In late 2023, Microsoft Entra began leveraging WhatsApp as an alternate channel to deliver multifactor authentication (MFA) one-time passcodes (OTPs) to users in India and Indonesia. This initiative saw improved deliverability, completion rates, and user satisfaction in both countries. Although the channel was temporarily disabled in India in early 2024, Microsoft is set to re-enable it in December 2024 and expand its use to additional countries.
When Will This Happen?
Starting in December 2024, users in India and other countries may begin receiving MFA text messages via WhatsApp. This feature will be available to users who are enabled to receive MFA text messages as an authentication method and already have WhatsApp installed on their phones. If a user with WhatsApp is unreachable or lacks internet connectivity, the system will quickly fall back to the regular SMS channel. Additionally, users receiving OTPs via WhatsApp for the first time will be notified of the change in behavior via SMS text message.
How Will This Affect Your Organization?
If you are a Microsoft Entra workforce customer currently using text-message authentication, it is recommended to notify your helpdesk about this upcoming change. The sender agent in WhatsApp will be branded as Microsoft with a verified checkmark, ensuring users recognize the legitimacy of the messages.
Organizations that prefer not to use WhatsApp for MFA text messages can disable this authentication method. However, Microsoft highly encourages moving to more modern, secure methods like Microsoft Authenticator and passkeys.
Key Highlights
- WhatsApp Delivery: Users with WhatsApp will receive MFA OTPs directly in the app, with SMS as a fallback if needed.
- Verified Sender: Messages will come from Microsoft with a verified checkmark.
- Enhanced User Experience: Improved deliverability and user satisfaction based on prior implementations in India and Indonesia.
Recommendations
- Inform Your Helpdesk: If you currently use text-message authentication, inform your helpdesk about this change.
- Consider More Secure Methods: Microsoft recommends adopting more secure authentication mechanisms, such as Microsoft Authenticator and passkeys.
What You Need to Do to Prepare
This rollout will happen automatically with no admin action required. You may want to notify your users about this change and update any relevant documentation as appropriate.
Keep Exploring. Happy Learning! ๐