Forum Discussion
Conditional Access not working as expected
- Dec 04, 2021
Yes, all users should be forced to use MFA. Here's an article I found just now which explains it all as you're on WHFB, much better than if I would give it a go! https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/why-are-my-users-not-prompted-for-mfa-as-expected/ba-p/1449032
Going forward, try out the What if tool and the Report-only option when you experience odd stuff. Perhaps you'd benefit using the new CA templates in preview too. Have a look https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-policy-common (the article was updated recently but you'll see those that are common to use if you scroll down)As sign-in frequency also includes MFA nowadays you should be able to get this working.
Good luck!
Hi Christian
many thanks for your feedback. I sent you all the settings i have in the policy.
Best regards,
Marc
- marckuhnNov 23, 2021Brass Contributor
this is what i would like to have, except that we would like to have for Windows 10 MFA in addition.
- Nov 23, 2021Hello again, difficult to say when not working in your environment. Have you tried the What If tool?
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/what-if-tool- marckuhnDec 03, 2021Brass Contributor
Hi Christian
i'm sorry for the late reply. We saw in the SignIn-Logs, that the "Windows Sign In" with Windows Hello for Business, which we use, is registered as "Single Factor Authentication", but shows "MFA requirement satisfied by claim in the token".
So i assume that probably Windows Hello for Business is causing this, but i'm not sure. Also because of this in the Conditional Access overview it shows those "Windows Sign In" as "Out of scope", which is a little odd.
Also i discovered, that i don't have enabled MFA for the individual users in AAD, but the Users needed to setup MFA because the Conditional Access policy initially. Is it necessary to enable or even enforce MFA for all users in AAD?
Best regards
Marc