Set up MFA, SSPR, and Microsoft Authenticator all at once

From our perspective, using Microsoft Authenticator is the best option to use as your default MFA sign-in method. Your other options are SMS, email, security questions, and Office phone.

The reason we like it is that:

  • It is secure
  • It is available for iOS and Android devices
  • You can MFA even if you have no cell coverage
  • You can MFA also if you have no wireless coverage
  • If you have a limited SMS Plan and have wifi, you will not be using your SMS plan to get authenticated
  • The best of all, you just need to click a button to MFA, no need to read, remember, and type a 6-digit code

 

Here is the process that you will experience, as a user, when setting up Microsoft Authenticator as your preferred authentication method

Note: Your IT administrator must have enabled MFA, and the Azure feature called “Users can use preview features for registering and managing security info – enhanced”

Let’s get started!

  1. Go to https://office.com
  2. Click on Sign in
  3. Type your username and click Next
  4. Type your password and click on Sign in

You will now be required to provide more information and start enrolling your device against your Office 365 account.

5. Click Next in the screen below

You will now be presented with a wizard to install the Microsoft Authenticator app on your phone

MFAScreen5

Once you have downloaded the app, please make sure you allow the Microsoft Authenticator app to use your camera (if asked). If the app cannot use the camera, you will not be able to complete the setup correctly.

Once the app is installed, you will need to set up your account to connect to the app.

Now that the app has been registered against your account, let’s validate that it has been set up correctly

MFA7

You will receive a ‘pop up’ notification from Microsoft Authenticator. You will need to press the Approve button to move forward. The beautiful thing, compared to SMS MFA is that you do not have to type any number, making the process faster and easier.

If the setup is successful, you will receive the following confirmation – “Notification approved”

MFA10

 

Now, you will set up the backup solution, which is to use the regular MFA using the SMS option

You will be asked to enter your mobile phone number. You will need to decide if you want to have your validation done via an SMS or having Microsoft call you

MFA11

In the example below, I have chosen the SMS option. Once you receive the SMS, enter it and click Next

MFA12

When successful, you will receive the following screen “SMS verified successfully.”

MFA13

You are now ready to use Microsoft Authenticator as the default sign-in method

MFA14

You have taken a significant step to secure your identity!