azureblog.co.uk
← cd ~/learn
azureblog.co.uk · cheat sheet

Entra ID authentication methods

Every sign-in method in Entra ID at a glance: how strong it is, whether it's passwordless, and where it fits.

Fits on one A4 page. Checked 8 Oct 2026.

Methods compared

MethodPhishing-resistantPasswordlessGood for
Passkey, device-bound (security key or Authenticator)YesYesEveryone, especially admins
Passkey, synced (password manager or phone platform)YesYesMost users. Control with passkey profiles
Windows Hello for BusinessYesYesCorporate Windows devices
Certificate-based authentication (multifactor)YesYesSmart card and PKI estates
Authenticator phone sign-inNoYesPasswordless where passkeys can't go yet
Authenticator push (number matching)NoNoSecond factor after a password
OATH codes (software or hardware token)NoNoUsers without a smartphone
SMS and voiceNoNoMicrosoft-provided SMS and voice end for most users on 1 Feb 2027, and for Global Admins and external users on 1 Jul 2027. Plan to move off
Temporary Access Passn/aYesOnboarding and recovery only
Email one-time passcodeNon/aPassword reset and guests only

Built-in authentication strengths

  • Multifactor authentication: any MFA combination, including password plus push, OATH or SMS, a Temporary Access Pass, and federated MFA.
  • Passwordless MFA: passkeys, Windows Hello for Business, certificate-based authentication and Authenticator phone sign-in.
  • Phishing-resistant MFA: passkeys (FIDO2), Windows Hello for Business and multifactor certificate-based authentication.

Use them as a Conditional Access grant control instead of plain "require MFA" when the method matters.

Where to set things

  • Authentication methods policy: which methods each group can register and use.
  • Registration campaign: nudges users to register a stronger method at sign-in.
  • System-preferred authentication: Entra picks the strongest method the user has.
  • Conditional Access: authentication strengths decide what's accepted per app or role.

A sensible target state

  • Admins: phishing-resistant only, enforced by Conditional Access
  • Staff: passkeys or Windows Hello as the default
  • Temporary Access Pass for day-one onboarding
  • SMS and voice switched off once nobody depends on them
  • Break-glass accounts with FIDO2 security keys