Microsoft Entra ID
Authentication

Optional Claims Reference

In brief

The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.

What Entra admins need to know

Review any interpretation of the `amr` claim and require an additional factor when verifying phishing-resistant MFA.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

| Passkey (device-bound) (PRMFA) | fido, mfa | | Passkey (synced) | fido, mfa | | Windows Hello for Business (PRMFA) | hwk, mfa, ngcmfa | | Certificate-based authentication (PRMFA) | hwk (Multi-factor CBA) or x509 (Single factor CBA), mfa, rsa | | Temporary Access Pass (TAP) | otp, mfa | | Windows integrated authentication (Kerberos) | wia | | Device based X509 authentication | x509 |

Microsoft includes x509 in the amr claim for both single-factor Certificate-Based Authentication (CBA) and device-based X.509 authentication. However, the presence of x509 alone does not qualify as phishing-resistant MFA (PRMFA). To meet PRMFA requirements, the user must also complete an additional MFA factor, which will be reflected by other authentication method indicators in the authentication context. Microsoft Entra ID forwards the amr values sent from an external MFA provider along with the amr values for the authentication methods performed in Microsoft Entra ID. For more information, see Supported AMR claims.

See also

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…