Tenant-level Microsoft Entra policy that switches on each sign-in method, such as FIDO2, Authenticator, certificate-based authentication, TAP or SMS, for chosen users or groups.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Authentication methods policy in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- FIDO2
An open standard, used together with WebAuthn, that underpins passkeys and hardware security keys. Sign-in relies on a private key kept on the device in place of a password, so it resists phishing.
- Certificate-based authentication
Lets people authenticate to Microsoft Entra by presenting an X.509 certificate from your organisation's PKI. Scoped to a group, it becomes an extra option, can count as passwordless MFA and doesn't stop anyone using other methods.
- Temporary Access Pass
A Microsoft Entra ID passcode valid for a limited time, used to onboard users or recover accounts. Its value can be viewed only when it is first created.
- SMS
Text-message verification, where a one-time code is sent to a phone for MFA, password reset or sign-in; Microsoft advises organisations to move to stronger options. Microsoft itself stops sending these texts and voice calls from 1 February 2027, or 1 July 2027 for Global Administrators and external users, so anyone still needing them must then bring a telephony provider.
Related terms
- Authentication Administrator
Microsoft Entra role for managing authentication methods on individual user accounts. Tenant-wide SSPR and the authentication methods policy lie outside its reach.
- Authentication Policy Administrator
Least-privileged Microsoft Entra role for tenant-level SSPR settings and the authentication methods policy, neither of which Authentication Administrator can change.
- Authentication strength
Grant control in Conditional Access that restricts which combinations of methods meet a policy, for example the built-in Phishing-resistant MFA. It narrows methods without enabling them; enabling is done in the authentication methods policy.
- Legacy MFA and SSPR policies
Older, all-users-or-nobody controls that once governed which multifactor authentication and self-service password reset methods were allowed. From 30 September 2025 methods can no longer be configured there, as that role has passed to the Authentication methods policy.
- Passwordless phone sign-in
Mode of Microsoft Authenticator, switched on for a target group in the Authentication methods policy, that lets users sign in with no password.