Message Center
Updated July 9, 2026: We have updated this post as a reminder. Thank you for your patience.
What and Why
As announced in the What's New (June Edition), we have been rolling out first-factor system-preferred authentication in the Microsoft-managed state.
System-preferred authentication in Microsoft Entra ID now applies to both first-factor and second-factor authentication when the setting is in the Microsoft managed state.
The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step, prompting the user to sign in with the most secure available method.
Rollout schedule
Impact on your organization
Who is affected
Platforms and services
What will happen
Behavior by setting state:
Note: This prompt does not mean the user is being asked to complete multifactor authentication (MFA) when MFA is not required. With this update, Microsoft Entra can prompt users to use their most secure available credential at first-factor sign-in instead of defaulting to a password. Some methods, such as passkeys, certificate-based authentication, or Microsoft Authenticator, can satisfy first-factor sign-in requirements and may also satisfy MFA requirements when MFA is required. The goal is to use the strongest available credential consistently, not to add an extra MFA prompt.
What you need to do to prepare:
Review whether you want system-preferred authentication to apply to first-factor authentication in your tenant:
Learn more
Compliance considerations
No compliance considerations identified, review as appropriate for your organization.
What and Why
As announced in the What's New (June Edition), we have been rolling out first-factor system-preferred authentication in the Microsoft-managed state.
System-preferred authentication in Microsoft Entra ID now applies to both first-factor and second-factor authentication when the setting is in the Microsoft managed state.
The system evaluates which credentials are registered for the user and selects the highest-ranked method for each authentication step, prompting the user to sign in with the most secure available method.
Rollout schedule
Impact on your organization
Who is affected
Platforms and services
What will happen
Behavior by setting state:
Note: This prompt does not mean the user is being asked to complete multifactor authentication (MFA) when MFA is not required. With this update, Microsoft Entra can prompt users to use their most secure available credential at first-factor sign-in instead of defaulting to a password. Some methods, such as passkeys, certificate-based authentication, or Microsoft Authenticator, can satisfy first-factor sign-in requirements and may also satisfy MFA requirements when MFA is required. The goal is to use the strongest available credential consistently, not to add an extra MFA prompt.
What you need to do to prepare:
Review whether you want system-preferred authentication to apply to first-factor authentication in your tenant:
Learn more
Compliance considerations
No compliance considerations identified, review as appropriate for your organization.