator
8080
>
8181
> When two methods are required, users can reset using either a notification or verification code in addition to any other enabled methods.
8282
83-
## OATH hardware tokens (public preview)
83+
## OATH hardware tokens (preview)
8484

85-
OATH is an open standard that specifies how one-time password (OTP) codes are generated. Azure AD supports the use of OATH-TOTP SHA-1 tokens of the 30-second or 60-second variety. Customers can purchase these tokens from the vendor of their choice. Secret keys are limited to 128 characters, which may not be compatible with all tokens. The secret key can only contain the characters *a-z* or *A-Z* and digits *1-7*, and must be encoded in *Base32*. OATH hardware tokens in Azure AD are currently in preview. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
85+
OATH is an open standard that specifies how one-time password (OTP) codes are generated. Azure AD supports the use of OATH-TOTP SHA-1 tokens of the 30-second or 60-second variety. Customers can purchase these tokens from the vendor of their choice. Secret keys are limited to 128 characters, which may not be compatible with all tokens. The secret key can only contain the characters *a-z* or *A-Z* and digits *1-7*, and must be encoded in *Base32*.
8686

87-
![Uploading OATH tokens to the MFA OATH tokens blade](media/concept-authentication-methods/mfa-server-oath-tokens-azure-ad.png)
87+
OATH hardware tokens in Azure AD are currently in preview. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).
88+
89+
![Uploading OATH tokens to the MFA OATH tokens window](media/concept-authentication-methods/mfa-server-oath-tokens-azure-ad.png)
8890

8991
Once tokens are acquired they must be uploaded in a comma-separated values (CSV) file format including the UPN, serial number, secret key, time interval, manufacturer, and model as shown in the following example:
9092

@@ -156,7 +158,7 @@ If you have problems with phone authentication for Azure AD, review the followin
156158
* SMS is not subscribed on the device.
157159
* Have the user change methods or activate SMS on the device.
158160
* Faulty telecom providers such as no phone input detected, missing DTMF tones issues, blocked caller ID on multiple devices, or blocked SMS across multiple devices.
159-
* Microsoft uses multiple telecom providers to route phone calls and SMS messages for authentication. If you see any of the above issues, have a user attempt to use the method at least 5 times within 5 minutes and have that user's information available when contacting Microsoft support.
161+
* Microsoft uses multiple telecom providers to route phone calls and SMS messages for authentication. If you see any of the above issues, have a user attempt to use the method at least five times within 5 minutes and have that user's information available when contacting Microsoft support.
160162

161163
## Security questions
162164

@@ -167,7 +169,7 @@ When users register for SSPR, they're prompted to choose the authentication / ve
167169
> [!NOTE]
168170
> Security questions are stored privately and securely on a user object in the directory and can only be answered by users during registration. There's no way for an administrator to read or modify a user's questions or answers.
169171
170-
Security questions can be less secure than other methods because some people might know the answers to another user's questions. If you use security questions with SSPR, it's recommend to use them in conjunction with another method. A user can be prompted to use the Microsoft Authenticator App or phone authentication to verify their identity during the SSPR process, and choose security questions only if they don't have their phone or registered device with them.
172+
Security questions can be less secure than other methods because some people might know the answers to another user's questions. If you use security questions with SSPR, it's recommended to use them in conjunction with another method. A user can be prompted to use the Microsoft Authenticator App or phone authentication to verify their identity during the SSPR process, and choose security questions only if they don't have their phone or registered device with them.
171173

172174
### Predefined questions
173175

@@ -187,7 +189,7 @@ The following predefined security questions are available for use as an authenti
187189
* What is your favorite food?
188190
* What is your maternal grandmother's first and last name?
189191
* What is your mother's middle name?
190-
* What is your oldest sibling's birthday month and year? (e.g. November 1985)
192+
* What is your oldest sibling's birthday month and year? (for example, November 1985)
191193
* What is your oldest sibling's middle name?
192194
* What is your paternal grandfather's first and last name?
193195
* What is your youngest sibling's middle name?
@@ -230,9 +232,9 @@ For both default and custom security questions, the following requirements and l
230232

231233
An email address can't be used as a direct authentication method. Email address is only available as an authentication / verification option for self-service password reset (SSPR). When email address is selected during SSPR, an email is sent to the user to complete the authentication / verification process.
232234

233-
During registration for SSPR, a user provides the email address to use. It's recommended that they use an a different email account than their corporate account to make sure they can access it during SSPR.
235+
During registration for SSPR, a user provides the email address to use. It's recommended that they use a different email account than their corporate account to make sure they can access it during SSPR.
234236

235-
## App Passwords
237+
## App passwords
236238

237239
Certain older, non-browser apps don't understand pauses or breaks in the authentication process. If a user is enabled for multi-factor authentication and attempts to use one of these older, non-browser apps, they usually can't successfully authenticate. An app password allows users to continue to successfully authenticate with older, non-browser apps without interruption.
238240

-16.2 KB
Loading

0 commit comments

Comments
 (0)