MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.28k stars 21.45k forks source link

Add details on "Non-usable authentication methods" #109068

Closed larasawalha90 closed 1 year ago

larasawalha90 commented 1 year ago

Hello,

We received multiple requests to explain what are "Non-usable authentication methods" under Authentication methods for each user in Azure portal.

Can you please add more details what are "Non-usable authentication methods" on this public article or an explanation that if an administrator required re-register MFA for a user their current authentication methods will be under "Non-usable authentication methods" until the method is deleted or registered again?


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

ManoharLakkoju-MSFT commented 1 year ago

@larasawalha90 Thanks for your feedback! We will investigate and update as appropriate.

ManoharLakkoju-MSFT commented 1 year ago

@Justinha Can you please check and add your comments on this doc update request as applicable.

ManoharLakkoju-MSFT commented 1 year ago

@larasawalha90 Thanks for bringing this to our attention. I'm going to assign this to the document author so they can take a look at it accordingly

larasawalha90 commented 1 year ago

@ManoharLakkoju-MSFT Thank you for the reply and appreciate your help in making this clear to our customer

Justinha commented 1 year ago

sorry for delay and thanks for raising this. I created an internal work item for SMEs to review and update the topic as needed. #please-close

MrTechGadget commented 1 year ago

This still has not been addressed. WTF is a non-usable MS authenticator app?

moogs37 commented 1 year ago

Can we get an update on this? This is impacting people's ability to log in.

ImNotIT commented 1 year ago

Ask the user if they have passcode disabled on their iPhone, this worked for me.

Justinha commented 1 year ago

@larasawalha90 @MrTechGadget @moogs37 @ImNotIT The reason why a method is unusable is listed under Detail in the admin center. If you don't see a reason listed, please contact Microsoft support. For more info, please see https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods#usable-and-non-usable-methods

MrTechGadget commented 1 year ago

Thank you, I see you added this verbiage in June which does not address the issue, which is that there is no explanation for what a non-usable state is, how their authenticator app that has been usable for months or years suddenly became "non-usable", and no instructions for how a user can restore their authenticator app to a "usable" state. Appreciate the continued lack of good support for these products /s Please notice that the website is called learn.microsoft.com. It isn't unreasonable for people to expect good documentation.

On Thu, Oct 5, 2023 at 9:54 AM Justin Hall @.***> wrote:

@larasawalha90 https://github.com/larasawalha90 @MrTechGadget https://github.com/MrTechGadget @moogs37 https://github.com/moogs37 @ImNotIT https://github.com/ImNotIT The reason why a method is unusable is listed under Detail in the admin center. If you don't see a reason listed, please contact Microsoft support. For more info, please see https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods#usable-and-non-usable-methods

— Reply to this email directly, view it on GitHub https://github.com/MicrosoftDocs/azure-docs/issues/109068#issuecomment-1748949548, or unsubscribe https://github.com/notifications/unsubscribe-auth/AECUW5IDTYW4TIGKEWDSM5TX523YXAVCNFSM6AAAAAAXVJVZGCVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMYTONBYHE2DSNJUHA . You are receiving this because you were mentioned.Message ID: @.***>

fenice80 commented 5 months ago

We are implementing MFA in our company and from entra ID we see:

1.6k Users registered by authentication methiod BUT 868 "Users capable of Azure multifactor authenticantion"

it means that half of registered users for a reason arent able to can use MFA !

It is very important to be able identify the list of those users to manage, mitigate and understand the source of the problem.

Please, implement the opportunity to extract these users.

thanks