Skip to main content

Issue or remove a Microsoft Authenticator device in Care Identity Management

How to use Care Identity Management to issue a Microsoft Authenticator device as an authenticator, as an alternative to a smartcard, or remove a device from a user's profile.

Which roles can do this?

  • Registration Authority Manager
  • Registration Authority Agent (Advanced)

Before you start

For the Registration Authority

You will need to set up a registration meeting with your user, either via video or face-to-face. Registration must be completed in your presence.

Microsoft Authenticator is currently only available for NCRS and MESH.

For the user

The user must:

  • have the Microsoft Authenticator App installed on their Smartphone
  • bring their device to the meeting
  • have a working internet connection
  • have an email account that is on the list of allowed domains

View the Warrantied Environment Specification to check browser compatibility.


Face-to-face process

From the Care Identity Management home page, choose 'Find an existing user'.

CIM home page find an existing user highlighted

 

Enter the user's details and select 'Search'.

Care Identity Management find an existing user

 

Choose 'View profile' on the right of the screen.

Care Identity Management user found

 

Go to the Authenticators tab on the user's profile page and select Issue other authenticator.

Shows the Authenticator tab selected with the Issue other authenticator button selected.

 

Select Microsoft Authenticator and continue.

CIM select other authenticator microsoft authenticator highlighted

 

You will now see a screen with instructions how to register the device.

When you've read the instructions and you are both ready to proceed, select 'Generate link'.

Shows instructions on how to register a device and generate a link

 

Copy the link and send it to the user by email, or paste it into the chat function of the video call software you are using.

Shows a registration link and a button to Copy link

 

The user should click the link. They will then be prompted to enter their Care Identity email address.

Shows a form field for email address to send a One Time password

 

The user will receive a one-time password in their inbox.

Shows an email in an inbox, containing a one time password.

 

The user should enter the One Time Password from their email and select Continue.

Shows a page with a form field where the user can add the one time password they have been to their email

 

The user will then be prompted to create a password.

Shows form fields to create and confirm a password

 

The user will then be prompted to scan a QR code using the Microsoft Authenticator app on their phone.

Shows an illustration of a QR code, a link in case you are on a mobile phone and cannot scan, and a Next button.

 

When the Microsoft Authenticator app has scanned the QR code, it will automatically add the account to the app.

Shows the Microsoft authenticator app, with Care Identity Authentication added

 

Guide the user back to their browser and ask them to select Next.

They will now be prompted to enter their verification code. This is the 6 digit code from the Microsoft Authenticator app.

Guide the user to look at the code in the Microsoft Authenticator app. Ensure there is enough time to read and type in the code before the timer ends.

Shows a form field for entering the verification code

 

The user will then be shown a screen confirming that registration was successful.

 

The user can now close the page.

The user profile page will now show that the user's device has been registered.

Shows a Microsoft authenticator has successfully been registered to the profile, and has an active status.


Test the Microsoft Authenticator device registration has been successful

To test and demonstrate that the registration of the Microsoft Authenticator device has been successful, the user needs to authenticate using Microsoft Authenticator.


Remove a Microsoft Authenticator device

From the user's profile, select the 'Authenticators' tab, find the Microsoft Authenticator device in the list and select 'Remove' on the right.

CIM authenticators Microsoft Authenticator remove link

 

Select the box to confirm you want to remove the Microsoft Authenticator device, followed by the 'Remove authenticator' button.

CIM remove Microsoft Authenticator

 

Finally you'll see a message confirming that the device has been removed from the user's profile.

CIM Microsoft Authenticator removed successfully


If a user changes their mobile device

If the user changes their mobile device, they'll need to transfer the authenticator to the new device.

Depending on the device it may be possible to transfer the authenticator directly to the new device.

If not, the user will need to ask a Registration Authority user to remove the existing authenticator before adding the new device as described above. Note if the user has another authenticator then they can add this themselves in Care Identity Management.

Last edited: 24 April 2025 2:33 pm