Forum Discussion
Does Rights Management Service currently support MFA claims from EAM?
Based on the behavior you've described, it doesn't look like a networking or SSL inspection issue, especially since excluding aadrm.com and bypassing certificate inspection didn't make a difference.
The fact that authentication succeeds and OME-protected emails decrypt correctly when using Microsoft Authenticator, but consistently fails when the flow is redirected to Duo through EAM, suggests that Rights Management Service may not currently honor MFA claims issued by External Authentication Methods.
This seems more like a service limitation than a client or configuration problem. I haven't come across any documentation explicitly stating that Azure Rights Management/OME supports EAM-issued MFA claims, so it's possible this scenario isn't supported yet.
It would be good if Microsoft could confirm whether RMS/OME is expected to work with External Authentication Methods today, or if support for this authentication flow is still planned.