

The Email OTP isn't relevant for my questions.įirst question: I have a few global admin users and those users can use the software TOTP feature in our password manager and are not required to use Microsoft Authenticator. Under Authentication methods for MFA I have "Microsoft Authenticator" Enabled = Yes and Targeted to "All Users." All other methods are Enabled = No which is the default other than Email OTP which I believe is required for Guest users to login to a SharePoint site or something like that. I have enabled all the suggested default CA policies that enable all the things the Security Defaults does.


I have security defaults turned off as I'm using conditional access. I have read Microsoft's documentation and I'm not getting a clear answer, or maybe I'm not understanding how these work.
