1608 - Supported Entra ID object attributes: Authentication method policies

Modified on Tue, 5 Aug at 1:09 PM

Page contents

 

Supported attributes by policy

Email OTP

AttributeDescriptionBacked upRestorable
allowExternalIdToUseEmailOtpDetermines whether email OTP is usable by external users for authentication.YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes

 

X.509

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not. YesYes
authenticationModeConfigurationDefines strong authentication configurations, including the default authentication mode and the different rules for strong authentication bindings.YesYes
certificateUserBindingsDefines fields in the X.509 certificate that map to attributes of the Entra user object in order to bind the certificate to the user.YesYes
crlValidationConfigurationDetermines whether certificate-based authentication should fail if the issuing CA doesn't have a valid certificate revocation list configured.YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

FIDO2

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes
isAttestationEnforcedDetermines whether attestation must be enforced for FIDO2 security key registration.YesYes
isSelfServiceRegistrationAllowedDetermines if users can register new FIDO2 security keys.YesYes
keyRestrictionsControls whether key restrictions are enforced on FIDO2 security keys, either allowing or disallowing certain key types as defined by Authenticator Attestation GUID (AAGUID), an identifier that indicates the type (e.g. make and model) of the authenticator.YesYes
keyRestrictions>isEnforcedDetermines if the configured key enforcement is enabled.YesYes
enforcementType>enforcementTypeEnforcement type. Possible values are: allow, block.YesYes
keyRestrictions>aaGuidsA collection of Authenticator Attestation GUIDs. AADGUIDs define key types and manufacturersYesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

Microsoft Authenticator

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not. Possible values are: enabled, disabled.YesYes
isSoftwareOathEnabledtrue if users can use the OTP code generated by the Microsoft Authenticator app, false otherwise.YesYes
featureSettingsA collection of Microsoft Authenticator settings such as number matching and location context, and whether they are enabled for all users or specific users only.YesYes
featureSettings>
companionAppAllowedState
Determines whether users are able to approve push notifications on other Microsoft applications such as Outlook Mobile.YesYes
featureSettings>
displayAppInformationRequiredState
Determines whether the user's Authenticator app shows them the client app they're signing into.YesYes
featureSettings>
displayLocationInformationRequiredState
Determines whether the user's Authenticator app shows them the geographic location of where the authentication request originated from.YesYes
featureSettings>
numberMatchingRequiredState
Specifies whether the user needs to enter a number in the Authenticator app from the login screen to complete their login. Value is ignored for phone sign-in notifications.YesNo
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

SMS authentication

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

Temporary Access Pass

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes
defaultLengthDefault length in characters of a Temporary Access Pass object. YesYes
defaultLifetimeInMinutesDefault lifetime in minutes for a Temporary Access Pass.YesYes
isUsableOnceIf true, all the passes in the tenant will be restricted to one-time use. If false, passes in the tenant can be created to be either one-time use or reusable.YesYes
minimumLifetimeInMinutesMinimum lifetime in minutes for any Temporary Access Pass created in the tenant.YesYes
maximumLifetimeInMinutesMaximum lifetime in minutes for any Temporary Access Pass created in the tenant.YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

Voice authentication

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes
isOfficePhoneAllowedtrue if users can register office phones, otherwise, false.YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

Software OATH

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

Hardware OATH

Note: hardwareOathTokenAuthenticationMethodDevice is not supported as an authentication method policy. 

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

External authentication method

AttributeDescriptionBacked upRestorable
idThe authentication method policy identifier. Inherited from authenticationMethodConfiguration.YesNo
stateIndicates whether this authentication method is enabled or not.YesYes
appIdappId for the app registration in Entra ID representing the integration with the external provider. YesYes
displayNameDisplay name for the external authentication method.YesYes
openIdConnectSettingOpenID Connect settings used by this external authentication method. YesYes
excludeTargetsGroups of users that are excluded from the policy.YesYes

 

Supported relationships

IncludeTargets
AssignTo

 

Note:

  • Due to API limitations, we do not back up or restore actual passwords, hints, certificates or credentials. After restoring, you will need to create the passwords, certificates and client secrets manually. 
  • Read about the limitations of Entra ID object recovery in Article 1554.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article