Introduction
Microsoft Authenticator is an authenticator application that integrates natively with Entra (Microsoft's cloud native IAM solution). It also may act as a general time-based one-time password (TOTP) provider.
This guide is for adding your Cochran account to Microsoft Authenticator. But it should also work for most Entra accounts and Microsoft accounts if adjusted.
Note: The images in this guide were taken from Apple iOS. There may be minor variances for Android or future versions of Apple iOS.
Requirements
- A mobile device that supports Microsoft Authenticator. Most current Apple / iOS devices and Android devices will work.
- A current and active Entra account. A Cochran account is a good example of this.
- For QR code-based configuration only: another device with web access. A PC or a tablet are good examples.
Process Overview
- Install Microsoft Authenticator app if it is not installed.
- Open Microsoft Authenticator, step through welcome prompts.
- Prepare to scan QR code if that option is available to you.
- Configure Microsoft Authenticator.
- Recommended - upgrade your authenticator connection to password-less sign-in.
Install Microsoft Authenticator
- For most devices Microsoft Authenticator was administratively pre-installed, feel free to check for it.
- Open the App Store for your device.
- Locate Microsoft Authenticator. Be sure that the publisher is Microsoft - competing 3rd party publishers may pay to be listed ahead of this official application.
The icon looks like a blue shield / padlock. - Install the application.
First launch
This only applies if you are launching Microsoft Authenticator for the first time on a particular device. Skip ahead to your configuration option if you have used Microsoft Authenticator on this device before.
- Locate the app tile for Microsoft Authenticator and then tap to open it.
- Read the informational greeting and proceed.
- If you wish, you may opt-in to providing telemetry data to Microsoft to assist in developing the Microsoft Authenticator application. Default selection is opt-out. Proceed after you decide.
- Select Work or School from the options.
- Select Scan QR code. Allow camera access if prompted.
QR code based configuration
On your mobile device
- Open the Microsoft Authenticator application if it is not open.
- If you followed the steps above in "First launch" move to the web browser section below. Otherwise:
- Tap the small plus '+' icon near the upper right part of the screen.
- If you don't see the small plus icon, navigate back using the icon '<'
- Select "Work or School"
- Select "Scan QR code" your mobile device is ready to scan the setup QR code.
- If prompted allow camera access
- Tap the small plus '+' icon near the upper right part of the screen.
On another device with a web browser
- Open any web browser.
- Navigate to mysignins.microsoft.com
- Sign-in if prompted.
- Navigate to Security info (menu on the left)
- You should see a list of sign-in methods
- Click the "+ Add sign-in method" button
- Select "Microsoft Authenticator" from the list of options
- This step directs you to install Microsoft Authenticator.
Assuming you installed Microsoft Authenticator already, click "Next" to proceed.- If you did not, please install Microsoft Authenticator and do the initial launch as described above.
- This step directs you to step through the initial prompts, which you should have done already.
Click Next to proceed. - A QR code should be displayed. Switch back to your mobile device.
- If a QR code was not displayed, then something went wrong. Please contact IT.
On your mobile device
- Unlock your device if you need to.
- Launch the Microsoft Authenticator app if it is not already in the foreground.
- If you did not get Microsoft Authenticator in the QR code scan state described in the "First launch" section:
- Locate the small + icon in the upper right part of the screen and tap it.
- Select "Work or School account"
- Select "Scan QR code"
- Allow camera access if prompted.
- Scan the QR code displayed on your browser with your mobile device camera.
- Allow notifications if prompted. You may need to repeat the above steps if notifications were disabled, and you had to enable them in Settings.
- The authenticator account should be added but must be verified.
Switch back to your other web browser device but keep your mobile device ready.
Coordinating between both devices
- You should be looking back at the screen with the QR code. Click the Next button.
- A number should be displayed, and your mobile device should receive a notification.
- Back on your mobile device, enter the number and press the confirmation prompt. Usually "Yes" is the correct confirmation prompt.
- Language and localization settings may result in variances.
- Confirm your mobile device's authentication prompt by entering your device PIN, fingerprint, or face ID.
- Back on your web browser device you should have automatically proceeded past the challenge number to a success prompt. Click "Next" and sometimes "Done". You should see a new sign-in method titled "Microsoft Authenticator"
Congratulations. You have completed required set-up of Microsoft Authenticator.
Device only configuration
Only perform these steps if you are unable to complete Microsoft Authenticator set-up using the QR code method.
- Open the Microsoft Authenticator application. Read and proceed through any introduction prompts that may appear. If prompted to add an account skip that step.
- Tap the + icon (plus sign) in the upper right if you were not prompted to add an account.
- Select "Work or school account" from the menu of choices.
- Select "Sign in" from the menu of choices.
- Enter the email address of the account you wish to add. Then press the Next button.
- Provide the requested authenticators. This will vary depending on your circumstances.
- Read and proceed through any remaining steps.
- If prompted to allow notifications, please do so.
- Verify your newly added account in Microsoft Authenticator is working properly. You should see something similar to the image below. Minor variances are fine.
Recommended - upgrade to password-less
Completing these steps enhances your authenticator account from multi-factor authentication to password-less multi-factor authentication.
- If you're not there currently, open Microsoft Authenticator on your mobile device
- Navigate into your Cochran account.
- Identify the "Set up passwordless sign-in requests" button in the "other ways to sign in" section.
Tap that button. - If the "Set up passwordless sign-in requests" button is not present:
- Password-less may already be configured. If your account has a line near the top that reads "Passwordless sign-in requests" then your authenticator account is already configured for password-less sign-in.
- You might be looking at the wrong authenticator account, if you have multiple double check.
- Your authenticator account might be incorrectly configured. Contact IT for support.
- Follow the on-screen prompts to complete passwordless sign-in configuration. Typically, you must authenticate with password or multi-factor and register the device.
Troubleshooting and help
If you find yourself stuck, or in a sequence of events that repeat, please reach out to helpdesk@cochraninc.com
Loss of Microsoft Authenticator - if you lose the authenticator app after it is set-up it might be difficult to re-configure. If you have a Windows 11 computer then aka.ms/mfasetup should get you going again. Otherwise reach out to helpdesk@cochraninc.com
Comments
0 comments
Article is closed for comments.