How to Configure Microsoft Authenticator Number Matching for Specific Groups
Question details
The user wants to apply Microsoft Authenticator number matching policies to a specific group, but the setting appears globally enforced and cannot be scoped.

- Product
- Microsoft Entra ID / Microsoft Authenticator
- Device & OS
- not provided
- Scenario
- Configuring MFA authentication method policies for organizational security.
- Observed behavior
- The number-matching setting cannot be scoped to a selected group and applies to all users across the organization.
Ensure you have Global Administrator or Authentication Policy Administrator privileges in the Microsoft Entra admin center before reviewing or modifying security policies.
Verify Global Enforcement of Number Matching
Understand that number matching is a mandatory security feature deployed globally by Microsoft and cannot be scoped to specific groups.
Microsoft has made number matching a default and mandatory security feature for Microsoft Authenticator push notifications to prevent MFA fatigue attacks.
Because this is a globally enforced security enhancement, the setting to enable or disable it cannot be scoped to specific Azure AD (Entra ID) groups. Even if you apply the base Authenticator policy to a selected group, the number matching requirement remains globally active for any user utilizing the app.
Log in to the Microsoft Entra admin center using your administrator credentials.
Go to Protection > Authentication methods > Policies in the left-hand navigation menu.
Click on the Microsoft Authenticator policy to review the targeted groups and configuration settings.
Check the 'Configure' tab. You will notice that while you can scope the overall Authenticator policy to specific groups, the 'Require number matching for push notifications' feature is enabled globally and cannot be toggled per group.

Boost Organizational Productivity with WPS Office
While you manage your organization's IT security and authentication policies, streamline your daily workflow with WPS Office. It provides a lightweight, highly compatible, and cost-effective alternative to Microsoft Office for your teams.
- 1. Download WPS Office: Visit the official WPS website and click the free download button.
- 2. Run the installer: Open the downloaded setup file and follow the on-screen instructions to install the suite.
- 3. Open and work: Launch WPS Office, open your existing Microsoft Office files seamlessly, and enjoy uninterrupted productivity.

Frequently Asked Questions
Why can't I disable number matching for specific users?
Microsoft enforces number matching globally for all users utilizing Microsoft Authenticator push notifications to mitigate MFA fatigue (spamming) attacks. It cannot be disabled for individual users or groups for security reasons.
Does the Authenticator policy group targeting apply to other settings?
Yes, you can still scope the overall use of Microsoft Authenticator to specific groups, as well as configure other features like location context or application context, provided they are not globally enforced by Microsoft.
How does number matching affect the user login experience?
When a user signs in, the login screen displays a two-digit number. The user must open the Microsoft Authenticator app on their mobile device, type that specific number into the prompt, and tap Approve to complete the authentication process.




