Still running the default Authentication methods policy in Entra ID?

๐Ÿ”’ Secure Bits ๐Ÿ’ก

๐—ฆ๐˜๐—ถ๐—น๐—น ๐—ฟ๐˜‚๐—ป๐—ป๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—บ๐—ฒ๐˜๐—ต๐—ผ๐—ฑ๐˜€ ๐—ฝ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—ถ๐—ป ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—œ๐——?

Most tenants I look at still have SMS and Voice call enabled for all users โ€” left over from the old per-user MFA/SSPR settings, never revisited after the move to the unified Authentication methods policy.

๐—ช๐—ต๐˜† ๐˜๐—ต๐—ฎ๐˜’๐˜€ ๐—ฎ ๐—ฝ๐—ฟ๐—ผ๐—ฏ๐—น๐—ฒ๐—บ:

๐Ÿ”น SMS and voice call are phishable โ€” SIM swap, real-time relay, or a convincing helpdesk call will get through

๐Ÿ”น If Conditional Access accepts any MFA method, attackers will simply target the weakest one enabled

๐Ÿ”น Old OATH hardware/software tokens left enabled “just in case” widen the attack surface once phishing-resistant methods are already in place

๐—ช๐—ต๐—ฎ๐˜ ๐˜๐—ผ ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ถ๐—ป๐˜€๐˜๐—ฒ๐—ฎ๐—ฑ:

๐Ÿ”น ๐—ฃ๐—ฎ๐˜€๐˜€๐—ธ๐—ฒ๐˜† (๐—™๐—œ๐——๐—ข๐Ÿฎ) โ€” phishing-resistant, security keys and platform authenticators

๐Ÿ”น ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ผ๐—ฟ โ€” passwordless phone sign-in, nothing sent over SMS

๐Ÿ”น ๐—ค๐—ฅ ๐—ฐ๐—ผ๐—ฑ๐—ฒ โ€” handy for shared devices and frontline workers

๐Ÿ”น ๐—–๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ-๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—ฎ๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป โ€” scope it to the group that actually needs it, not all users

๐Ÿ› ๏ธ ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐˜๐—ผ ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ถ๐˜:

Entra admin center โ†’ Protection โ†’ Authentication methods โ†’ Policies. Enable and target the stronger methods first, confirm adoption, then disable SMS, Voice call, and legacy OATH tokens for “All users.”

โš ๏ธ Check Sign-in logs before you disable anything โ€” you want to know who still relies on SMS/voice today, or you’ll get a wave of helpdesk tickets tomorrow.

๐Ÿ’ฌ ๐—ช๐—ต๐—ฎ๐˜ ๐—ฑ๐—ผ๐—ฒ๐˜€ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—บ๐—ฒ๐˜๐—ต๐—ผ๐—ฑ๐˜€ ๐—ฝ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—น๐—ผ๐—ผ๐—ธ ๐—น๐—ถ๐—ธ๐—ฒ ๐—ฟ๐—ถ๐—ด๐—ต๐˜ ๐—ป๐—ผ๐˜„ โ€” still default, or hardened?

Author: Martin Strnad