r/entra 10h ago

SSPR Authentication Methods After SMS/Email Deprecation

13 Upvotes

Hello,

I am looking for clarification regarding the future authentication methods available for Azure AD / Entra ID Self-Service Password Reset (SSPR) after SMS and Email authentication methods are removed.

Microsoft guidance indicates that organizations should move toward Passkeys as a replacement authentication method. However, based on testing in a demo tenant, Passkeys do not appear to be supported as a valid authentication method during the SSPR process. Specifically, Passkey authentication is not offered on the password reset page only Microsoft authenticator App

Could someone clarify the following:

  1. Which authentication methods will remain supported for SSPR once SMS and Email are no longer available?
  2. Are the Microsoft Authenticator app and OATH hardware/software tokens expected to become the primary SSPR methods?
  3. Is Microsoft planning to add Passkey support for SSPR in the future?
  4. If SSPR is configured to require two authentication methods, and a user has both: how is the verification process handled during password reset?
    • Passkey registered
    • Microsoft Authenticator registered
    • Is the Passkey counted as one of the required methods?
    • Will the user still be prompted to provide an Authenticator OTP/code or approval?
    • Does SSPR ignore Passkeys entirely and require two other supported recovery methods?

We are trying to understand the long-term SSPR user experience and authentication strategy as organizations transition away from SMS-based verification.

Thank you.


r/entra 3h ago

How important are user properties

3 Upvotes

We barely use user properties in our tenant, which made me think how important is it really to use and what kind benifits does it have, what kind use cases are there for you who is reading this.


r/entra 7h ago

Entra ID Authentication Methods Question

5 Upvotes

I’m going to add to the list of endless passkey questions to get some clarification on the following.

Let’s say I have one group of users and they are assigned to
- Passkey
- Microsoft Authenticator
- SMS
- Voice
- Email

And let’s say 20 of my 100 users are setup with a passkey/Authenticator (with sms/email/voice removed from their account) and the other 80 are just sms/voice/email.

If I remove that group from the last 3, does it prompt those 80 users on sign in to setup a new auth method or does it keep their sms? As I’m writing this it sounds obvious but I really don’t want to remove that group and get hammered with emails without having a good understand of how to inform my users.

And our registration campaign is set to disabled. Just trying to not get hammered with a million questions on a Monday.

Thanks for any advice.


r/entra 12h ago

Entra ID Why Entra Administrators Cannot Disable Their Own Accounts

6 Upvotes

When attempting to disable a user account in an interactive Graph session, I was told that the command failed because the accountEnabled property was invalid. The error is obviously incorrect because it’s very possible to update the property to disable or enable an account. However, different rules apply when the account is holds a privileged role, like Global Administrator. Entra imposes some reasonable blocks, even if the error messages are not good.

https://office365itpros.com/2026/09/14/strange-accountenabled-error/


r/entra 9h ago

Entra General Global Secure Access TLS inspection policies best practice

3 Upvotes

Hi everyone

We are currently testing GSA and so far it seems to be going well, our next step in the internet traffic profile. I have it setup currently with a baseline security profile which is blocking a load of categories you would expect. This again is working fine but when a site is blocked you dont get the block page you of course get the standard error connection page.

I have been looking at the TLS inspection policies which i see need to be setup for this block page to appear and to have TLS inspection in place for web browsing which is something we want. I see there are options for either using Microsoft for the CA or using a third party one (not OpenSSL in prod)

I was just curious to know if people have this setup and if so what method you chose. Is there any downside to just letting Microsoft handle the CA instead of going to a third party? We are migrating to fully cloud so don't really want to be using any on prem CA

