How to Create a Country-Based Conditional Access Policy Without Microsoft Authenticator
Question details
The user wants to configure a conditional access policy restricting sign-ins by country but needs to prevent the policy from mandating Microsoft Authenticator app registration.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Setting up geo-blocking or location-based security policies for tenant sign-ins while retaining flexible multifactor authentication (MFA) methods.
- Observed behavior
- Applying the country-based policy triggers an unexpected prompt for users to register the Microsoft Authenticator app due to specific grant controls.
Ensure you have Conditional Access Administrator or Global Administrator privileges in your Microsoft Entra ID tenant, and always configure a break-glass (emergency access) account to prevent accidental lockouts.
Adjust Grant Controls and Authentication Strengths
Modify the policy's grant settings to use a broader multifactor authentication requirement rather than a strict authentication strength that mandates the Authenticator app.
When a Conditional Access policy enforces a specific 'Authentication strength' (like Passwordless MFA), it may inadvertently force users to register for the Microsoft Authenticator app if it is the only method that satisfies the requirement. Adjusting this control ensures users can use other approved methods like SMS, Voice, or hardware tokens.
Log in to the Microsoft Entra admin center. Navigate to Protection > Conditional Access > Policies, and select your country-based policy.
Under the 'Access controls' section on the left menu, click on 'Grant'.
Instead of selecting 'Require authentication strength' with a strict profile, select 'Require multifactor authentication'. This allows any MFA method configured in your tenant to satisfy the prompt.
Click 'Select' to apply the changes, leave the policy in 'Report-only' mode to verify its behavior in the sign-in logs, and then switch to 'On' once confirmed.

Disable the Tenant-Wide Registration Campaign
Check if a Microsoft Authenticator registration campaign is active, which can cause registration prompts independently of your country-based policy.
Boost Your Productivity with WPS Office
While configuring Microsoft 365 security policies and licensing can be complex, choosing the right productivity suite is easy. WPS Office provides a lightweight, highly compatible, and free alternative to Microsoft Office, keeping your team productive without the heavy overhead.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the setup file and follow the quick installation wizard to get started in minutes.
- 3. Open Your Office Files: Launch WPS Office and directly open your existing .docx, .xlsx, or .pptx files with full formatting retention.

Frequently Asked Questions
Why does my Conditional Access policy force Microsoft Authenticator?
This typically occurs if the policy's 'Grant' controls are configured to require an authentication strength that only the Microsoft Authenticator app can satisfy, or if your tenant has an active Microsoft Authenticator registration campaign running in the background.
How do I define countries for a location-based policy?
In the Microsoft Entra admin center, go to Protection > Conditional Access > Named locations. Click 'Countries location', select the countries you want to include, and choose whether to determine location by IP address or GPS coordinates.
Can I use SMS or Voice calls for MFA instead of the Authenticator app?
Yes, if SMS or Voice methods are enabled in your tenant's Authentication methods policy. You must ensure your Conditional Access grant controls use a generic 'Require multifactor authentication' setting or a custom authentication strength that allows SMS/Voice.
How can I safely test my Conditional Access policy before enforcing it?
Always set new policies to 'Report-only' mode. This allows the system to log how the policy would affect user sign-ins without actually blocking access or forcing MFA prompts. You can review the impact in the Entra ID Sign-in logs.




