Skip to content

Commit 7723b13

Browse files
authored
Merge pull request #67188 from MicrosoftDocs/master
Publish for AAD
2 parents 75fef81 + 8900412 commit 7723b13

File tree

753 files changed

+2950
-2820
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

753 files changed

+2950
-2820
lines changed

.openpublishing.redirection.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17494,6 +17494,16 @@
1749417494
"redirect_url": "/azure/active-directory/active-directory-reporting-risk-events",
1749517495
"redirect_document_id": false
1749617496
},
17497+
{
17498+
"source_path": "articles/active-directory/authentication/concept-registration-mfa-sspr-converged.md",
17499+
"redirect_url": "/azure/active-directory/authentication/concept-registration-mfa-sspr-combined",
17500+
"redirect_document_id": true
17501+
},
17502+
{
17503+
"source_path": "articles/active-directory/authentication/howto-registration-mfa-sspr-converged-troubleshoot.md",
17504+
"redirect_url": "/azure/active-directory/authentication/howto-registration-mfa-sspr-combined-troubleshoot",
17505+
"redirect_document_id": true
17506+
},
1749717507
{
1749817508
"source_path": "articles/active-directory/active-directory-reporting-activity-sign-ins-mfa.md",
1749917509
"redirect_url": "/azure/active-directory/authentication/howto-mfa-reporting",

articles/active-directory-b2c/active-directory-b2c-reference-policies.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,6 @@ Only the **otherMails** and **signInNames** properties are exposed through the A
8181

8282
## Next steps
8383

84-
To create the recommended user flows, follow the instructions in [Tutorial: Create a user flow](tutorial-create-tenant.md).
84+
To create the recommended user flows, follow the instructions in [Tutorial: Create a user flow](tutorial-create-user-flows.md).
8585

8686

articles/active-directory/authentication/TOC.yml

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -25,8 +25,8 @@
2525
items:
2626
- name: Authentication methods
2727
href: concept-authentication-methods.md
28-
- name: Converged registration
29-
href: concept-registration-mfa-sspr-converged.md
28+
- name: Combined registration
29+
href: concept-registration-mfa-sspr-combined.md
3030
- name: Password reset
3131
items:
3232
- name: How password reset works
@@ -103,6 +103,12 @@
103103
href: howto-mfa-nps-extension-rdg.md
104104
- name: VPN
105105
href: howto-mfa-nps-extension-vpn.md
106+
- name: Combined registration
107+
items:
108+
- name: Enable combined registration
109+
href: howto-registration-mfa-sspr-combined.md
110+
- name: Troubleshoot combined registration
111+
href: howto-registration-mfa-sspr-combined-troubleshoot.md
106112
- name: Azure AD password protection
107113
items:
108114
- name: Configure the banned password list
@@ -190,8 +196,6 @@
190196
href: howto-mfa-nps-extension-errors.md
191197
- name: Troubleshoot
192198
items:
193-
- name: Disable converged registration
194-
href: howto-registration-mfa-sspr-converged-troubleshoot.md
195199
- name: Troubleshoot SSPR
196200
href: active-directory-passwords-troubleshoot.md
197201
- name: SSPR FAQ

articles/active-directory/authentication/concept-authentication-methods.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ services: active-directory
66
ms.service: active-directory
77
ms.subservice: authentication
88
ms.topic: conceptual
9-
ms.date: 01/31/2018
9+
ms.date: 02/20/2019
1010

1111
ms.author: joflore
1212
author: MicrosoftGuyJFlo
@@ -226,6 +226,6 @@ If your organization is federated for SSO with Azure AD and you are going to be
226226

227227
[Enable Azure Multi-Factor Authentication for your organization](howto-mfa-getstarted.md)
228228

229-
[Enable converged registration for Azure Multi-Factor Authentication and Azure AD self-service password reset](concept-registration-mfa-sspr-converged.md)
229+
[Enable combined registration in your tenant](howto-registration-mfa-sspr-combined.md)
230230

