Upgrade Weak Authentication Methods Putting Your Network At Risk
Are business users still relying on insecure authentication methods like SMS, voice calls, or email one-time passwords? At DTS, we strongly recommend moving away from these vulnerable options toward stronger, more secure methods that meet the NIST Authentication Assurance Levels 2 and 3 (AAL2 and AAL3). This practical roadmap will help you phase out weak methods while enforcing stronger, phishing-resistant authentication for better protection.
What Is NIST Authentication Assurance Level (AAL)?
NIST AAL is a widely recognized framework from the National Institute of Standards and Technology that categorizes authentication methods by their security strength:
-
AAL2 (Moderate Assurance): Requires multi-factor authentication using two different types of factors — something you know (password), plus something you have (a mobile authenticator app or security key). This level reduces risks like password theft and simple phishing attacks.
-
AAL3 (High Assurance): Requires multi-factor authentication using cryptographic hardware or software-based authenticators that are phishing-resistant, such as hardware security keys (FIDO2). This level provides the strongest protection, guarding against sophisticated attacks including phishing and credential theft.
Following these levels helps organizations apply authentication methods matched to the sensitivity of resources they protect.
Step-by-Step Roadmap
-
Assess and Define Your Authentication Strategy: Identify which insecure methods you want to retire (SMS, voice calls, email OTP) and which secure methods you want to keep or enable (Microsoft Authenticator app, FIDO2 security keys, passwordless phone sign-in). This clarity helps prevent confusion and lockouts.
-
Enable Stronger Authentication Methods: In Entra ID > Authentication methods > Policies, activate authentication options that meet AAL2/AAL3 standards, for example Microsoft Authenticator (push notifications or TOTP codes), FIDO2 security keys, and passwordless phone sign-in.
-
Communicate and Support Users: Notify business units and users well in advance about upcoming changes. Provide clear instructions and support to help them register and start using the new authentication methods.
-
Create Authentication Strengths in Microsoft Entra: Navigate to Protection > Authentication Strengths and set up strengths representing AAL2 and AAL3 levels by including only strong, phishing-resistant methods.
-
Enforce Authentication Strengths with Conditional Access: In Conditional Access > Policies, require users to authenticate with your defined Authentication Strengths to access sensitive applications, ensuring weak methods cannot be used.
-
Phase Out Insecure Methods Gradually: Initially, keep insecure methods enabled but restrict their usage via Conditional Access or limited scope policies. This gives users time to switch without disruption.
-
Monitor User Adoption and Compliance: Use sign-in logs and reports to verify users have registered and are using strong authentication methods, and that policies are effective.
-
Disable Legacy Authentication Methods: When confident all users have transitioned, disable insecure authentication methods (SMS, voice calls, email OTP) completely under Security > Authentication methods > Policies.
-
Ongoing Review and Improvement: Regularly update your Authentication Strengths and policies to keep pace with new technologies and emerging threats.
Why Follow This Roadmap?
Rushing to disable insecure methods without preparation can cause user frustration and business disruption. DTS recommends this phased approach because it:
-
Ensures all users are ready and supported
-
Maintains continuous access to resources
-
Enforces use of strong, phishing-resistant authentication effectively
-
Significantly reduces risk of account compromise and phishing attacks
Following this roadmap will help you modernize your authentication approach to meet practical security standards while minimizing disruption. Contact DTS for expert help in implementing a secure, user-friendly authentication transition in Microsoft Entra ID.

Terms and Definitions
-
Authentication Assurance Level (AAL) A standardized classification from the National Institute of Standards and Technology (NIST) that describes the strength and security guarantees of an authentication process. AAL levels help organizations select appropriate authentication methods based on the sensitivity of the resources they protect.
-
AAL2 (Moderate Assurance) An authentication level that requires multi-factor authentication with two different types of factors — for example, a password plus a mobile authenticator app or a hardware security key. AAL2 provides protection against common threats such as password theft and basic phishing attacks.
-
AAL3 (High Assurance) The highest authentication level defined by NIST, requiring multi-factor authentication that includes cryptographic hardware or software authenticators designed to be phishing-resistant, such as FIDO2 security keys. AAL3 offers protection against sophisticated attacks including phishing and credential theft.
-
Conditional Access A security feature within Microsoft Entra ID that enforces policies determining how users can access resources based on conditions like device compliance, user location, and authentication strength.
-
Authentication Strengths Configurations within Microsoft Entra ID that define which authentication methods satisfy certain assurance levels (like AAL2 or AAL3). These strengths can be assigned to Conditional Access policies to require users to authenticate using specific, approved methods.
-
Authentication Methods The techniques or mechanisms users employ to prove their identity when signing into systems. Examples include passwords, SMS one-time passcodes, authenticator apps, FIDO2 security keys, and passwordless phone sign-in.
-
Insecure Authentication Methods Authentication options considered vulnerable due to susceptibility to interception, social engineering, or replay attacks. Common examples are SMS, voice calls, and email one-time passwords (OTP).
-
Phishing Resistance The capability of an authentication method to prevent attackers from successfully tricking users into giving up credentials or authentication tokens. Methods like hardware security keys and authenticator apps with push notifications provide phishing-resistant authentication.
-
Microsoft Entra ID Microsoft’s cloud-based identity and access management service that provides secure sign-in, authentication, and conditional access capabilities for users and devices.
-
FIDO2 Security Keys Hardware devices that support the FIDO2 authentication standard, enabling strong, phishing-resistant, passwordless authentication by using public-key cryptography.
-
Microsoft Authenticator App A mobile app that generates time-based one-time passwords (TOTP) or sends push notifications to approve sign-in requests, providing stronger and more secure multi-factor authentication.
