You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory-b2c/identity-provider-adfs2016-custom.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -165,7 +165,7 @@ Now that you have a button in place, you need to link it to an action. The actio
165
165
To use ADFS as an identity provider in Azure AD B2C, you need to create an ADFS Relying Party Trust with the Azure AD B2C SAML metadata. The following example shows a URL address to the SAML metadata of an Azure AD B2C technical profile:
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/concept-registration-mfa-sspr-combined.md
+14-22Lines changed: 14 additions & 22 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,40 +1,39 @@
1
1
---
2
2
title: Combined registration for SSPR and MFA - Azure Active Directory
3
-
description: Azure AD Multi-Factor Authentication and self-service password reset registration (preview)
3
+
description: Azure AD Multi-Factor Authentication and self-service password reset registration
4
4
5
5
services: active-directory
6
6
ms.service: active-directory
7
7
ms.subservice: authentication
8
8
ms.topic: conceptual
9
-
ms.date: 03/06/2020
9
+
ms.date: 04/15/2020
10
10
11
11
ms.author: iainfou
12
12
author: iainfoulds
13
13
manager: daveba
14
-
ms.reviewer: sahenry
14
+
ms.reviewer: rhicock
15
15
16
16
ms.collection: M365-identity-device-management
17
17
---
18
-
# Combined security information registration (preview)
18
+
# Combined security information registration overview
19
19
20
20
Before combined registration, users registered authentication methods for Azure Multi-Factor Authentication and self-service password reset (SSPR) separately. People were confused that similar methods were used for Multi-Factor Authentication and SSPR but they had to register for both features. Now, with combined registration, users can register once and get the benefits of both Multi-Factor Authentication and SSPR.
21
21
22
+
This article outlines what combined security registration is. To get started with combined security registration, see the following article:

23
28
24
29
Before enabling the new experience, review this administrator-focused documentation and the user-focused documentation to ensure you understand the functionality and effect of this feature. Base your training on the [user documentation](../user-help/user-help-security-info-overview.md) to prepare your users for the new experience and help to ensure a successful rollout.
25
30
26
31
Azure AD combined security information registration is not currently available to national clouds like Azure US Government, Azure Germany, or Azure China 21Vianet.
27
32
28
-
||
29
-
| --- |
30
-
| Combined security information registration for Multi-Factor Authentication and Azure Active Directory (Azure AD) self-service password reset is a public preview feature of Azure AD. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).|
31
-
||
32
-
33
33
> [!IMPORTANT]
34
34
> Users who are enabled for both the original preview and the enhanced combined registration experience will see the new behavior. Users who are enabled for both experiences will see only the new My Profile experience. The new My Profile aligns with the look and feel of combined registration and provides a seamless experience for users. Users can see My Profile by going to [https://myprofile.microsoft.com](https://myprofile.microsoft.com).
35
-
36
-
> [!NOTE]
37
-
> You might encounter an error message while trying to access the Security info option. For example, "Sorry, we can't sign you in". In this case, confirm that you don't have any configuration or group policy object that blocks third-party cookies on the web browser.
35
+
>
36
+
> You might encounter an error message while trying to access the Security info option. For example, "Sorry, we can't sign you in". In this case, confirm that you don't have any configuration or group policy object that blocks third-party cookies on the web browser.
38
37
39
38
My Profile pages are localized based on the language settings of the computer accessing the page. Microsoft stores the most recent language used in the browser cache, so subsequent attempts to access the pages will continue to render in the last language used. If you clear the cache, the pages will re-render. If you want to force a specific language, you can add `?lng=<language>` to the end of the URL, where `<language>` is the code of the language you want to render.
40
39
@@ -74,7 +73,6 @@ As we continue to add more authentication methods to Azure AD, those methods wil
74
73
There are two modes of combined registration: interrupt and manage.
75
74
76
75
-**Interrupt mode** is a wizard-like experience, presented to users when they register or refresh their security info at sign-in.
77
-
78
76
-**Manage mode** is part of the user profile and allows users to manage their security info.
79
77
80
78
For both modes, users who have previously registered a method that can be used for Multi-Factor Authentication will need to perform Multi-Factor Authentication before they can access their security info.
@@ -136,14 +134,8 @@ A user who has previously set up at least one method that can be used for Multi-
136
134
137
135
## Next steps
138
136
139
-
[Force users to re-register authentication methods](howto-mfa-userdevicesettings.md#manage-user-authentication-options)
140
-
141
-
[Enable combined registration in your tenant](howto-registration-mfa-sspr-combined.md)
142
-
143
-
[SSPR and MFA usage and insights reporting](howto-authentication-methods-usage-insights.md)
144
-
145
-
[Available methods for Multi-Factor Authentication and SSPR](concept-authentication-methods.md)
137
+
To get started, see the tutorials to [enable self-service password reset](tutorial-enable-sspr.md) and [enable Azure Multi-Factor Authentication](tutorial-enable-azure-mfa.md).