231231
[End-user authentication method configuration documentation](https://aka.ms/securityinfoguide)
Lines changed: 137 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,137 @@
1+
---
2+
title: Combined registration for Azure AD SSPR and MFA (preview)
3+
description: Azure AD Multi-Factor Authentication and self-service password reset registration (preview)
4+
5+
services: active-directory
6+
ms.service: active-directory
7+
ms.subservice: authentication
8+
ms.topic: conceptual
9+
ms.date: 02/20/2019
10+
11+
ms.author: joflore
12+
author: MicrosoftGuyJFlo
13+
manager: daveba
14+
ms.reviewer: sahenry
15+
16+
ms.collection: M365-identity-device-management
17+
---
18+
# Combined security information registration (preview)
19+
20+
Before combined registration, users registered authentication methods for Azure Multi-Factor Authentication (MFA) and self-service password reset (SSPR) through two different experiences. People were confused that similar methods were used for both Azure MFA and SSPR but they had to register for each feature separately. Now, with combined registration, users can register once and get the benefits of both Azure MFA and SSPR.
21+
22+
![Combined security information - My Profile showing registered Security info for a user, including Microsoft Authenticator and Phone for a sample user in the directory.](media/concept-registration-mfa-sspr-combined/combined-security-info-defualts-registered.png)
23+
24+
Before enabling the new experience, review this administrator-focused documentation and the user-focused documentation to ensure you understand the functionality and impact of this feature. Base your training on the user documentation to prepare your users for the new experience and help to ensure a successful rollout.
25+
26+
| |
27+
| --- |
28+
| Combined security information registration for Azure Multi-Factor Authentication and Azure AD self-service password reset is a public preview feature of Azure Active Directory. For more information about previews, see [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/)|
29+
| |
30+
31+
> [!IMPORTANT]
32+
> If a user is enabled for both the original preview and the enhanced combined registration experience, they will see the new experience. Users who are enabled for both experiences will only see the new My Profile experience. The new My Profile aligns with the look and feel of combined registration and provides a seamless experience for users. Users can see My Profile by going to [https://myprofile.microsoft.com](https://myprofile.microsoft.com).
33+
34+
![My Profile interface showing Security info and ability for user to setup SSPR or other additional security verification methods.](media/howto-registration-mfa-sspr-combined/combined-security-info-my-profile.png)
35+
36+
## Methods available in converged registration
37+
38+
At this time, combined registration supports the following methods and actions for those methods:
39+
40+
| | Register | Change | Delete |
41+
| --- | --- | --- | --- |
42+
| Microsoft Authenticator | Yes (max 5) | No | Yes |
43+
| Other authenticator app | Yes (max 5) | No | Yes |
44+
| Hardware token | No | No | Yes |
45+
| Phone | Yes | Yes | Yes |
46+
| Alternate phone | Yes | Yes | Yes |
47+
| Office phone | No | No | No |
48+
| Email | Yes | Yes | Yes |
49+
| Security questions | Yes | No | Yes |
50+
| App passwords | Yes | No | Yes |
51+
52+
> [!NOTE]
53+
> App passwords are only available to users who have been enforced for MFA. App passwords are not available to users who are enabled for MFA via a conditional access policy.
54+
55+
Users can set the following options as their default method for MFA:
56+
57+
- Microsoft Authenticator – notification
58+
- Authenticator app or hardware token – code
59+
- Phone call
60+
- Text message
61+
62+
As we continue to add more authentication methods such to Azure AD, those methods will be available in combined registration.
63+
64+
## Combined registration Modes
65+
66+
There are two “modes” of combined registration: interrupt and manage.
67+
68+
Interrupt mode, is a wizard-like experience, shown to a user when they register or refresh their security info at sign in.
69+
70+
Manage mode is part of the user’s profile and allows them to manage their security info.
71+
72+
For both modes, if a user has previously registered a method that can be used for MFA, they will need to perform MFA before they can access their security info.
73+
74+
### Interrupt mode
75+
76+
Combined registration respects both MFA and SSPR policies, if both are enabled for your tenant. These policies control, whether a user is interrupted to register during sign in, and which methods are available to register.
77+
78+
The following list several scenarios where a user may be prompted to register or refresh their security info:
79+
80+
