logo
search
MFA Security Issues

Is Microsoft Authenticator Required for Enterprise Two-Factor Authentication?

Algirdas JasaitisAlgirdas Jasaitis Sep 25, 2026 869 views

Question details

The user is inquiring whether the Microsoft Authenticator app is the only option for enterprise two-factor authentication, specifically for employees who do not have a mobile phone.

Is Microsoft Authenticator Required for Enterprise Two-Factor Authentication?
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Configuring enterprise two-factor authentication (MFA) for users who lack a smartphone or cannot install the Microsoft Authenticator app.
Observed behavior
Users need to fulfill MFA requirements but cannot use a mobile app, prompting administrators to look for fallback authentication methods.
Before you start

Ensure you have access to the Microsoft Entra admin center with at least Authentication Policy Administrator privileges to view and modify organizational MFA settings.

Solution 1Recommended

Enable Alternative Authentication Methods in Microsoft Entra ID

Microsoft Entra ID supports multiple authentication methods beyond the Authenticator app, such as hardware keys, temporary passes, and phone calls. Administrators can configure these options for users without smartphones.

Microsoft Authenticator is highly recommended for security, but it is not strictly mandatory. Entra ID administrators can deploy several alternative options based on user requirements and hardware availability.

1
Sign in to the Admin Center

Log in to the Microsoft Entra admin center using your administrator credentials.

2
Navigate to Authentication Methods

On the left sidebar, expand the 'Protection' menu and select 'Authentication methods', then click on 'Policies'.

3
Select an Alternative Method

Review the available methods from the list. Click on an alternative method such as 'FIDO2 security key', 'OATH hardware tokens', or 'Temporary Access Pass'.

4
Enable and Target Users

Toggle the 'Enable' switch to 'Yes'. Under the 'Target' tab, select 'All users' or specify a particular group of users who need this alternative method, then click 'Save'.

Enable Alternative Authentication Methods in Microsoft Entra ID
Phone Call Authentication Limitation: If you choose to enable phone-call authentication to an office phone, be aware that automated Microsoft systems typically do not support dialing extensions. Users will need a direct inward dialing (DID) number, or you should provide hardware tokens instead.
Free Microsoft Office alternative

Need a Lightweight Office Suite for Your Enterprise?

While you manage security and MFA policies for your organization, you might also be looking for cost-effective productivity tools. WPS Office is a free, highly compatible alternative to Microsoft Office that meets enterprise document needs without heavy licensing costs.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button.
  2. 2. Install WPS Office: Run the downloaded executable file and follow the quick setup wizard.
  3. 3. Start Creating Documents: Open WPS Office and immediately start editing your existing DOCX, XLSX, and PPTX files with complete formatting preservation.
Seamless compatibility with Microsoft Word, Excel, and PowerPoint formats.Lightweight architecture ensuring fast performance even on older devices.Familiar user interface that requires zero learning curve for seamless team migration.Cost-effective solution ideal for businesses looking to optimize their software budget.
microsoft office alternative - wps office

Frequently Asked Questions

What should I do if an employee doesn't own a smartphone for MFA?

Administrators can issue FIDO2 security keys, OATH hardware tokens, or configure a Temporary Access Pass (TAP) for employees who cannot use smartphone authenticator apps.

Can I use an office landline for Microsoft Entra ID authentication?

Yes, phone call authentication is supported. However, the system does not accommodate phone extensions, so the user must have a direct line to receive the authentication call.

Are third-party authenticator apps supported in Microsoft Entra?

Yes. Microsoft Entra ID supports any third-party authenticator app that uses the OATH TOTP (Time-based One-Time Password) standard, provided the administrator has enabled this option in the authentication policies.

What is a Temporary Access Pass (TAP)?

A Temporary Access Pass is a time-limited passcode issued by an IT administrator. It allows a user to sign in securely without a password to register other MFA methods, such as a security key or the Microsoft Authenticator app.