logo
search
MFA Security Issues

How to Configure Microsoft Authenticator Number Matching for Specific Groups

Natalie TaylorNatalie Taylor Sep 28, 2026 869 views

Question details

The user wants to apply Microsoft Authenticator number matching policies to a specific group, but the setting appears globally enforced and cannot be scoped.

How to Configure Microsoft Authenticator Number Matching for Specific Groups
Product
Microsoft Entra ID / Microsoft Authenticator
Device & OS
not provided
Scenario
Configuring MFA authentication method policies for organizational security.
Observed behavior
The number-matching setting cannot be scoped to a selected group and applies to all users across the organization.
Before you start

Ensure you have Global Administrator or Authentication Policy Administrator privileges in the Microsoft Entra admin center before reviewing or modifying security policies.

Solution 1Recommended

Verify Global Enforcement of Number Matching

Understand that number matching is a mandatory security feature deployed globally by Microsoft and cannot be scoped to specific groups.

Microsoft has made number matching a default and mandatory security feature for Microsoft Authenticator push notifications to prevent MFA fatigue attacks.

Because this is a globally enforced security enhancement, the setting to enable or disable it cannot be scoped to specific Azure AD (Entra ID) groups. Even if you apply the base Authenticator policy to a selected group, the number matching requirement remains globally active for any user utilizing the app.

1
Access the Entra admin center

Log in to the Microsoft Entra admin center using your administrator credentials.

2
Navigate to Authentication methods

Go to Protection > Authentication methods > Policies in the left-hand navigation menu.

3
Select Microsoft Authenticator

Click on the Microsoft Authenticator policy to review the targeted groups and configuration settings.

4
Review Configure settings

Check the 'Configure' tab. You will notice that while you can scope the overall Authenticator policy to specific groups, the 'Require number matching for push notifications' feature is enabled globally and cannot be toggled per group.

Verify Global Enforcement of Number Matching
Global Enforcement: Number matching is enabled for all users by design to provide a consistent and high level of security against spam authentication requests.
Free Microsoft Office alternative

Boost Organizational Productivity with WPS Office

While you manage your organization's IT security and authentication policies, streamline your daily workflow with WPS Office. It provides a lightweight, highly compatible, and cost-effective alternative to Microsoft Office for your teams.

  1. 1. Download WPS Office: Visit the official WPS website and click the free download button.
  2. 2. Run the installer: Open the downloaded setup file and follow the on-screen instructions to install the suite.
  3. 3. Open and work: Launch WPS Office, open your existing Microsoft Office files seamlessly, and enjoy uninterrupted productivity.
Highly compatible with Microsoft Word, Excel, and PowerPoint formats.Free and lightweight, reducing software deployment overhead for IT admins.Familiar user interface ensuring seamless employee onboarding.Built-in PDF editing tools for secure and efficient document management.
microsoft office alternative - wps office

Frequently Asked Questions

Why can't I disable number matching for specific users?

Microsoft enforces number matching globally for all users utilizing Microsoft Authenticator push notifications to mitigate MFA fatigue (spamming) attacks. It cannot be disabled for individual users or groups for security reasons.

Does the Authenticator policy group targeting apply to other settings?

Yes, you can still scope the overall use of Microsoft Authenticator to specific groups, as well as configure other features like location context or application context, provided they are not globally enforced by Microsoft.

How does number matching affect the user login experience?

When a user signs in, the login screen displays a two-digit number. The user must open the Microsoft Authenticator app on their mobile device, type that specific number into the prompt, and tap Approve to complete the authentication process.