Skip to content

Commit c7d676d

Browse files
authored
Merge pull request #251357 from MicrosoftDocs/main
9/13/2023 PM Publish
2 parents 3668a03 + cfc8fba commit c7d676d

File tree

186 files changed

+2946
-1637
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

186 files changed

+2946
-1637
lines changed

.openpublishing.redirection.active-directory.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1185,6 +1185,11 @@
11851185
"redirect_url": "/azure/role-based-access-control/change-history-report",
11861186
"redirect_document_id": true
11871187
},
1188+
{
1189+
"source_path_from_root": "/articles/active-directory/fundamentals/concept-fundamentals-mfa-get-started.md",
1190+
"redirect_url": "/azure/active-directory/authentication/concept-mfa-licensing",
1191+
"redirect_document_id": true
1192+
},
11881193
{
11891194
"source_path_from_root": "/articles/active-directory/conditional-access-azure-management.md",
11901195
"redirect_url": "/azure/active-directory/conditional-access/concept-conditional-access-cloud-apps",

articles/active-directory/authentication/concept-authentication-phone-options.md

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: authentication
88
ms.topic: conceptual
9-
ms.date: 09/12/2023
9+
ms.date: 08/23/2023
1010

1111
ms.author: justinha
1212
author: justinha
@@ -19,9 +19,9 @@ ms.collection: M365-identity-device-management
1919

2020
# Authentication methods in Azure Active Directory - phone options
2121

22-
Microsoft recommends users move away from using text message or voice calls for multifactor authentication (MFA). Modern authentication methods like [Microsoft Authenticator](concept-authentication-authenticator-app.md) are a recommended alternative. For more information, see [It's Time to Hang Up on Phone Transports for Authentication](https://aka.ms/hangup). Users can still verify themselves using a mobile phone or office phone as secondary form of authentication used for multifactor authentication (MFA) or self-service password reset (SSPR).
22+
Microsoft recommends users move away from using text messages or voice calls for multifactor authentication (MFA). Modern authentication methods like [Microsoft Authenticator](concept-authentication-authenticator-app.md) are a recommended alternative. For more information, see [It's Time to Hang Up on Phone Transports for Authentication](https://aka.ms/hangup). Users can still verify themselves using a mobile phone or office phone as secondary form of authentication used for multifactor authentication (MFA) or self-service password reset (SSPR).
2323

24-
You can [configure and enable users for SMS-based authentication](howto-authentication-sms-signin.md) for direct authentication using SMS. SMS sign-in is convenient for Frontline workers. With SMS sign-in, users don't need to know a username and password to access applications and services. The user instead enters their registered mobile phone number, receives a text message with a verification code, and enters that in the sign-in interface.
24+
You can [configure and enable users for SMS-based authentication](howto-authentication-sms-signin.md) for direct authentication using text message. Text messages are convenient for Frontline workers. With text messages, users don't need to know a username and password to access applications and services. The user instead enters their registered mobile phone number, receives a text message with a verification code, and enters that in the sign-in interface.
2525

2626
>[!NOTE]
2727
>Phone call verification isn't available for Azure AD tenants with trial subscriptions. For example, if you sign up for a trial license Microsoft Enterprise Mobility and Security (EMS), phone call verification isn't available. Phone numbers must be provided in the format *+CountryCode PhoneNumber*, for example, *+1 4251234567*. There must be a space between the country/region code and the phone number.
@@ -46,10 +46,14 @@ Microsoft doesn't guarantee consistent text message or voice-based Azure AD Mult
4646

4747
With text message verification during SSPR or Azure AD Multi-Factor Authentication, a text message is sent to the mobile phone number containing a verification code. To complete the sign-in process, the verification code provided is entered into the sign-in interface.
4848

49-
Android users can enable Rich Communication Services (RCS) on their devices. RCS offers encryption and other improvements over Simple Message Service (SMS). For Android, MFA text messages may be sent over RCS rather than SMS. The experience is similar to text message, but RCS messages have more Microsoft branding and a verified checkmark so users know they can trust the message.
49+
Text messages can be sent over channels such as Short Message Service (SMS), Rich Communication Services (RCS), or WhatsApp.
50+
51+
Android users can enable RCS on their devices. RCS offers encryption and other improvements over SMS. For Android, MFA text messages may be sent over RCS rather than SMS. The MFA text message is similar to SMS, but RCS messages have more Microsoft branding and a verified checkmark so users know they can trust the message.
5052

