Loading...

Microsoft Entra: System-preferred authentication now applies to first-factor authentication

Microsoft Entra: System-preferred authentication now applies to first-factor authentication

Microsoft Entra now applies system-preferred authentication to first-factor sign-in for tenants in the Microsoft managed state, selecting the most secure registered method. Rollout starts late June 2026. Tenants can keep or change this setting and should update user guidance accordingly. What and Why As announced in the What’s New (June Edition), we have been rolling out first-factor system-preferred authentication in the Microsoft-managed state. System-preferred authentication in Microsoft Entra ID now applies to both first-factor and second-factor authentication when the setting is in the Microsoft managed state. The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step, prompting the user to sign in with the most secure available method. Rollout schedule General Availability (Worldwide): Beginning late June 2026 and expected to complete by late July 2026 Impact on your organization Who is affected Organizations whose system-preferred authentication setting is in the Microsoft managed state. If your setting is in the Enabled or Disabled state, first-factor sign-in behavior remains unchanged and there is no impact from this update. Platforms and services Microsoft Entra ID System-preferred authentication User sign-in experiences What will happen For tenants in the Microsoft managed state, the system applies credential ranking to both first-factor and second-factor authentication. When a user signs in, the authentication process checks which authentication methods are registered and prompts the user with the most secure method according to the system-defined order. The method order is dynamic and can update when users register more secure authentication methods, such as a passkey, or as Microsoft updates credential rankings based on evolving security guidance. For example, if a user has both a password and a passkey registered, Microsoft Entra may prompt the user to use the passkey at their next first-factor sign-in instead of the password. To sign in using a different option, users can always cancel and choose another available sign-in method. Behavior by setting state: Microsoft managed: The system applies credential ranking to both first-factor and second-factor authentication. Enabled: Credential ranking applies only to second-factor authentication. First-factor sign-in behavior remains unchanged. Disabled: System-preferred authentication is not applied. […]

The post Microsoft Entra: System-preferred authentication now applies to first-factor authentication appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra: System-preferred authentication now applies to first-factor authentication

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

5 hours ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

5 hours ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

5 hours ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

5 hours ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

5 hours ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

5 hours ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

5 hours ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

5 hours ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

16 hours ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

16 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.