#IDentity Microsoftie, PM for strong authentication keeping bad guys out of your account, climbing mountains on the weekend. All opinions my own. he/him/his
@TokenTwo @guillaumeQD @notameadow@NateePretikul@Alex_A_Simons That setting controls which app approval mode can be used, but not TOTP. To ensure TOTP is turned off, you can go to the old MFA and SSPR policy UXes and disable it there too. We're working on bringing all of those controls into the new policy but they're separate for now.
@dotMudge I will say, the Office365 + Microsoft Authenticator app solution now is super mature and easier than SMS. If you have an old tenant make sure you follow modernization guides to flip on all the new user features and consolidation of enrollment.
@BaarsDylan@inbarck Not at a policy level, but this will let you remove phone numbers from individual users. The request to disable methods on a per-user basis is noted, though!
@MrAzureAD Not sad, just not built yet! We're building mgmt APIs for all methods, phone is just the first to ship. Good suggestion on the cross-ref link, I can run with that.