Microsoft Entra ID
Authentication

System-preferred authentication in Microsoft Entra ID

In brief

The article date was updated to October 7, 2026, and the note about gradual Microsoft-managed deployment through September 2026 was removed.

What Entra admins need to know

Administrators will no longer see the September 2026 rollout described as ongoing; no action is stated as required.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

System-preferred authentication is a Microsoft managed setting, which is a three-state policy (enabled, disabled, or Microsoft managed). If you don't want to enable system-preferred authentication, change the state from Microsoft managed to Disabled, or exclude users and groups from the policy.

After system-preferred authentication is enabled, the authentication system does all the work. Users don't need to set any authentication method as their default because the system always determines and presents the most secure method they registered.

How system-preferred authentication applies to sign-in

After system-preferred authentication is enabled, the authentication system does all the work. Users don't need to set any authentication method as their default because the system always determines and presents the most secure method they registered.

How system-preferred authentication applies to sign-in

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…