Learn how to use system-preferred multifactor authentication
External ID guidance clarifies paid SMS limits, customer password recovery, and role permissions; Entra ID MFA guidance also changed
28 February was a documentation-clarification day: all four recorded items were Microsoft Learn updates—three for External ID and one for Entra ID—with no new, removed, or Message Center items. The clearest operational point is that External ID SMS is described as an additional-cost option for second-factor verification and self-service password reset, not first-factor authentication. The evidence does not establish a new feature launch, preview, general-availability change, retirement, or tenant-wide behavior change.
- External ID SMS is documented as paid second-factor and SSPR support only
External ID · Authentication
The updated Multifactor Authentication Customers guidance states that SMS is available at additional cost for second-factor verification and self-service password reset in external tenants, but is not currently supported for first-factor authentication. This is a documented support and cost boundary, not evidence of a newly launched capability.
- Email OTP guidance clarifies the customer self-service recovery path
External ID · Authentication
The updated Email OTP page says customers can change or reset their passwords without administrator or help-desk involvement. It also describes prompts that let customers unblock themselves after an account lockout or forgotten password. The record clarifies the recovery experience but does not identify a new availability or behavior change.
- External ID role and default-permission guidance is clarified
External ID · Fundamentals
The updated Supported Features Customers page states that roles and administrators are supported for administrative and user accounts, roles are supported for all users, and users in an external tenant have default permissions unless assigned an admin role. Administrators should check designs that depend on default permissions or explicit admin-role assignment.
- System-preferred MFA guidance was updated without a specified product change
Entra ID · Authentication
The Entra ID System-preferred multifactor authentication page was updated with guidance on how to use the capability. The supplied record gives no detail about changed policy, availability, configuration, or rollout status, so it should be treated as an ordinary documentation update rather than evidence of a launch, preview, retirement, or behavior change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
4 updates
Microsoft Entra ID
1 updateMicrosoft Entra External ID
3 updatesSMS is available at an additional cost for second-factor verification and for self-service password reset in external tenants. It isn't currently supported for first-factor authentication.
Email OTP
UpdatedSelf-service password reset (SSPR) in Microsoft Entra External ID gives customers the ability to change or reset their password, with no administrator or help desk involvement. If a customer's account is locked or they forget their password, they can follow prompts to unblock themselves and get back to work.
Supported Features Customers
Updated| **Roles and administrators**| [Roles and administrators](~/fundamentals/how-subscriptions-associated-directory.md) are fully supported for administrative and user accounts. | Roles are supported for all users. All users in an external tenant have [default permissions](reference-user-permissions.md) unless they’re assigned an [admin role](how-to-manage-admin-accounts.md).|
