← cd ~/learn
azureblog.co.uk · cheat sheet
Entra ID authentication methods
Every sign-in method in Entra ID at a glance: how strong it is, whether it's passwordless, and where it fits.
Fits on one A4 page. Checked 8 Oct 2026.
Methods compared
| Method | Phishing-resistant | Passwordless | Good for |
|---|---|---|---|
| Passkey, device-bound (security key or Authenticator) | Yes | Yes | Everyone, especially admins |
| Passkey, synced (password manager or phone platform) | Yes | Yes | Most users. Control with passkey profiles |
| Windows Hello for Business | Yes | Yes | Corporate Windows devices |
| Certificate-based authentication (multifactor) | Yes | Yes | Smart card and PKI estates |
| Authenticator phone sign-in | No | Yes | Passwordless where passkeys can't go yet |
| Authenticator push (number matching) | No | No | Second factor after a password |
| OATH codes (software or hardware token) | No | No | Users without a smartphone |
| SMS and voice | No | No | Microsoft-provided SMS and voice end for most users on 1 Feb 2027, and for Global Admins and external users on 1 Jul 2027. Plan to move off |
| Temporary Access Pass | n/a | Yes | Onboarding and recovery only |
| Email one-time passcode | No | n/a | Password reset and guests only |
Built-in authentication strengths
- Multifactor authentication: any MFA combination, including password plus push, OATH or SMS, a Temporary Access Pass, and federated MFA.
- Passwordless MFA: passkeys, Windows Hello for Business, certificate-based authentication and Authenticator phone sign-in.
- Phishing-resistant MFA: passkeys (FIDO2), Windows Hello for Business and multifactor certificate-based authentication.
Use them as a Conditional Access grant control instead of plain "require MFA" when the method matters.
Where to set things
- Authentication methods policy: which methods each group can register and use.
- Registration campaign: nudges users to register a stronger method at sign-in.
- System-preferred authentication: Entra picks the strongest method the user has.
- Conditional Access: authentication strengths decide what's accepted per app or role.
A sensible target state
- Admins: phishing-resistant only, enforced by Conditional Access
- Staff: passkeys or Windows Hello as the default
- Temporary Access Pass for day-one onboarding
- SMS and voice switched off once nobody depends on them
- Break-glass accounts with FIDO2 security keys