Entra ID: Expansion of WhatsApp as an MFA one-time passcode delivery channel [MC926195]

Entra ID: Expansion of WhatsApp as an MFA one-time passcode delivery channel [MC926195]

Message ID: MC926195

In late 2023, Microsoft Entra started leveraging WhatsApp as an alternate channel to deliver multifactor authentication (MFA) one-time passcodes (OTPs) to users in India and Indonesia. We saw improved deliverability, completion rates, and satisfaction when leveraging the channel in both countries. The channel was temporarily disabled in India in early 2024. Starting early December 2024, we will be re-enabling the channel in India and expanding its use to additional countries.  

[When this will happen:]

Starting December 2024, users in India and other countries may start receiving MFA text messages via WhatsApp. Only users that are enabled to receive MFA text messages as an authentication method and already have WhatsApp on their phone will get this experience. If a user with WhatsApp on their device is unreachable or doesn’t have internet connectivity, they will quickly fall back to the regular SMS channel. In addition, users receiving OTPs via WhatsApp for the first time will be notified of the change in behavior via SMS text message. 

The sender agent in WhatsApp where users will see the OTPs will be branded as Microsoft with a verified checkmark. 


[How this will affect your organization:]

If you’re a Microsoft Entra workforce customer and currently leverage the text-message authentication method, we recommend you notify your helpdesk about this upcoming change.

Additionally, if you don’t want your users to receive MFA text messages through WhatsApp, you may disable text messages as an authentication method in your organization. Please note that we highly encourage organizations move to using more modern, secure methods like Microsoft Authenticator and passkeys in favor of telecom and messaging app methods.

This feature update is available by default.

For more information, see Phone authentication methods in Entra ID.

[What you need to do to prepare:]

This rollout will happen automatically with no admin action required. You may want to notify your users about this change and update any relevant documentation as appropriate.

Source: Microsoft

Show 1 Comment

1 Comment

  1. Mike Rosoft

    What a fascinating update from Microsoft Entra! The expansion of WhatsApp as an MFA one-time passcode delivery channel is like finding a hidden treasure chest in the vast ocean of digital security.

    For admins, this change means a smoother sailing experience in managing user authentication. With improved deliverability and completion rates, you’ll likely spend less time troubleshooting failed OTP deliveries and more time enjoying that well-deserved coffee break! Plus, the verified checkmark next to Microsoft on WhatsApp adds a sprinkle of credibility—like wearing a superhero cape while saving the day in the realm of security.

    Now, for users, this update could feel like upgrading from a flip phone to the latest smartphone. Who wouldn’t want their OTPs delivered through WhatsApp? It’s convenient, quick, and let’s face it, most of us are glued to our messaging apps anyway! The fallback to traditional SMS when connectivity is lacking is like having a safety net—always good to know it’s there if you need it.

    But let’s not forget the importance of keeping the conversation going! What do you all think about this change? Is WhatsApp your preferred method for receiving codes, or do you have a different favorite? Share your thoughts below! Your insights could help others navigate this new feature with a bit more ease. Let’s keep the chat lively!

Leave a Reply

Your email address will not be published. Required fields are marked *