Available to federal agencies, Microsoft Authentication Application Authenticator meets FIPS 140 standards

Dec 09, 2022|

February 9, 2007, Microsoft announced today that the Microsoft Authenticator app has met the requirements of the Federal Information Processing Standard (FIPS 140) in the United States. That means the identity app can use encryption that has been vetted by federal agencies. This is a very important milestone for Microsoft, meaning that the app will be available to all federal agencies in the United States.


Currently, only Microsoft Authenticator applications for iOS version 6.68 and up comply with FIPS 140 by default and can be used for Azure Active Directory (AAD) authentication when not configured by an IT administrator.


It is intended for customers who utilize Push multifactor authentication (MFA), password-less telephone login (PSI), and time-based one-time passwords (TOTP). Microsoft says an Android version will be released later, though it's not sure when. Microsoft points out that the app implements the FIPS 140 standard through CryptoCore, Apple's native encryption module on iOS.

FIPS stands for Federal Information Processing Standard. Based on the U.S. Information Technology Management Reform Act (Public Law 104-106), the Secretary of Commerce approved standards and guidelines for federal computer systems developed by the National Council on Standards and Technology (NIST).


These standards and guidelines are published by NIST and widely adopted across government agencies as Federal Information Processing Standards (FIPS). NIST develops FIPS standards for mandatory federal government requirements, such as security and interoperability, and for those requirements that have not yet resulted in an acceptable industry standard or solution.

20221206145658b3e8bb0d2e374df4a98dbdd519770012

Send Inquiry