Microsoft Authenticator is an MFA app for securing online accounts. Launched in 2016 as a TOTP generator, the app has now evolved into an authentication solution for Microsoft 365 and Entra ID environments as well as other major third-party apps. Users can quickly verify their identities in supported apps and services by approving the push notifications sent to the Microsoft Authenticator app.
Microsoft Authenticator also supports all apps and services that use TOTP-based authentication. After registering with the application once, the Microsoft Authenticator app will continuously generate codes that can be used to log in toaccounts without a password.
Traditional passwords come with a host of disadvantages, from being easily forgotten to being vulnerable to hacking. Weak or reused passwords can compromise security, while even strong passwords can be susceptible to sophisticated cyberattacks. To address these issues, MFAis widely used as a secure alternative to password-based authentication. Authenticator apps play a crucial role by providing multiple layers of verification, ensuring that even if one factor is compromised,access to accounts is still protected.
Microsoft Authenticator supports MFA for a large suite of applications and services with TOTP-based authentication. However, its mainadvantage over other authenticator apps is its tight integration with Microsoft's solutions, the most prominent being Entra ID. Entra ID is a widely used IAM solution andthe preferred choice for building a cloud-based directory.Using Microsoft Authenticator for passwordless authentication for Entra ID keeps organizations safe against cyberattacks and phishing attempts by a large margin, at no additional cost.
Users can verify their identities through Microsoft Authenticatorin the following ways:
The simplicity of setting up Microsoft Authenticator is one of its main advantages. All that's needed is an Android or iOS device to install the app on.
To use the app forservices that support TOTP authentication, you will need to initiate configuration in the third-party app and scan the QR code displayed using Microsoft Authenticator. Then,Microsoft Authenticator will generate a TOTP for the app.
For setting up passwordless authentication for Microsoft services, you just need to log in to your Microsoft account from the Microsoft Authenticator app. Once done, follow the steps displayed in the app to complete the setup.
Microsoft Authenticator operates by providing a secondary verification method during sign-ins. Here’show it works:
ManageEngine ADSelfService Plus offers adaptive MFA with 20 different authenticators, including Microsoft Authenticator. You can use MFA to protect endpoints, such as on-premises and cloud application logins, computers, VPNs, OWA, and self-service password management tasks. With ADSelfService Plus, customize the MFA authentication process for various user accounts based on their OU and group memberships, allowing you to secure your privileged accounts and activities against cyberthreats.
Microsoft Authenticator is a mobile app for MFA that's used to enhance the security of your online accounts. It supports passwordless sign-in for your Microsoft services, using various verification methods to secure access to your accounts, such as biometric verification, TOTPs, and number-matching push notifications.
Microsoft Authenticator secures a wide range of resources, including:
To implement Microsoft Authenticator, you'll need:
No, Microsoft Authenticator cannot be installed on desktops and PCs. It can only be installed on iOS and Android devices.
When you sign in to your non-Microsoft accounts, you will be prompted for a TOTP to be entered on the login screen. You can find this TOTP in the Microsoft Authenticator app, which can be accessed after completing the device verification.
When you sign in to your Microsoft account, you will be prompted to approve the sign-in notification on the Microsoft Authenticator app, where you will use the device verification method that you registered with.
Microsoft Authenticator requires an internet connection to receive verification notifications and for the initial setup of services using TOTP. Once these are set up, TOTP codes can be generated by Microsoft Authenticator without an internet connection.
To set up Microsoft Authenticator for your personal accounts:
To set up Microsoft Authenticator for your users in Microsoft 365, you can add it as a verification method when setting upEntra ID MFA