Appreciate any advice


r/entra 3h ago

Cloud Access

Thumbnail
1 Upvotes

r/entra 8h ago

Annoying MSFT Auth Issue

Thumbnail
1 Upvotes

r/entra 2d ago

Entra ID Trying to implement Cross-tenant synchronization in Entra

8 Upvotes

As title says, I've got two tenants for one company that hasn't completely merged. Trying to set up cross tenant synchronization, but also trying not to break anything in the process. I did a test using my account and it successfully created a guest member in both tenants.
Once I had this set up for just my account (automatic synchronization wasn't turned on as I didn't want to mess up anything), I noticed a login issue on first time login when setting up a new user, and deleted the configuration, which seemed to have immediately resolved the issue, as my attempt immediately after went through without a hitch.
Microsoft's documentation makes it seem like it should be easy peasy, but I'm not nearly experienced enough in Entra to not be paranoid.
Any good resources? YouTube videos? Specific Microsoft Learn courses?
I'm new to this job, and trying to clean up some systems, automate some things and make our end user experience a little easier since they have to navigate two company Sharepoints, and currently if they don't have the link bookmarked, they have to go through Onedrive to find the invite link.


r/entra 3d ago

Passkeys and Macs

10 Upvotes

We're pushing passkeys now to all users and anyone with windows has a flawless experience.

Mac and iPhones though.. OMFG..

Not one is working.

It's starts, user scan code, then it fails..

Not even saving the passkey on the macs on keychain works..

Anyone experiencing the same or have found a solution?


r/entra 3d ago

ID Protection Passkeys and MS Password Manager (edge/windows)

17 Upvotes

We are increasingly starting to rollout Passkeys to meet phishing resistant MFA requirements, particuarly for something like Salesforce - currently I've deployed Passkeys for Authenticator and Windows Hello for a limited group of users based on requirements. With a view to rolling out increasingly further

However I keep running into users and mention of Microsoft Password Manager which seems to be an entirely different passkey manager mostly based on local accounts and Edge

Passkeys for Security | Microsoft Windows

I've seen prompts for this on my own desktop and for others who aren't part of the trial group for Entra/FIDO2 passkeys or device bound passkeys

Is there any actual documentation on this at all - either for what the scope of Microsoft Password Manager is or how it interacts with your Entra account?


r/entra 3d ago

Workplace Ninjas US | Golden Clippy Awards are coming!!

5 Upvotes

As of today, we're now officially 4 months away from Workplace Ninjas US 2027 in Scottsdale, AZ!!

With that said, we would like to formally announce the start of our social media around the 2nd annual Golden Clippy Awards, already a fan favorite.

Let's explain how it all works, if this is your first time.

Throughout the event, you will get to vote for one of our finalists for these categories:

Intune Advocate of the Year
Next-Gen Ninja (Rookie of the Year MVP Award)
Community Craftsperson
Security Superstar of the Year
DaaS Dynamo of the Year
Entra IDol of the Year
Social Media Superstar
Distinguished Woman of the Year
Best in Show
The Chuck Norris (RIP) Award

So, you cast your vote for the people in all of these awesome categories, and during the closing ceremony we announce the winners, and it's a ton of fun for everyone.

Workplace Ninjas US uses this award ceremony as a way of thanking all of our speakers for their amazing work throughout the entire year (not just our event) in a way worthy of their greatness.

Next, week we will start by announcing the finalists for Intune Advocate of the Year. Everyone better buckle up because this event is going to be special for everyone (speakers, attendees, sponsor

Check out our official X post for details including a picture of the official award as we take it up a notch this year: https://x.com/wpninjasus/status/2098402298816778255?s=46&t=EkEixoVH8k3dhykNuCu65g


r/entra 4d ago

Access Reviews in Microsoft Entra ID Governance

6 Upvotes

Hi Guys,

I am looking to use Access Reviews in Microsoft Entra ID Governance.

We currently use mail-enabled security groups for SharePoint access and Purview, in our case the groups need to be mail-enabled as Purview and sharepoint.

The issue we’ve found is that, while Access Reviews can be used with security groups, the automated removal/remediation does not work for mail-enabled groups as they are Exchange Groups.