Learn how to [enable combined registration in your tenant](howto-registration-mfa-sspr-combined.md) or [force users to re-register authentication methods](howto-mfa-userdevicesettings.md#manage-user-authentication-options).
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/howto-authentication-passwordless-phone.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -38,7 +38,7 @@ Instead of seeing a prompt for a password after entering a username, a person wh
38
38
39
39
### Enable the combined registration experience
40
40
41
-
Registration features for passwordless authentication methods rely on the combined registration preview. Follow the steps in the article [Enable combined security information registration (preview)](howto-registration-mfa-sspr-combined.md), to enable the combined registration preview.
41
+
Registration features for passwordless authentication methods rely on the combined registration feature. Follow the steps in the article [Enable combined security information registration](howto-registration-mfa-sspr-combined.md), to enable combined registration.
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/howto-authentication-passwordless-security-key.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -45,7 +45,7 @@ Hybrid Azure AD joined devices must run Windows 10 Insider Build 18945 or newer.
45
45
46
46
### Enable the combined registration experience
47
47
48
-
Registration features for passwordless authentication methods rely on the combined registration preview. Follow the steps in the article [Enable combined security information registration (preview)](howto-registration-mfa-sspr-combined.md), to enable the combined registration preview.
48
+
Registration features for passwordless authentication methods rely on the combined registration feature. Follow the steps in the article [Enable combined security information registration (preview)](howto-registration-mfa-sspr-combined.md), to enable combined registration.
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/howto-mfa-getstarted.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -141,7 +141,7 @@ A text message that contains a verification code is sent to the user, the user i
141
141
142
142
## Plan registration policy
143
143
144
-
Administrators must determine how users will register their methods. Organizations should [enable the new combined registration experience](howto-registration-mfa-sspr-combined.md) for Azure MFA and self-service password reset (SSPR). SSPR allows users to reset their password in a secure way using the same methods they use for multi-factor authentication. We recommend this combined registration, currently in public preview, because it's a great experience for users, with the ability to register once for both services. Enabling the same methods for SSPR and Azure MFA will allow your users to be registered to use both features.
144
+
Administrators must determine how users will register their methods. Organizations should [enable the new combined registration experience](howto-registration-mfa-sspr-combined.md) for Azure MFA and self-service password reset (SSPR). SSPR allows users to reset their password in a secure way using the same methods they use for multi-factor authentication. We recommend this combined registration because it's a great experience for users, with the ability to register once for both services. Enabling the same methods for SSPR and Azure MFA will allow your users to be registered to use both features.
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/howto-registration-mfa-sspr-combined-troubleshoot.md
+12-17Lines changed: 12 additions & 17 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,29 +1,24 @@
1
1
---
2
2
title: Troubleshoot combined registration - Azure Active Directory
3
-
description: Troubleshoot Azure AD Multi-Factor Authentication and self-service password reset combined registration (preview)
3
+
description: Troubleshoot Azure AD Multi-Factor Authentication and self-service password reset combined registration
4
4
5
5
services: active-directory
6
6
ms.service: active-directory
7
7
ms.subservice: authentication
8
8
ms.topic: troubleshooting
9
-
ms.date: 11/21/2019
9
+
ms.date: 04/15/2020
10
10
11
11
ms.author: iainfou
12
12
author: iainfoulds
13
13
manager: daveba
14
-
ms.reviewer: sahenry
14
+
ms.reviewer: rhicock
15
15
16
16
ms.collection: M365-identity-device-management
17
17
---
18
-
# Troubleshooting combined security information registration (preview)
18
+
# Troubleshooting combined security information registration
19
19
20
20
The information in this article is meant to guide admins who are troubleshooting issues reported by users of the combined registration experience.
21
21
22
-
||
23
-
| --- |
24
-
| Combined security information registration for Azure Multi-Factor Authentication and Azure Active Directory (Azure AD) self-service password reset is a public preview feature of Azure AD. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/).|
25
-
||
26
-
27
22
## Audit logs
28
23
29
24
The events logged for combined registration are in the Authentication Methods category in the Azure AD audit logs.
