logo
search
Conditional Access Problems

How to Create a Country-Based Conditional Access Policy Without Microsoft Authenticator

Adam DavisAdam Davis Oct 1, 2026 868 views

Question details

The user wants to configure a conditional access policy restricting sign-ins by country but needs to prevent the policy from mandating Microsoft Authenticator app registration.

Create a Country-Based Conditional Access Policy Without Microsoft Authenticator
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Setting up geo-blocking or location-based security policies for tenant sign-ins while retaining flexible multifactor authentication (MFA) methods.
Observed behavior
Applying the country-based policy triggers an unexpected prompt for users to register the Microsoft Authenticator app due to specific grant controls.
Before you start

Ensure you have Conditional Access Administrator or Global Administrator privileges in your Microsoft Entra ID tenant, and always configure a break-glass (emergency access) account to prevent accidental lockouts.

Solution 1Recommended

Adjust Grant Controls and Authentication Strengths

Modify the policy's grant settings to use a broader multifactor authentication requirement rather than a strict authentication strength that mandates the Authenticator app.

When a Conditional Access policy enforces a specific 'Authentication strength' (like Passwordless MFA), it may inadvertently force users to register for the Microsoft Authenticator app if it is the only method that satisfies the requirement. Adjusting this control ensures users can use other approved methods like SMS, Voice, or hardware tokens.

1
Access Conditional Access Policies

Log in to the Microsoft Entra admin center. Navigate to Protection > Conditional Access > Policies, and select your country-based policy.

2
Modify Grant Controls

Under the 'Access controls' section on the left menu, click on 'Grant'.

3
Update Authentication Requirements

Instead of selecting 'Require authentication strength' with a strict profile, select 'Require multifactor authentication'. This allows any MFA method configured in your tenant to satisfy the prompt.

4
Save and Test

Click 'Select' to apply the changes, leave the policy in 'Report-only' mode to verify its behavior in the sign-in logs, and then switch to 'On' once confirmed.

Adjust Grant Controls and Authentication Strengths
Custom Authentication Strengths: If you still want to use Authentication Strengths, you can create a custom strength in Entra ID that explicitly includes your preferred alternative methods (like FIDO2 or SMS) alongside or instead of Microsoft Authenticator.
Free Microsoft Office alternative

Boost Your Productivity with WPS Office

While configuring Microsoft 365 security policies and licensing can be complex, choosing the right productivity suite is easy. WPS Office provides a lightweight, highly compatible, and free alternative to Microsoft Office, keeping your team productive without the heavy overhead.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install WPS Office: Run the setup file and follow the quick installation wizard to get started in minutes.
  3. 3. Open Your Office Files: Launch WPS Office and directly open your existing .docx, .xlsx, or .pptx files with full formatting retention.
Seamless format compatibility with Microsoft Word, Excel, and PowerPoint files.Lightweight installation that runs fast on Windows, Mac, Linux, iOS, and Android.Familiar tabbed interface that requires zero learning curve for new users.Built-in PDF editing, conversion, and merging tools included for free.
microsoft office alternative - wps office

Frequently Asked Questions

Why does my Conditional Access policy force Microsoft Authenticator?

This typically occurs if the policy's 'Grant' controls are configured to require an authentication strength that only the Microsoft Authenticator app can satisfy, or if your tenant has an active Microsoft Authenticator registration campaign running in the background.

How do I define countries for a location-based policy?

In the Microsoft Entra admin center, go to Protection > Conditional Access > Named locations. Click 'Countries location', select the countries you want to include, and choose whether to determine location by IP address or GPS coordinates.

Can I use SMS or Voice calls for MFA instead of the Authenticator app?

Yes, if SMS or Voice methods are enabled in your tenant's Authentication methods policy. You must ensure your Conditional Access grant controls use a generic 'Require multifactor authentication' setting or a custom authentication strength that allows SMS/Voice.

How can I safely test my Conditional Access policy before enforcing it?

Always set new policies to 'Report-only' mode. This allows the system to log how the policy would affect user sign-ins without actually blocking access or forcing MFA prompts. You can review the impact in the Entra ID Sign-in logs.