How to Set Up SMS MFA While Keeping Microsoft Authenticator for Specific Users
Question details
The administrator needs to configure multi-factor authentication (MFA) so that a specific group of users authenticates via SMS (phone), while the rest of the organization continues using the Microsoft Authenticator app.

- Product
- Microsoft Entra
- Device & OS
- not provided
- Scenario
- Configuring varying MFA methods for different user groups within an organization.
- Observed behavior
- The admin wants granular control over MFA methods, including and excluding specific users for SMS and App-based authentication, without applying a one-size-fits-all policy.
Ensure you have at least Authentication Policy Administrator privileges in the Microsoft Entra admin center to modify these global authentication settings.
Configure Authentication Methods Policies in Entra ID
Use the Microsoft Entra admin center to explicitly include or exclude specific user groups for SMS and Microsoft Authenticator methods.
By utilizing the granular policies within Microsoft Entra ID, you can designate exactly which users or groups are permitted to use specific authentication methods, allowing for a hybrid MFA environment.
Sign in to the Microsoft Entra admin center. In the left navigation pane, browse to Protection > Authentication methods > Policies.
Click on the 'Microsoft Authenticator' policy. Under the 'Enable and Target' tab, toggle the status to Enable. Use the 'Include' and 'Exclude' options to target the groups of users who should use the app for authentication.
Return to the Policies list and click on the 'SMS' policy. Toggle its status to Enable, and assign it exclusively to the specific subset of users or groups who require phone-based authentication.
Click 'Save' on both policy pages to apply the changes to your tenant.

Disable Conflicting Global MFA Requirements
Ensure global settings like Security Defaults or Registration Campaigns do not override your custom per-group MFA policies.
Need a Lightweight Office Alternative? Try WPS Office
While managing complex Microsoft 365 security policies like MFA, you might be looking for a simpler, cost-effective office suite for your team. WPS Office offers robust document creation with seamless Microsoft format compatibility.

Frequently Asked Questions
Why is Microsoft Authenticator still prompting users who are assigned to SMS?
This usually happens if 'Security Defaults' are enabled in your Microsoft tenant, which globally forces all users to register for the Authenticator app regardless of specific policies. You must disable Security Defaults and use Conditional Access to prevent this.
Can I set a default authentication method for users who have multiple options?
If 'System-preferred MFA' is enabled, Microsoft Entra automatically chooses the most secure registered method for the user (Authenticator over SMS). Users cannot manually set a default method if system-preferred MFA is active.
How do I stop the 'Help us protect your account' prompt for SMS users?
You need to exclude those specific users from the Microsoft Authenticator Registration Campaign. You can do this in the Entra Admin Center under Protection > Authentication methods > Registration campaign by adding the SMS-only user group to the Exclude list.




