

You can only exclude one group from Authenticator Lite, which can be a dynamic or nested group.Ī single entity that is included in this feature. PropertyĪ single entity that is excluded from this feature. After general availability, the Microsoft managed state default value will change to enable Authenticator Lite.

Operating systemīy default, Authenticator Lite is Microsoft managed and disabled during preview. Users must run a minimum Outlook mobile version. Users enabled for shared device mode on Outlook mobile aren't eligible for Authenticator Lite.

If your organization is using the Active Directory Federation Services (AD FS) adapter or Network Policy Server (NPS) extensions, upgrade to the latest versions for a consistent experience. You can edit the Authentication methods policy by using the Azure portal or Microsoft Graph API. Your organization needs to enable Microsoft Authenticator (second factor) push notifications for some users or groups by using the Authentication methods policy. If you wish to change the state of this feature, please do so before May 26th, 2023. This will enable the feature for all users in tenants where the feature is set to Microsoft managed. The 'Microsoft managed' setting for this feature will be set to enabled on May 26th, 2023. This is an important security enhancement for users authenticating via telecom transports.
