System-preferred authentication in Microsoft Entra ID
In brief
The documentation now states that Microsoft-managed system-preferred authentication deployment will continue through September 2026, rather than August 2026.
What Entra admins need to know
Administrators should account for the revised rollout timeline when monitoring tenant and user behavior.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: System-preferred authentication in Microsoft Entra ID
description: Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both first-factor and second-factor authentication.
ms.topic: overview
ms.date: 04/15/09/01/2026
ms.reviewer: msft-poulomi
ms.custom: msecd-doc-authoring-1012
ai-usage: ai-assisted
System-preferred authentication is a Microsoft managed setting, which is a three-state policy (enabled, disabled, or Microsoft managed). If you don't want to enable system-preferred authentication, change the state from Microsoft managed to Disabled, or exclude users and groups from the policy.
After system-preferred authentication is enabled, the authentication system does all the work. Users don't need to set any authentication method as their default because the system always determines and presents the most secure method they registered.
@@ -2,7 +2,7 @@ title: System-preferred authentication in Microsoft Entra ID description: Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both first-factor and second-factor authentication. ms.topic: overview-ms.date: 04/15/2026+ms.date: 09/01/2026 ms.reviewer: msft-poulomi ms.custom: msecd-doc-authoring-1012 ai-usage: ai-assisted@@ -19,7 +19,7 @@ For example, if a user registered both a password and a passkey, system-preferre System-preferred authentication is a Microsoft managed setting, which is a [three-state policy](#authentication-method-feature-configuration-properties) (enabled, disabled, or Microsoft managed). If you don't want to enable system-preferred authentication, change the state from **Microsoft managed** to **Disabled**, or exclude users and groups from the policy. > [!NOTE]-> The **Microsoft managed** state behavior affects both first-factor and multifactor authentication and is being gradually deployed to tenants through August 2026. If your tenant or users don't experience system-preferred authentication as the first factor when the **State** is **Microsoft managed**, the rollout isn't deployed yet for your tenant.+> The **Microsoft managed** state behavior affects both first-factor and multifactor authentication and is being gradually deployed to tenants through September 2026. If your tenant or users don't experience system-preferred authentication as the first factor when the **State** is **Microsoft managed**, the rollout isn't deployed yet for your tenant. After system-preferred authentication is enabled, the authentication system does all the work. Users don't need to set any authentication method as their default because the system always determines and presents the most secure method they registered. 