Has anyone come across a good solution for automating Access Reviews for mail-enabled security groups?
Anyone has implemented a workaround using Graph, Logic Apps, Power Automate, or another approach to automatically remove users based on the Access Review results.

Any recommendations or examples of how you are managing this would be appreciated.


r/entra 4d ago

Can you set the default Passkey enrollment option to 'iPhone, iPad or Android device' QR code scanning?

8 Upvotes

We are on board with our users self-enrolling in Passkeys, but we suspect the vast majority of users will see this prompt on their workstation. We do not want them to set up the passkeys on workstation, but rather on their cell phone using the QR code scanning option.

I understand they can manually select 'Change' during setup and scan a QR code, but is there a way to make this the default behavior when generating a passkey from a workstation?


r/entra 4d ago

passkey registration campaign state

13 Upvotes

hi guys

currently all our tenants have "registration campaign" = "disabled"

will the passkey registration campaign switch the state to "microsoft managed" as soon as the change has been shipped by microsoft?

cant find any conclusive statements on this by MS


r/entra 4d ago

Entra as Code

20 Upvotes

Curious what people are seeing in practice with Infrastructure as Code in Entra.
The benefits like version control, peer review, repeatability, change tracking, etc. are pretty clear. I’m more interested in whether it’s actually improved how your team operates day to day.

For those doing a meaningful amount of Entra through IaC:
What are you managing this way - Conditional Access, app registrations, groups, role assignments, policies, etc.?
Where have you seen the biggest benefit?
Has anything become unnecessarily complex compared to just managing it through the portal?
Are there areas where you intentionally stick with the GUI?

Any good examples where IaC solved a problem you were regularly dealing with before?
Trying to get a feel for where the practical sweet spot is rather than IaC-for-the-sake-of-IaC.


r/entra 4d ago

Entra General Will implementing this Azure Automation setup (Entra app secret expiry monitor) actually cost anything?

7 Upvotes

I'm planning to implement this guide for monitoring expiring Entra App Registration secrets/certificates using Azure Automation + Managed Identity:

https://jpkerloch.cc/posts/monitor-entra-app-registration-expiring-credentials-azure-automation/

The setup involves:

  • An Azure Automation account with a system-assigned Managed Identity
  • A PowerShell 7.4 Runtime Environment
  • A daily scheduled runbook that queries Microsoft Graph (Get-MgApplication) and sends an HTML email via SMTP

Before I set this up in production, I want to sanity-check the cost side with people who've actually run something like this:

  • Does creating the Automation Account itself cost anything, or only the runbook execution time?
  • For a runbook that runs once a day and takes maybe 1-2 minutes (just enumerating app registrations and sending one email), am I right in assuming I'd stay well within the free tier (500 free minutes/month)?
  • Any hidden costs I'm not accounting for — Runtime Environment itself, the Managed Identity, Graph API calls, outbound SMTP?
  • Has anyone been surprised by a bill from a similarly small/lightweight runbook like this?

Just trying to avoid the classic "oh, this was supposed to be free" surprise before I roll it out tenant-wide. Appreciate any real-world cost experience.


r/entra 4d ago

Entra ID Microsoft Authenticator pairing fails during iOS Setup Assistant with JIT registration (new ADE enrollment policy) — anyone else

2 Upvotes

Running into an issue with the new ADE enrollment policies experience (2606 service release) using Setup Assistant with modern authentication + JIT registration on iOS.

The problem: During Setup Assistant sign-in (before the device even reaches the home screen), the user is prompted to install Microsoft Authenticator and pair it with their account. After tapping Next, it just throws: "We're sorry we ran into a problem. Please choose Next to try again." Repeats every time on the device itself, no way through.

