logo
search
MFA Security Issues

How to Set Up SMS MFA While Keeping Microsoft Authenticator for Specific Users

WPS Content ManagerWPS Content Manager Sep 30, 2026 868 views

Question details

The administrator needs to configure multi-factor authentication (MFA) so that a specific group of users authenticates via SMS (phone), while the rest of the organization continues using the Microsoft Authenticator app.

How to Set Up SMS MFA and Microsoft Authenticator for Different Users
Product
Microsoft Entra
Device & OS
not provided
Scenario
Configuring varying MFA methods for different user groups within an organization.
Observed behavior
The admin wants granular control over MFA methods, including and excluding specific users for SMS and App-based authentication, without applying a one-size-fits-all policy.
Before you start

Ensure you have at least Authentication Policy Administrator privileges in the Microsoft Entra admin center to modify these global authentication settings.

Solution 1Recommended

Configure Authentication Methods Policies in Entra ID

Use the Microsoft Entra admin center to explicitly include or exclude specific user groups for SMS and Microsoft Authenticator methods.

By utilizing the granular policies within Microsoft Entra ID, you can designate exactly which users or groups are permitted to use specific authentication methods, allowing for a hybrid MFA environment.

1
Access Authentication Methods

Sign in to the Microsoft Entra admin center. In the left navigation pane, browse to Protection > Authentication methods > Policies.

2
Configure Microsoft Authenticator

Click on the 'Microsoft Authenticator' policy. Under the 'Enable and Target' tab, toggle the status to Enable. Use the 'Include' and 'Exclude' options to target the groups of users who should use the app for authentication.

3
Configure SMS Authentication

Return to the Policies list and click on the 'SMS' policy. Toggle its status to Enable, and assign it exclusively to the specific subset of users or groups who require phone-based authentication.

4
Save Changes

Click 'Save' on both policy pages to apply the changes to your tenant.

Configure Authentication Methods Policies in Entra ID
Security Note: SMS is generally less secure than app-based MFA. Use it only when strictly necessary and permitted by your organizational security policy.
Free Microsoft Office alternative

Need a Lightweight Office Alternative? Try WPS Office

While managing complex Microsoft 365 security policies like MFA, you might be looking for a simpler, cost-effective office suite for your team. WPS Office offers robust document creation with seamless Microsoft format compatibility.

Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Free and lightweight, reducing deployment complexity across your organization.Familiar user interface for a smooth transition with zero training curve.
QA img-9

Frequently Asked Questions

Why is Microsoft Authenticator still prompting users who are assigned to SMS?

This usually happens if 'Security Defaults' are enabled in your Microsoft tenant, which globally forces all users to register for the Authenticator app regardless of specific policies. You must disable Security Defaults and use Conditional Access to prevent this.

Can I set a default authentication method for users who have multiple options?

If 'System-preferred MFA' is enabled, Microsoft Entra automatically chooses the most secure registered method for the user (Authenticator over SMS). Users cannot manually set a default method if system-preferred MFA is active.

How do I stop the 'Help us protect your account' prompt for SMS users?

You need to exclude those specific users from the Microsoft Authenticator Registration Campaign. You can do this in the Entra Admin Center under Protection > Authentication methods > Registration campaign by adding the SMS-only user group to the Exclude list.