Forum Discussion
RahamimL
Dec 17, 2018Iron Contributor
Migrate users from Office 365 multi factor authentications to Azure conditional accss
Hi all, We enabled Office 365 MFA in our organization (We have E1 licensing). We recently discovered that Microsoft enabled for us Azure conditional access where we can let the users work without...
RahamimL
Dec 17, 2018Iron Contributor
The conditional access options are limited, we have 4 options: 1 is required MFA another is device registration and 2 more that I don't remember.
When we found out about it, it was with a certified Microsoft consultant which was shocked as we were.
Because these options are sufficient to our needs, we would like to roll it out.
When we found out about it, it was with a certified Microsoft consultant which was shocked as we were.
Because these options are sufficient to our needs, we would like to roll it out.
Jethro Seghers
Dec 17, 2018Copper Contributor
Your users will always have to be configured for MFA. Depending on your wishes you can define your conditional access but your users need to have their MFA setup.
- RahamimLDec 17, 2018Iron ContributorWhile reading your answer I realized that my question should be different:
Is it correct to assume that if I enabled office MFA and afterwards added the user to conditional access the user, the conditional access won't apply and I will have to disable the office MFA in order for conditional access to work. This will force the user to re-set it's authentication device.
So the transition will never go smoothly...- Jethro SeghersDec 17, 2018Copper Contributor
Do you mean Office 365 MFA?
Office 365 MFA and Conditional access use the same MFA service, Azure MFA. So if you would enable Conditional Access it will use the same configuration for the users that already have configured their additional authentication. So, since it is the same MFA it should not ask to reset the device setup.
- RahamimLDec 17, 2018Iron Contributor
So if we enabled MFA through Office 365 and than added the user to Azure conditional access this should work? I don't need to do anything else?