Forum Discussion
azure federated managed apple id verification prompt frequently
i am using azure federated managed apple id to sign in icloud. once every few days, i will get apple id verification prompt to authenticate. is this normal?
- PablomcseBrass ContributorHi @jrng89, good morning. Federated authentication requires that a user’s User Principal Name (UPN) match their email address. User Principal Name aliases and Alternate IDs are not supported. To use federated authentication with Apple School Manager, your Apple devices must meet the following requirements: iOS 11.3 or later iPadOS 13.1 or later macOS 10.13.4 or later. Check your federation services logs and see where is the problem it should be my first option. Here you have more info about Federation services with Apple ids. https://support.apple.com/en-ie/guide/apple-school-manager/apdb19317543/web I hope this can help. Good luck!
- jrngsgIron Contributor
thanks. i have no problem signing in to federated azure work account.
it is just that the verification prompt will happen every few days
- PablomcseBrass Contributor
Hi jrngsg , good evening.
Maybe your Azure AD MFA "remember multi-factor authentication settings" is Disabled.
You can see this here:
- In the Azure AD portal, search for and select Azure Active Directory.
- Select Security, then MFA.
- Under Configure, select Additional cloud-based MFA settings.
- In the Multi-factor authentication service settings page, scroll to remember multi-factor authentication settings.
You can find more info here: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concepts-azure-multi-factor-authentication-prompts-session-lifetime
I hope this can help you.
Good luck!
- jackfirthCopper Contributor
Hey!! Did you find a fix, i have exactly the same issue while using federated authentication. - jackfirthCopper Contributor
- Hi
How are the vpp apps licences deployed/configured? user based or device based?- jrngsgIron ContributorAll vpp apps are deployed as device based license
- Bruce RobertsCopper Contributor
jrngsgwe are having a similar problem - most recently this has gotten more frequent. We are an ABM federated domain, we allow users to remember MFA authentication for X days.
Some troubleshooting we are just now trying is to check and confirm the authenticator app is logged in and working for the user and also for intune company portal app having the end user log out and then fully log back in (using their work email/apple federated ID - which are the same). Looking for suggestions to mitigate this end user interuption
- deb42Copper Contributor
- JuusoHCopper ContributorWe are also seeing this issue and it is very frequent for some of the users.
Has anyone found out the reason for it?