5153
:::image type="content" source="media/concept-authentication-methods/brand.png" alt-text="Screenshot of Microsoft branding in RCS messages.":::
5254

55+
Some users with phone numbers that have country codes belonging to India, Indonesia and New Zealand may receive their verification codes via WhatsApp. Like RCS, these messages are similar to SMS, but have more Microsoft branding and a verified checkmark. Only users that have WhatsApp will receive verification codes via this channel. To determine whether a user has WhatsApp, we silently attempt delivering them a message via the app using the phone number they already registered for text message verification and see if it's successfully delivered. If users don't have any internet connectivity or uninstall WhatsApp, they'll receive their verification codes via SMS. The phone number associated with Microsoft's WhatsApp Business Agent is: *+1 (217) 302 1989*.
56+
5357
### Phone call verification
5458

5559
With phone call verification during SSPR or Azure AD Multi-Factor Authentication, an automated voice call is made to the phone number registered by the user. To complete the sign-in process, the user is prompted to press # on their keypad.
@@ -78,13 +82,13 @@ If you have problems with phone authentication for Azure AD, review the followin
7882
* Ensure that the user has their phone turned on and that service is available in their area, or use alternate method.
7983
* User is blocked
8084
* Have an Azure AD administrator unblock the user in the Azure portal.
81-
* text message is not subscribed on the device.
82-
* Have the user change methods or activate text message on the device.
83-
* Faulty telecom providers such as no phone input detected, missing DTMF tones issues, blocked caller ID on multiple devices, or blocked text messages across multiple devices.
84-
* Microsoft uses multiple telecom providers to route phone calls and text messages for authentication. If you see any of the above issues, have a user attempt to use the method at least five times within 5 minutes and have that user's information available when contacting Microsoft support.
85+
* Text messaging platforms like SMS, RCS, or WhatsApp aren't subscribed on the device.
86+
* Have the user change methods or activate a text messaging platform on the device.
87+
* Faulty telecom providers, such as when no phone input is detected, missing DTMF tones issues, blocked caller ID on multiple devices, or blocked text messages across multiple devices.
88+
* Microsoft uses multiple telecom providers to route phone calls and text messages for authentication. If you see any of these issues, have a user attempt to use the method at least five times within 5 minutes and have that user's information available when contacting Microsoft support.
8589
* Poor signal quality.
8690
* Have the user attempt to log in using a wi-fi connection by installing the Authenticator app.
87-
* Or, use text message authentication instead of phone (voice) authentication.
91+
* Or use a text message instead of phone (voice) authentication.
8892

8993
* Phone number is blocked and unable to be used for Voice MFA
9094

articles/active-directory/authentication/how-to-mfa-registration-campaign.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ In addition to choosing who can be nudged, you can define how many days a user c
6262

6363
![Confirmation of approval](./media/how-to-nudge-authenticator-app/approved.png)
6464

65-
1. Authenticator app is now successfully set up as the users default sign-in method.
65+
1. Authenticator app is now successfully set up as the user's default sign-in method.
6666

6767
![Installation complete](./media/how-to-nudge-authenticator-app/finish.png)
6868

@@ -88,7 +88,7 @@ In addition to using the Azure portal, you can also enable the registration camp
8888

8989
To configure the policy using Graph Explorer:
9090

91-
1. Sign in to Graph Explorer and ensure youve consented to the **Policy.Read.All** and **Policy.ReadWrite.AuthenticationMethod** permissions.
91+
1. Sign in to Graph Explorer and ensure you've consented to the **Policy.Read.All** and **Policy.ReadWrite.AuthenticationMethod** permissions.
9292

9393
To open the Permissions panel:
9494

articles/active-directory/authentication/howto-mfa-mfasettings.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -206,7 +206,7 @@ The following table lists more numbers for different countries.
206206
| Vietnam | +84 2039990161 |
207207

208208
> [!NOTE]
209-
> When Azure AD Multi-Factor Authentication calls are placed through the public telephone network, sometimes the calls are routed through a carrier that doesn't support caller ID. Because of this, caller ID isn't guaranteed, even though Azure AD Multi-Factor Authentication always sends it. This applies both to phone calls and text messages provided by Azure AD Multi-Factor Authentication. If you need to validate that a text message is from Azure AD Multi-Factor Authentication, see [What SMS short codes are used for sending messages?](multi-factor-authentication-faq.yml#what-sms-short-codes-are-used-for-sending-sms-messages-to-my-users-).
209+
> When Azure AD Multi-Factor Authentication calls are placed through the public telephone network, sometimes the calls are routed through a carrier that doesn't support caller ID. Because of this, caller ID isn't guaranteed, even though Azure AD Multi-Factor Authentication always sends it. This applies both to phone calls and text messages provided by Azure AD Multi-Factor Authentication. If you need to validate that a text message is from Azure AD Multi-Factor Authentication, see [What short codes are used for sending messages?](multi-factor-authentication-faq.yml#what-short-codes-are-used-for-sending-text-messages-to-my-users-).
210210
211211
To configure your own caller ID number, complete the following steps:
212212

