Forum Discussion
Prompts for MFA across OneDrive, Teams, Outlook
isotonic_uk Hello, even though Moe_Kinani replied with a workaround that historically fix similar issues with authentication it shouldn't be used anymore. As for the prompt it most likely shows as the "remember device" service setting is ticked and it's configurable 1-60 days **edit** (just checked and its 365 now). I understand the customer has CA in their subscription so they should be able to work around this to either exclude managed devices, trusted locations, sign-in frequency etc. and not use the remember mfa service setting.
The WAM/ADAL issue
https://docs.microsoft.com/en-my/office365/troubleshoot/authentication/connection-issue-when-sign-in-office-2016
As for your question "60 days" (note the admins update)
https://feedback.azure.com/forums/169401-azure-active-directory/suggestions/35055382-mfa-remember-device-permanently-remember-per-d
Sign-in frequency
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-session-lifetime
To assist in reviewing your settings
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings
Hope it helps.
- ranj-singh111Sep 20, 2020Brass ContributorMany thanks for all the replies. Very useful and certainly something I can work with.
I agree think CA is the way forward to a avoid unneccessary prompts when in a safe network defined by CA,