Avatar of Tiras25
Tiras25
Flag for United States of America asked on

MFA authentication international locations

How does password reset works in international locations with MFA.  Here in US I can input a phone number in AD Mobile field. example +1-415-111-1111
Then it sends a code to the phone and you confirm.  Would it work with international locations?  Example China +86-180-1111-1111

https://passwordreset.microsoftonline.com/
Internet Protocol SecurityMobileActive DirectoryAzureSecurity

Avatar of undefined
Last Comment
btan

8/22/2022 - Mon
Mahesh

Ideally you will adding ISD code of country followed by his cell number...the purpose is to cover entire globe

That will work if number is valid one
Tiras25

ASKER
Thanks.  I guess another questions particularly about Chinese regulations.  I know they blocking direct access to the major sites like ms, azure, okta, aws, etc.  Would it work with MFA code sent from MS reset to their phones?
ASKER CERTIFIED SOLUTION
Mahesh

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
btan

Depends but good to clarify the availability
Azure AD Premium and its capabilities is not currently available in Tenants hosted in our Mainland China Azure AD instance such as when a company signs up for Office 365 or Azure operated by our partner 21Vianet.

A company with Tenant in our Global Azure AD instance, hosted in our global datacenters, has access to Azure AD Premium services and all employees in that Tenant, including those in China, can leverage the services.
The SMS will works and there are other reset option
We do have other options available for both SSPR and MFA that do not require SMS/Phone calls (e.g. Azure Authenticator app for MFA and Q/A gate for SSPR) but does require internet connectivity.

Fun Fact: For Azure MFA, you can change the Caller ID Phone Number but this is only from US phone numbers only.
https://techcommunity.microsoft.com/t5/Enterprise-Mobility-Security/AzureAD-Mailbag-International-Deployments-Round-2/ba-p/250025

Other interesting info
Azure AD Password Reset is localized into the full Office language set. SSPR uses the user's browser locale when choosing how to localize the SSPR page and all of its communication (SMS, voice, question languages).
https://techcommunity.microsoft.com/t5/Enterprise-Mobility-Security/AzureAD-Mailbag-International-Deployments/ba-p/250020
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23