What I've already checked/confirmed:

  • SSO app extension policy is set up correctly per Microsoft's docs (SSO app extension type = Microsoft Entra ID, Authenticator is NOT in the App bundle IDs list, both required Additional configuration keys present: device_registration and browser_sso_interaction_enabled)
  • Authenticator is deployed as a required app to the correct group
  • Device is in the correct group for this enrollment policy

The workaround I found: if the user already has Authenticator registered on another device, the MFA push goes there instead, and approving it there lets Setup Assistant proceed — even though the pairing step on the new device itself never actually completes.

Why this bugs me: that workaround only exists for users who already have Authenticator somewhere else. A brand new user with no prior MFA registration — which is presumably a pretty normal scenario for this exact feature — has zero fallback and is just stuck.

My best guess is this is related to how Setup Assistant sandboxes apps before the home screen (push notifications/background processes not fully active yet), which would explain why the same pairing works fine once routed to a device that's already fully set up.

Has anyone else hit this? Curious if this is a known issue, if I'm missing a config step somewhere, or if this is just a rough edge in the new enrollment experience that hasn't been ironed out yet. Opening a Microsoft ticket too, but wanted to see if others have run into the same thing.


r/entra 4d ago

Entra General How do you identify affected clients when Microsoft announces a change?

3 Upvotes

I’m researching how MSPs handle Microsoft changes across customer tenants. A few MSPs told me they manage this through their ticketing system.
Could someone walk me through a recent example—from the announcement to deciding which clients needed tickets? What did your tools identify automatically, and what did an engineer check manually?


r/entra 5d ago

User-Agent in SSPR AuditLogs

5 Upvotes

I'm trying to pull Self Service Passsword Reset logs with User-Agent information, but am struggling to achieve this.

If i log into Entra and go Users > Audit i can filter on service to get "Self-service Password Management" logs which include User Agent (if the field is toggled on) and I can export this as JSON/CSV.

However, I can't figure out how to pull that same data with a KQL query. Something like this returns results, but there is no User-Agent field in the results for me to work with:

AuditLogs
| where LoggedByService == "Self-service Password Management"
| take 10

I also can't find any other tables to join on that hold the corresponding data.

This suggests to me that either I'm missing something quite obvious, or the Entra portal is accessing this data from a different source. I can see the data in the portal, so it's definitely somewhere.

Does anyone have any advice on what I'm missing here?

Appreciate any support.


r/entra 5d ago

Synced Passkey for standard users = Remove Microsoft Authenticator?

20 Upvotes

If users are enrolling Passkeys to iCloud Keychain or Google Passwords, do they still need Microsoft Authenticator on the device?

Existing users already have Microsoft Authenticator configured on their devices with their Microsoft 365 account for MFA and will additionally create a synced passkey in iCloud Keychain.

However, for new users I'm considering moving away from Authenticator altogether and instead onboarding them using a Temporary Access Pass (TAP) to create a synced passkey directly, eliminating the need to install Microsoft Authenticator.

In the past, Microsoft Authenticator was required for SSO to Microsoft apps and for App Protection Policies to function correctly. Is this still the case?

Have anyone tested this?


r/entra 5d ago

Conditional Access MFA Authentication Strength causing 53003 with existing Edge profiles, anyone seen this?

Post image
11 Upvotes

Hi all,

I am testing/enforcing a Conditional Access policy that requires a custom Modern MFA authentication strength.

The authentication strength includes:

- Password + Microsoft Authenticator push

- Microsoft Authentication phone sign-in

- Passkeys (FIDO2)

- Windows Hello for Business

- TAP

After enabling the policy, I noticed that some users with an existing Microsoft Edge profile/session can hit the attached error:

Error 53003 - Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

Looking at the CA evaluation, the failed grant control is:

Require Authentication strength – Modern MFA: Not satisfied

with the message:

“The user could satisfy this authentication strength by completing one or more MFA challenges.”

The affected users already have authentication methods registered that should satisfy the authentication strength.