@@ -48,25 +43,25 @@ The following table lists all audit events generated by combined registration:
48
43
49
44
| Symptom | Troubleshooting steps |
50
45
| --- | --- |
51
-
| I’m not seeing the methods I expected to see. | 1. Check if the user has an Azure AD admin role. If yes, view the SSPR admin policy differences. <br> 2. Determine whether the user is being interrupted because of Multi-Factor Authentication registration enforcement or SSPR registration enforcement. See the [flowchart](../../active-directory/authentication/concept-registration-mfa-sspr-combined.md#combined-registration-modes) under "Combined registration modes" to determine which methods should be shown. <br> 3. Determine how recently the Multi-Factor Authentication or SSPR policy was changed. If the change was recent, it might take some time for the updated policy to propagate.|
46
+
| I'm not seeing the methods I expected to see. | 1. Check if the user has an Azure AD admin role. If yes, view the SSPR admin policy differences. <br> 2. Determine whether the user is being interrupted because of Multi-Factor Authentication registration enforcement or SSPR registration enforcement. See the [flowchart](../../active-directory/authentication/concept-registration-mfa-sspr-combined.md#combined-registration-modes) under "Combined registration modes" to determine which methods should be shown. <br> 3. Determine how recently the Multi-Factor Authentication or SSPR policy was changed. If the change was recent, it might take some time for the updated policy to propagate.|
52
47
53
48
## Troubleshooting manage mode
54
49
55
50
| Symptom | Troubleshooting steps |
56
51
| --- | --- |
57
-
| I don’t have the option to add a particular method. | 1. Determine whether the method is enabled for Multi-Factor Authentication or for SSPR. <br> 2. If the method is enabled, save the policies again and wait 1-2 hours before testing again. <br> 3. If the method is enabled, ensure that the user hasn’t already set up the maximum number of that method that they're allowed to set up.|
52
+
| I don't have the option to add a particular method. | 1. Determine whether the method is enabled for Multi-Factor Authentication or for SSPR. <br> 2. If the method is enabled, save the policies again and wait 1-2 hours before testing again. <br> 3. If the method is enabled, ensure that the user hasn't already set up the maximum number of that method that they're allowed to set up.|
58
53
59
54
## Disable combined registration
60
55
61
56
When a user registers a phone number and/or mobile app in the new combined experience, our service stamps a set of flags (StrongAuthenticationMethods) for those methods on that user. This functionality allows the user to perform Multi-Factor Authentication with those methods whenever Multi-Factor Authentication is required.
62
57
63
58
If an admin enables the preview, users register through the new experience, and then the admin disables the preview, users might unknowingly be registered for Multi-Factor Authentication also.
64
59
65
-
If a user who has completed combined registration goes to the current self-service password reset (SSPR) registration page at [https://aka.ms/ssprsetup](https://aka.ms/ssprsetup), the user will be prompted to perform Multi-Factor Authentication before they can access that page. This step is expected from a technical standpoint, but it's new for users who were previously registered for SSPR only. Though this extra step does improve the user’s security posture by providing another level of security, admins might want to roll back their users so that they're no longer able to perform Multi-Factor Authentication.
60
+
If a user who has completed combined registration goes to the current self-service password reset (SSPR) registration page at [https://aka.ms/ssprsetup](https://aka.ms/ssprsetup), the user will be prompted to perform Multi-Factor Authentication before they can access that page. This step is expected from a technical standpoint, but it's new for users who were previously registered for SSPR only. Though this extra step does improve the user's security posture by providing another level of security, admins might want to roll back their users so that they're no longer able to perform Multi-Factor Authentication.
66
61
67
62
### How to roll back users
68
63
69
-
If you, as an admin, want to reset a user's Multi-Factor Authentication settings, you can use the PowerShell script provided in the next section. The script will clear the StrongAuthenticationMethods property for a user’s mobile app and/or phone number. If you run this script for your users, they'll need to re-register for Multi-Factor Authentication if they need it. We recommend testing rollback with one or two users before rolling back all affected users.
64
+
If you, as an admin, want to reset a user's Multi-Factor Authentication settings, you can use the PowerShell script provided in the next section. The script will clear the StrongAuthenticationMethods property for a user's mobile app and/or phone number. If you run this script for your users, they'll need to re-register for Multi-Factor Authentication if they need it. We recommend testing rollback with one or two users before rolling back all affected users.
70
65
71
66
The steps that follow will help you roll back a user or group of users.
72
67
@@ -147,16 +142,16 @@ In a PowerShell window, run the following command, providing the script and user
147
142
148
143
`<script location> -path <user file location>`
149
144
150
-
### Disable the preview experience
145
+
### Disable the updated experience
151
146
152
-
To disable the preview experience for your users, complete these steps:
147
+
To disable the updated experience for your users, complete these steps:
153
148
154
149
1. Sign in to the Azure portal as a user administrator.
155
150
2. Go to **Azure Active Directory** > **User settings** > **Manage settings for access panel preview features**.
156
151
3. Under **Users can use preview features for registering and managing security info**, set the selector to **None**, and then select **Save**.
157
152
158
-
Users will no longer be prompted to register by using the preview experience.
153
+
Users will no longer be prompted to register by using the updated experience.
159
154
160
155
## Next steps
161
156
162
-
*[Learn more about the public preview of combined registration for self-service password reset and Azure Multi-Factor Authentication](concept-registration-mfa-sspr-combined.md)
157
+
*[Learn more about combined registration for self-service password reset and Azure Multi-Factor Authentication](concept-registration-mfa-sspr-combined.md)
0 commit comments