* MFA registration enforced through Identity Protection: Users will be asked to register during sign in. They register MFA methods and SSPR methods (if the user is enabled for SSPR).
81+
* MFA registration enforced through per-user MFA: Users will be asked to register during sign in. They register MFA methods and SSPR methods (if the user is enabled for SSPR).
82+
* MFA registration enforced through conditional access or other policies: Users are asked to register when accessing a resource that requires MFA. Users will register MFA methods and SSPR methods (if the user is enabled for SSPR).
83+
* SSPR registration enforced: Users are asked to register during sign in. They only register SSPR methods
84+
* SSPR refresh enforced: Users are required to review their security info at an interval set by the admin. Users are shown their info and can choose "Looks good" or make changes if needed.
85+
86+
When registration is enforced, users are shown the minimum number of methods needed to be compliant with both MFA and SSPR policies from most to least secure.
87+
88+
Example:
89+
90+
* A user is enabled for SSPR. The SSPR policy required two methods to reset and has enabled mobile app code, email, and phone.
91+
* This user is required to register two methods.
92+
* They're shown authenticator app and phone by default.
93+
* The user can choose to register email instead of authenticator app or phone.
94+
95+
The following flowchart describes which methods are shown to a user when interrupted to register during sign in:
96+
97+
![Combined security info flow chart explaining number of methods required when More information is required when signing in. This can change if only MFA or only SSPR is required](media/concept-registration-mfa-sspr-combined/combined-security-info-flow-chart.png)
98+
99+
If you have both MFA and SSPR enabled, we recommend that you enforce MFA registration.
100+
101+
If the SSPR policy requires users to review their security info at a regular interval, users are interrupted during sign in and shown all their registered methods. They can choose “Looks good” if the info is up-to-date or they can choose “Edit info” to make changes.
102+
103+
### Manage mode
104+
105+
Users can access manage mode by going to [https://aka.ms/mysecurityinfo](https://aka.ms/mysecurityinfo) or by choosing “Security info” from My Profile. From there, users can add methods, delete or change existing methods, change their default method, and more.
106+
107+
## Key usage scenarios
108+
109+
### Set up security info during sign in
110+
111+
An admin has enforced registration.
112+
113+
A user has not set up all required security info and navigates to the Azure portal. After entering their username and password, the user is prompted to set up security info. The user then follows the steps shown in the wizard to set up the required security info. The user can choose to set up methods other than what is shown by default if your settings allow. At the end of the wizard, the user reviews the methods they set up and their default method for MFA. To complete the setup process, the user confirms the info and continues to the Azure portal.
114+
115+
### Set up security info from My Profile
116+
117+
An admin has not enforced registration.
118+
119+
A user who has not yet set up all required security info navigates to [https://myprofile.microsoft.com](https://myprofile.microsoft.com). The user then chooses **Security info** from the left-hand navigation. From there, the user chooses to add a method, selects any of the methods available to them, and follows the steps to set up that method. When finished, the user sees the method they just set up on the security info page.
120+
121+
### Delete security info from My Profile
122+
123+
A user who has previously set up at least one method navigates to [https://aka.ms/mysecurityinfo](https://aka.ms/mysecurityinfo). The user chooses to delete one of the previously registered methods. When finished, the user no longer sees that method on the security info page.
124+
125+
### Change default method from My Profile
126+
127+
A user who has previously set up at least one method that can be used for MFA navigates to [https://aka.ms/mysecurityinfo](https://aka.ms/mysecurityinfo). The user changes their current default method to a different default method. When finished, the user sees their new default method on the security info page.
128+
129+
## Next steps
130+
131+
[Enable combined registration in your tenant](howto-registration-mfa-sspr-combined.md)
132+
133+
[Available methods for MFA and SSPR](concept-authentication-methods.md)
134+
135+
[Configure self-service password reset](howto-sspr-deployment.md)
136+
137+
[Configure Azure Multi-Factor Authentication](howto-mfa-getstarted.md)

articles/active-directory/authentication/concept-registration-mfa-sspr-converged.md

Lines changed: 0 additions & 94 deletions
This file was deleted.

0 commit comments

Comments
 (0)