Forum Discussion
Tim_Healey
Jul 17, 2023Copper Contributor
Excessive MFA prompts for a specific user
One specific user in my tenant is prompted for MFA multiples times/day. Our conditional access policies specify that a user must re-authenticate every 90 days with MFA. All other users do not get pro...
Tim_Healey
Jul 18, 2023Copper Contributor
Devices are Azure AD registered. Yes, there is a sign in frequency control of 90 days. Other than that, it targets all cloud apps and grants access with MFA required. There is no requirement the device be Azure AD joined or compliant in the policy.
You're right that the "Incoming token type" is often none in the sign ins. Interesting that it could be TPM because we're on device number 2. It could be a coincidence. Windows does not indicate any problems with TPM.
You're right that the "Incoming token type" is often none in the sign ins. Interesting that it could be TPM because we're on device number 2. It could be a coincidence. Windows does not indicate any problems with TPM.
Spindle8551
Jul 18, 2023Copper Contributor
Hopefully this could be of some use?
https://youtu.be/uYJLQGL7ftA.
https://youtu.be/uYJLQGL7ftA.
- Tim_HealeyJul 18, 2023Copper Contributor
Thanks this is helpful. Current AzureADprt state is YES, but I'll comb through event viewer when the problem re-occurs.