How to Configure Microsoft 365 MFA Alternatives for Small Businesses
Question details
Small businesses need to configure alternative Microsoft 365 authentication methods so employees do not have to use company phones, and they need to know proper offboarding procedures for departing staff.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Setting up multi-factor authentication (MFA) methods for staff without dedicated company devices and handling account security during employee departures.
- Observed behavior
- Administrators require alternative verification methods like SMS or voice calls instead of the Authenticator app, alongside safe protocols for blocking access when an employee leaves the company.
Ensure you are logged in to the Microsoft Entra admin center with an account that has Global Administrator privileges, as these permissions are required to modify organization-wide authentication policies.
Enable SMS and Phone Call MFA Alternatives
Configure your tenant policies to allow employees to receive authentication verification codes via SMS text messages or voice calls.
Depending on your tenant configuration and licensing, administrators can enable SMS-based authentication. This allows users to authenticate using their personal mobile devices without requiring the installation of the Microsoft Authenticator app.
Log in to the Microsoft Entra admin center as a Global Administrator.
Go to Protection in the left sidebar, click on Authentication methods, and select Policies.
Select the 'SMS' or 'Voice call' method from the list, toggle the setting to 'Enable', and assign it to the 'All users' group or specific selected groups.
Click 'Save' to apply the policy. Users will now be prompted to register their phone numbers for text or voice verification during their next login.

Execute Secure Employee Offboarding Procedures
Follow best practices to properly revoke Microsoft 365 access and authentication methods when an employee leaves the business.
Looking for a Simpler Software Solution? Try WPS Office
While managing Microsoft 365 security policies requires complex administrative configurations, WPS Office provides small businesses with a lightweight, highly secure, and user-friendly alternative. Enjoy powerful tools for your business operations without the heavy administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install the Software: Run the installer and follow the quick on-screen instructions to set up the suite on your device.
- 3. Open and Edit Business Files: Launch WPS Office and immediately open your existing Microsoft Office files to resume work seamlessly.

Frequently Asked Questions
Can I turn off MFA completely for my small business?
It is highly discouraged to disable MFA entirely. You should only disable multi-factor authentication if there is a documented security reason and you have already deployed an approved alternative security replacement.
Can employees use their personal phones for Microsoft 365 MFA verification?
Yes, if the Global Administrator configures the authentication policies to allow SMS or voice calls, employees can securely use their personal phone numbers to receive verification codes without needing a company-issued device.
Who has permission to change MFA methods in Microsoft 365?
Only users assigned the Global Administrator or Authentication Policy Administrator roles can modify and configure the allowed authentication methods for the organization's tenant.
How do I remove an ex-employee's personal phone from their Microsoft 365 MFA settings?
A Global Administrator must log into the Microsoft Entra admin center, locate the specific user, select 'Authentication methods' under their profile, and delete the registered mobile phone number or linked authentication apps.