@@ -215,7 +215,7 @@ To configure your own caller ID number, complete the following steps:
215215
1. Select **Save**.
216216

217217
> [!NOTE]
218-
> When Azure AD Multi-Factor Authentication calls are placed through the public telephone network, sometimes the calls are routed through a carrier that doesn't support caller ID. Because of this, caller ID isn't guaranteed, even though Azure AD Multi-Factor Authentication always sends it. This applies both to phone calls and text messages provided by Azure AD Multi-Factor Authentication. If you need to validate that a text message is from Azure AD Multi-Factor Authentication, see [What SMS short codes are used for sending messages?](multi-factor-authentication-faq.yml#what-sms-short-codes-are-used-for-sending-sms-messages-to-my-users-).
218+
> When Azure AD Multi-Factor Authentication calls are placed through the public telephone network, sometimes the calls are routed through a carrier that doesn't support caller ID. Because of this, caller ID isn't guaranteed, even though Azure AD Multi-Factor Authentication always sends it. This applies both to phone calls and text messages provided by Azure AD Multi-Factor Authentication. If you need to validate that a text message is from Azure AD Multi-Factor Authentication, see [What short codes are used for sending messages?](multi-factor-authentication-faq.yml#what-short-codes-are-used-for-sending-text-messages-to-my-users-).
219219
220220
### Custom voice messages
221221

articles/active-directory/authentication/multi-factor-authentication-faq.yml

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ sections:
3434
* **Unique ID** (either user name or on-premises Multi-Factor Authentication Server ID)
3535
* **First and Last Name** (optional)
3636
* **Email Address** (optional)
37-
* **Phone Number** (when using a voice call or SMS authentication)
37+
* **Phone Number** (when using a voice call or text message authentication)
3838
* **Device Token** (when using mobile app authentication)
3939
* **Authentication Mode**
4040
* **Authentication Result**
@@ -49,27 +49,24 @@ sections:
4949
For more information, see [Data residency and customer data for Azure AD Multi-Factor Authentication](concept-mfa-data-residency.md).
5050
5151
- question: |
52-
What SMS short codes are used for sending SMS messages to my users?
52+
What short codes are used for sending text messages to my users?
5353
answer: |
54-
In the United States, we use the following SMS short codes:
54+
In the United States, we use the following short codes:
5555
5656
* *97671*
5757
* *69829*
5858
* *51789*
5959
* *99399*
6060
61-
In Canada, we use the following SMS short codes:
61+
In Canada, we use the following short codes:
6262
6363
* *759731*
6464
* *673801*
6565
66-
There's no guarantee of consistent SMS or voice-based Multi-Factor Authentication prompt delivery by the same number. In the interest of our users, we may add or remove short codes at any time as we make route adjustments to improve SMS deliverability.
66+
There's no guarantee of consistent text message or voice-based multifactor authentication prompt delivery by the same number. In the interest of our users, we may add or remove short codes at any time as we make route adjustments to improve text message deliverability.
6767
6868
We don't support short codes for countries or regions besides the United States and Canada.
6969
70-
## Billing
71-
Most billing questions can be answered by referring to either the [Multi-Factor Authentication Pricing page](https://azure.microsoft.com/pricing/details/multi-factor-authentication/) or the documentation for [Azure AD Multi-Factor Authentication versions and consumption plans](concept-mfa-licensing.md).
72-
7370
- question: |
7471
Does Azure AD Multi-Factor Authentication throttle user sign-ins?
7572
answer: |
@@ -135,7 +132,7 @@ sections:
135132
- question: |
136133
What should I tell my users to do if they don't receive a response on their phone?
137134
answer: |
138-
Have your users attempt up to five times in 5 minutes to get a phone call or SMS for authentication. Microsoft uses multiple providers for delivering calls and SMS messages. If this approach doesn't work, open a support case to troubleshoot further.
135+
Have your users attempt up to five times in 5 minutes to get a phone call or text message for authentication. Microsoft uses multiple providers for delivering calls and text messages. If this approach doesn't work, open a support case to troubleshoot further.
139136
140137
Third-party security apps may also block the verification code text message or phone call. If using a third-party security app, try disabling the protection, then request another MFA verification code be sent.
141138
@@ -168,7 +165,7 @@ sections:
168165
- question: |
169166
My users say that sometimes they don't receive the text message or the verification times out.
170167
answer: |
171-
Delivery of SMS messages aren't guaranteed because there are uncontrollable factors that might affect the reliability of the service. These factors include the destination country or region, the mobile phone carrier, and the signal strength.
168+
Delivery of text messages isn't guaranteed because uncontrollable factors might affect the reliability of the service. These factors include the destination country or region, the mobile phone carrier, and the signal strength.
172169
173170
Third-party security apps may also block the verification code text message or phone call. If using a third-party security app, try disabling the protection, then request another MFA verification code be sent.
174171

