You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/concept-authentication-methods.md
+13-15Lines changed: 13 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,24 +17,22 @@ ms.custom: contperfq4
17
17
18
18
# Customer intent: As an identity administrator, I want to understand what authentication options are available in Azure AD and how or why I can use them to improve and secure user sign-in events.
19
19
---
20
-
# What authentication methods and features are available in Azure Active Directory?
20
+
# What authentication and verification methods are available in Azure Active Directory?
21
21
22
22
As part of the sign-in experience for accounts in Azure Active Directory (Azure AD), there are different ways that a user can authenticate themselves. A username and password is the most common way a user would historically provide credentials. With modern authentication and security features in Azure AD, that basic password can be supplemented or replaced with additional authentication methods.
23
23
24
-
A user could choose to authenticate using one of the following authentication methods:
24
+
A user in Azure AD can choose to authenticate using one of the following authentication methods:
25
25
26
26
* Traditional username and password
27
27
* Microsoft Authenticator App passwordless sign-in
28
-
* OATH hardware token, such as FIDO2 security key
28
+
* OATH hardware token or FIDO2 security key
29
29
* SMS-based passwordless sign-in
30
30
31
-
Many accounts in Azure AD are enabled for self-service password reset (SSPR) or Azure Multi-Factor Authentication. These features include additional authentication methods such as a phone call or security questions.
31
+
Many accounts in Azure AD are enabled for self-service password reset (SSPR) or Azure Multi-Factor Authentication. These features include additional verification methods, such as a phone call or security questions. It's recommended that you require users to register multiple verification methods. When one method isn't available for a user, they can choose to authenticate with another method.
32
32
33
-
It's recommended that you require users to register multiple authentication methods. When an authentication method isn't available for a user, they can choose to authenticate with another method.
33
+
The following table outlines what authentication or verification methods are available for the different scenarios:
34
34
35
-
The following table outlines what authentication methods are available for the different scenarios:
36
-
37
-
|Authentication Method|Usage|
35
+
|Method|Usage|
38
36
| --- | --- |
39
37
|[Password](#password)| MFA and SSPR |
40
38
|[Microsoft Authenticator app](#microsoft-authenticator-app)| MFA and SSPR |
@@ -45,7 +43,7 @@ The following table outlines what authentication methods are available for the d
45
43
|[Email address](#email-address)| SSPR Only |
46
44
|[App passwords](#app-passwords)| MFA only in certain cases |
47
45
48
-
This article outlines these different authentication methods and any specific limitations or restrictions, such as what can be used for security questions.
46
+
This article outlines these different authentication and verification methods available in Azure AD and any specific limitations or restrictions.
49
47
50
48

51
49
@@ -57,7 +55,7 @@ Even if you use an authentication method such as [SMS-based sign-in](howto-authe
57
55
58
56
## Microsoft Authenticator app
59
57
60
-
With the Microsoft Authenticator app, users can authenticate passwordless during sign-in, or as an additional authentication / verification option during self-service password reset (SSPR) or Azure Multi-Factor Authentication events.
58
+
With the Microsoft Authenticator app, users can authenticate passwordless during sign-in, or as an additional verification option during self-service password reset (SSPR) or Azure Multi-Factor Authentication events.
61
59
62
60
The Authenticator app provides an additional level of security to your Azure AD work or school account or your Microsoft account and is available for [Android](https://go.microsoft.com/fwlink/?linkid=866594), [iOS](https://go.microsoft.com/fwlink/?linkid=866594), and [Windows Phone](https://www.microsoft.com/p/microsoft-authenticator/9nblgggzmcj6).
63
61
@@ -116,7 +114,7 @@ Users may have a combination of up to five OATH hardware tokens or authenticator
116
114
117
115
## Phone options
118
116
119
-
Users can authenticate using a mobile phone or office phone. Phone authentication is a secondary form of authentication used during Azure Multi-Factor Authentication or self-service password reset (SSPR). For direct authentication using text message, you can [Configure and enable users for SMS-based authentication(preview)](howto-authentication-sms-signin.md).
117
+
Users can verify themselves using a mobile phone or office phone. Phone authentication is a secondary form of authentication used during Azure Multi-Factor Authentication or self-service password reset (SSPR). For direct authentication using text message, you can [Configure and enable users for SMS-based authentication(preview)](howto-authentication-sms-signin.md).
120
118
121
119
With the mobile phone authentication option, a text message is sent with a verification code to enter into the sign-in interface. Both mobile and office phones can also receive a phone call that prompts the user to enter their defined code to complete the sign-in process.
122
120
@@ -172,9 +170,9 @@ If you have problems with phone authentication for Azure AD, review the followin
172
170
173
171
## Security questions
174
172
175
-
Security questions aren't used as an authentication method during a sign-in event. Instead, security questions can be used during the self-service password reset (SSPR) process to confirm who you are. Administrator accounts can't use security questions as an authentication / verification method with SSPR.
173
+
Security questions aren't used as an authentication method during a sign-in event. Instead, security questions can be used during the self-service password reset (SSPR) process to confirm who you are. Administrator accounts can't use security questions as verification method with SSPR.
176
174
177
-
When users register for SSPR, they're prompted to choose the authentication / verification methods to use. If they choose to use security questions, they pick from a set of questions to prompt for and then provide their own answers.
175
+
When users register for SSPR, they're prompted to choose the authentication methods to use. If they choose to use security questions, they pick from a set of questions to prompt for and then provide their own answers.
178
176
179
177

180
178
@@ -185,7 +183,7 @@ Security questions can be less secure than other methods because some people mig
185
183
186
184
### Predefined questions
187
185
188
-
The following predefined security questions are available for use as an authentication method with SSPR. All of these security questions are translated and localized into the full set of Office 365 languages based on the user's browser locale:
186
+
The following predefined security questions are available for use as an verification method with SSPR. All of these security questions are translated and localized into the full set of Office 365 languages based on the user's browser locale:
189
187
190
188
* In what city did you meet your first spouse/partner?
191
189
* In what city did your parents meet?
@@ -242,7 +240,7 @@ For both default and custom security questions, the following requirements and l
242
240
243
241
## Email address
244
242
245
-
An email address can't be used as a direct authentication method. Email address is only available as an authentication / verification option for self-service password reset (SSPR). When email address is selected during SSPR, an email is sent to the user to complete the authentication / verification process.
243
+
An email address can't be used as a direct authentication method. Email address is only available as an verification option for self-service password reset (SSPR). When email address is selected during SSPR, an email is sent to the user to complete the authentication / verification process.
246
244
247
245
During registration for SSPR, a user provides the email address to use. It's recommended that they use a different email account than their corporate account to make sure they can access it during SSPR.
0 commit comments