South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Not since 2019? Passwordless is already implemented.Except you always had to use your PW AFAIK?
No you miss my point.Your device was stolen, your fingerprint only works on that device.
You're concerned with someone using your device to access your MS account, forgetting they have access to everything on the device...
Just RTFM.
I think it must it must be explicitly enabled in Azure AD for business users.So is that a setting you need to enable? Is this for business or home users?
I'm not seeing it my side.
*edit* I see it on my personal account now but not business. I also see 'use your password instead' on personal. Assume I must disable that somewhere...
So curious.... if I get a new device and lose my old one... how do I set up authenticator if not with a password?
Biometrics are only for your device.No you miss my point.
The point is that biometrics is not a very secure way to protect anything - just as you say above.
A password provides better protection, because it's not left behind on everything you touch.
Saying "you have bigger problems" does not make a case for this whole new scheme being an "improvement" in security. It just distracts from the point I'm trying to make.
If on 365, you would have Azure AD behind the scenes, it’s free.My new phone arrives today. I'll give feedback lol
If you don't subscribe to AD on the business side, is it not an option then?
Have you ever succesfully logged into any device with a impression of a fingerprint that was left behind on another surface?No you miss my point.
The point is that biometrics is not a very secure way to protect anything - just as you say above.
A password provides better protection, because it's not left behind on everything you touch.
Saying "you have bigger problems" does not make a case for this whole new scheme being an "improvement" in security. It just distracts from the point I'm trying to make.
Have you ever succesfully logged into any device with a impression of a fingerprint that was left behind on another surface?
Well the auth flow asks if it’s a personal or work account.Insecurity by obfuscation IMO. I see they have introduced so many new things since the last time I looked... you have to disable "Legacy MFA" in favour of org wide "Modern Authenticaiton" according to their documentation. These firms always have to differentiate themselves and end up complicating everyone's lives.
On that subject, has MS resolved the whole for home / school / work issue with their accounts?
It’s in the docs, same link you provided.The point is that you can sign up a single account for both work and personal. That's a mistake on their part IMO.
I use the authenticator with multiple tenants but on the same account - in these cases, the vendor has added my work account to their AD as a guest and given me access...
If someone wanted to give me a new account, I imagine I'd have to set up another profile on my phone... what a PITA. I think Samsung might also allow you to install certain apps from their app store as independent to apps installed from the Play Store if you have Samsung and needed a second account... a bit of a work around.
Right now the issue I'm having is setting up for passwordless logins for the work email. I've got authenticator working but can't seem to get it to stop asking for the password.
Following their instructions here:
There's this step:![]()
Passwordless sign-in with Authenticator - Microsoft Entra ID
Learn how to enable passwordless sign-in to Microsoft Entra ID by using Microsoft Authenticator.docs.microsoft.com
View attachment 1149650
That app - "Azure Multi Factor Auth Connector" does not exist in my setup at all.
And here we go with the obscurity.... I already have MFA enabled and require password + authenticator to sign in... but when I go to the azure portal (after logging in with MFA) and go to the MFA services overview tab, I get this:
View attachment 1149652
I mean... I've already got MFA, yet I'm expected to "Get Free Premium Trial" to enable MFA... LOL.
We use Microsoft Business Basic - assuming that doesn't include the option for passwordless login?
It's this kind of obscurity that makes people go... stuff it, i'll stick with the "old way of doing things"
It works with Business Basic.One prerequisite is that the device on which the Microsoft Authenticator app is installed must be registered within the Azure AD tenant to an individual user.
Currently, a device can only be registered in a single tenant. This limit means that only one work or school account in the Microsoft Authenticator app can be enabled for phone sign-in.
Agree.I hate that piece of ****. No, really, I loathe it.
Still one device. It's in the app settings, if your device is registered also it won't allow you to enable the feature for another account.I'm not following, what's in that link? That prerequisite is not available to me.
View attachment 1149688
Second item - can only be registered in a single tenant is not strictly true if you have a different profile on your device AFAIK.
That's something else, MFA but in a diffferent context. Go to Authentication methods.when I go to the azure portal (after logging in with MFA) and go to the MFA services overview tab
Windows Hello or domain joined probably.Edge was being uber promiscuous and just authenticated me no matter what we did - we logged out, cleared all cache items from 'beginning of time', closed the browser, restarted it, went to office.com, selected my account (it was still there - cached), and it authenticated me without asking for password or authenticator app intervention (incognito window included) lol.... eventually we resorted to Chrome incognito.
MS took me through a whole host of changes to AD. It was working when on the phone with them, so we ended the support call.
The first attempt to log in now through Azure and passwordless is not working again - it wants my PW lol...
Not phoning them again right now, but there you go...
I get this now:
View attachment 1149728
If I select 'Use an app instead' I get this:
View attachment 1149730
...after which I get this:
View attachment 1149734
And authenticate with the app (which works)....
what a joke lol