How can we improve Azure Active Directory?

Enable Flash SMS for MFA/Multi Factor Authentication

I'd like the possibility to use Flash SMS (http://en.wikipedia.org/wiki/Short_Message_Service#Flash_SMS) when sending one-way OTPs using Azure MFA / Multi-Factor Authentication.

28 votes
Sign in
Check!
(thinking…)
Reset
or sign in with
  • facebook
  • google
    Password icon
    Signed in as (Sign out)

    We’ll send you updates on this idea

    Anonymous shared this idea  ·   ·  Flag idea as inappropriate…  ·  Admin →

    5 comments

    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)
      Submitting...
      • Anonymous commented  ·   ·  Flag as inappropriate

        I wouldn't recommend sms. It's essy to hack. Case in point when Reddit users using SMS as their "MFA" was hacked. By definition of NIST SP800-63B, it is considered Authenticator Assurance Level (AAL) 1, which is not MFA. It is Single Factor Authentication. AAL2 is required to be classified as MFA. Dependent on the data being protected, the AAL1 may be sufficient. Otherwise you need a more secure solution for the use case.

      • Thomas commented  ·   ·  Flag as inappropriate

        Hi. Flash SMS is one of the most user friendly MFA methods. Will this be a feature in the nearest future?

      Feedback and Knowledge Base