articles/active-directory/authentication/passwords-faq.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -95,25 +95,25 @@ sections:
9595
>
9696
> Users can attempt to validate their information (such as their phone number), but if they're unable to prove their identity five times within a 24-hour period, they're locked out for 24 hours.
9797
>
98-
> Users can try to validate a phone number, auth app, send a SMS, or validate security questions and answers only five times within an hour before they're locked out for 24 hours.
98+
> Users can try to validate a phone number, auth app, send a text message, or validate security questions and answers only five times within an hour before they're locked out for 24 hours.
9999
>
100100
> Users can send an email a maximum of 10 times within a 10 minute period before they're locked out for 24 hours.
101101
>
102102
> The counters are reset once a user resets their password.
103103
>
104104
>
105105
- question: |
106-
How long should I wait to receive an email, SMS, or phone call from password reset?
106+
How long should I wait to receive an email, text message, or phone call from password reset?
107107
answer: |
108-
> Emails, SMS messages, and phone calls should arrive in under a minute. The normal case is 5 to 20 seconds.
108+
> Emails, text messages, and phone calls should arrive in under a minute. The normal case is 5 to 20 seconds.
109109
> If you don't receive the notification in this time frame:
110110
> * Check your junk folder.
111111
> * Check that the number or email being contacted is the one you expect.
112112
> * Check that the authentication data in the directory is correctly formatted, for example, +1 4255551234 or *user\@contoso.com*.
113113
- question: |
114114
What languages are supported by password reset?
115115
answer: |
116-
> The password reset UI, SMS messages, and voice calls are localized in the same languages that are supported in Microsoft 365.
116+
> The password reset UI, text messages, and voice calls are localized in the same languages that are supported in Microsoft 365.
117117
>
118118
>
119119
- question: |
@@ -201,9 +201,9 @@ sections:
201201
>
202202
>
203203
- question: |
204-
How long are the email and SMS one-time passcodes valid?
204+
How long are the email and text message one-time passcodes valid?
205205
answer: |
206-
> The session lifetime for password reset is 15 minutes. From the start of the password reset operation, the user has 15 minutes to reset their password. The email and SMS one-time passcode are valid for 5 minutes during the password reset session.
206+
> The session lifetime for password reset is 15 minutes. From the start of the password reset operation, the user has 15 minutes to reset their password. The one-time passcodes are valid for 5 minutes during the password reset session.
207207
>
208208
>
209209
- question: |

articles/active-directory/cloud-infrastructure-entitlement-management/how-to-add-remove-user-to-group.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ This article describes how you can add or remove a new user for a group in Permi
2121
2222
## Add a user
2323

24-
1. Navigate to the [Microsoft Entra admin center](https://entra.microsoft.com/#home).
24+
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#home).
2525
1. From the Azure Active Directory tile, select **Go to Azure Active Directory**.
2626
1. From the navigation pane, select the **Groups** drop-down menu, then **All groups**.
2727
1. Select the group name for the group you want to add the user to.
@@ -37,7 +37,7 @@ This article describes how you can add or remove a new user for a group in Permi
3737

3838
## Remove a user
3939

40-
1. Navigate to the Microsoft [Entra admin center](https://entra.microsoft.com/#home).
40+
1. Sign in to the Microsoft [Entra admin center](https://entra.microsoft.com/#home).
4141
1. From the Azure Active Directory tile, select **Go to Azure Active Directory**.
4242
1. From the navigation pane, select the **Groups** drop-down menu, then **All groups**.
4343
1. Select the group name for the group you want to remove the user from.

0 commit comments

Comments
 (0)