Azure Azure Security

Advanced Microsoft Authenticator Security Features is now Generally Available 

cubesys
Share this blog post on Twitter Share this blog post on Facebook Share this blog post on LinkedIn

Previously in public preview, Microsoft Authenticator security features are now Generally Available for your organisation! So, how will this affect you? 

Admins can now use number matching, location context, and application context to prevent accidental approvals in Microsoft Authenticator. For those that might not be aware of the terminology, number matching involves entering a number into the Authenticator app that matches the one presented to the user.  

On top of this, admins can now also better manage the Microsoft Authenticator app with new Admin UX and Admin APIs (Application Programming Interface). Admin UX refers to the Admin user experience, which refers to the experience the user takes away from interacting with that product.  

With the rise of Multi-Factor Authentication (MFA) fatigue attacks, critical security features are enabled to eradicate threats before they become a problem. An MFA fatigue attack involves bombarding a user’s authentication app with push notifications until they accept, allowing them to gain entry to their account or device.  

Number matching in Microsoft Authenticator 

By the end of February 2023, number matching will be enabled for all Microsoft Authenticator users. Admins can make it a requirement for users to number match when approving an MFA request in Authenticator. This not only prevents accidental approvals, it helps defend users against the MFA fatigue attacks mentioned prior.  

Security awareness training solution for Small Businesses

Additional context in approval requests 

Showing users additional context in Microsoft Authenticator notifications is another way to reduce any accidental approvals. The following contexts can be selected by Admins to be displayed to users: 

  • Application context: Users see which application they’re signing into 
  • Location context: Users see their sign-in location based on the IP address of the device they’re signing into 

Updated Admin UX and APIs 

The refresh Admin UX and APIs will help Admins better manage their Microsoft Authenticator features. The new Configure tab in the Admin UX allows different features to be enabled or disabled. It also includes the ability to exclude groups from features, a highly requested feature, which will help with smoother feature rollouts.  

Note: Once number matching has been enabled for all at the end of February 2023, these rollout controls will be disconnected. 

Ongoing security and usability optimisations 

Microsoft Authenticator is working on constantly innovating and improving its security and user experience features. For example, the iOS app now includes App Transport Security (ATS), which improves the privacy and data integrity between Authenticator and web services.  

Update security info with Microsoft Authenticator

Leave a Comment

Related Articles

Azure AD

Azure AD – You can use your Microsoft Authenticator mobile application to update your security info

As you know, end-users can access the Microsoft My Sign-Ins website (https://mysignins.microsoft.com/) to manage their security information (register MFA authentication...

cubesys
Read More
Azure Security Office 365 MFA

Security – The Authenticator Application now provides a full screen experience and allow to manage the ‘display code’ for all account at once

By now you should already know the Microsoft Authenticator application used for multi-factor authentication (MFA) when accessing Microsoft services (Microsoft Accounts,...

cubesys
Read More

About

  • Menu Item One
  • Menu Item Two
  • Menu Item Three

Services

  • Menu Item One
  • Menu Item Two
  • Menu Item Three

News

  • Menu Item One
  • Menu Item Two
  • Menu Item Three
Follow us on Facebook Follow us on LinkedIn Follow us on Twitter Follow us on Instagram