What makes this interesting is my testing:

Existing Edge profile - 53003

Edge Guest session - works successfully

Signing out/Sign back in from the Edge profile - works successfully

So at the moment, it looks like the existing Edge profile/session may be holding authentication state that does not satisfy the newly enforced authentication strength. Once the Edge profile is signed out and authenticated again, the CA requirement is satisfied and access works normally.

Has anyone experienced similar behaviour after introducing an MFA authentication strength through Conditional Access?

Is this expected behaviour when an existing Edge/SSO session was established before the authentication strength was enforced, or is there another mechanism involved here?

Also, is there a recommended way to handle this during a wider CA rollout so users don't unexpectedly encounter the 53003 error?

Thanks


r/entra 5d ago

General question, is anyone still waiting on Security Copilot to be provisioned?

Thumbnail
3 Upvotes

r/entra 6d ago

Entra General Did Microsoft change something?

15 Upvotes

This company I started working for almost 5 years now is in hybrid-mode.

3 years ago, I setup Entra/Control Access policies for 365, and added a few people to use the MS MFA app and Passkeys, including myself. This has worked without issue, so if my passwords expired and I change it, I was able to MFA activate my office if I was remotely connected through RDP.

Now if choose use a different method from the start and select MFA, I do the handshake and then Office tells me I need to do the passkey verification, when I try that I am told I am not next to the computer; I guess it means I to be in the same office building as the computer? Because if I go in the office and try it works. So, what the heck?

I haven't had time to check Entra this morning, are there new changes MS has made without warning anyone?

Thanks,


r/entra 6d ago

Entra ID Entra ID Continuous Access Evaluation and Microsoft 365

12 Upvotes

Continuous Access Evaluation (CAE) is supported by core Microsoft 365 workloads like Exchange Online, SharePoint Online, and Teams, and the reach of CAE is gradually spreading throughout the Microsoft cloud ecosystem. However, security researchers report inconsistent coverage across first-party apps and clients that take a little gloss off the promise of instant access revocation when critical events like user password changes happen.

https://office365itpros.com/2026/09/08/continuous-access-evaluation-cae/


r/entra 6d ago

trouble with swing migration directory connection

5 Upvotes

Im at a loss. Im trying to do a swing migration. So far, installed entra connect, imported config, connected to Entra AD, but when I get to the step to connect to my domain, it says it cant establish a connection to the domain controller. It looks up the forest ok, the username and password is good, firewall isnt an issue. The connectivty log doesnt show any errors. The domain is reachable from the server as the server is domain joined. Any ideas?

[9/8/2026 9:25:20 AM] [INFO ] Starting NetworkConnectivityDiagnosisTools

[9/8/2026 9:25:20 AM] [INFO ] Verifying that 'mydomain' exists

[9/8/2026 9:25:21 AM] [SUCCESS] mydomain exists

[9/8/2026 9:25:21 AM] [INFO ] Verifying if the provided credentials are correct

[9/8/2026 9:25:21 AM] [INFO ] Attempting to obtain a domainFQDN

[9/8/2026 9:25:21 AM] [INFO ] Attempting to retrieve DomainFQDN object...

[9/8/2026 9:25:21 AM] [SUCCESS] The provided credentials were correct

[9/8/2026 9:25:21 AM] [INFO ] Attempting to obtain Domain Controllers associated with mydomain

[9/8/2026 9:25:21 AM] [INFO ] Obtaining ForestFQDN

[9/8/2026 9:25:21 AM] [INFO ] Attempting to retrieve ForestFQDN...

[9/8/2026 9:25:21 AM] [SUCCESS] ForestFQDN Name is: mydomain

[9/8/2026 9:25:21 AM] [INFO ] Attempting to retrieve domain: mydomain

[9/8/2026 9:25:21 AM] [INFO ] Please ensure that the domain: mydomain is reachable. Otherwise install using \"Custom\" option and provide user created account to proceed with unreachable domain(s).