Forum Discussion
Alexander Filipin
Jul 06, 2017Brass Contributor
MFA and Azure B2B
If you enfore MFA on a B2B user via AAD conditional access and the user cant use the already confiured MFA app / MFA options.
They have to register for MFA again and even end up with two entries in the Authenticator App if used.
Are you looking to improve this?
HI Alexander - thanks for the question!
Currently, MFA is managed at the resource tenant - that is the tenant that has invited the B2B user. This allows the organization to work with users with social IDs and with partners that don't have MFA capabilties and partners whose MFA policies that the resource tenant may not trust.
This does mean that if the user has an MFA profile with the partner org already - they will still have to re-register with the resource tenant/inviting organization.
We are looking into enabling the resource tenant to trust certain partner organizations' MFA so that the users from these partner companies do not have to re-register and can use their existing MFA profile.
Hope that helps.
Sarat
- Sarat Subramaniam
Microsoft
HI Alexander - thanks for the question!
Currently, MFA is managed at the resource tenant - that is the tenant that has invited the B2B user. This allows the organization to work with users with social IDs and with partners that don't have MFA capabilties and partners whose MFA policies that the resource tenant may not trust.
This does mean that if the user has an MFA profile with the partner org already - they will still have to re-register with the resource tenant/inviting organization.
We are looking into enabling the resource tenant to trust certain partner organizations' MFA so that the users from these partner companies do not have to re-register and can use their existing MFA profile.
Hope that helps.
Sarat
- joe-zuchoraCopper Contributor
Hi there,
Any update on this? Do we have an idea of when this will be available?
- JonasBackSteel ContributorI wonder this too...
- Shane WrightCopper Contributor
Hey Sarat,
It has been 12 months since your post - my company wishes to leverage this ability to trust a partner company MFA.
Any progress on this item?
Cheers
Shane