Home

Require MFA for Intune device enrollments

%3CLINGO-SUB%20id%3D%22lingo-sub-614593%22%20slang%3D%22en-US%22%3ERequire%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-614593%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ebelonging%20to%20the%20following%20MS%20docs%20i'm%20wondering%20why%20some%20of%20my%20users%20need%20to%20provide%20MFA%20while%20enrolling%20their%20device%2C%20even%20if%20i%20have%20not%20set%20up%20the%20conditional%20access%20as%20descibed%20in%20the%20MS%20Docs%2C%20yet.%3C%2FP%3E%3CP%3E%3CA%20title%3D%22MS%20Docs%3A%20Require%20multi-factor%20authentication%20for%20Intune%20device%20enrollments%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fmulti-factor-authentication%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fmulti-factor-authentication%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20in%20advance.%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3CP%3EPatrick%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-614593%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-614673%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-614673%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Esome%20of%20them%20could%20mean%20only%20Windows%2010%3F%20Then%20it%20might%20be%20the%20case%20that%20you%20are%20enforcing%20MFA%20on%20AADJ%20like%20this%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F114335iB95D9AB5515BA996%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22SNAG-0000.png%22%20title%3D%22SNAG-0000.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-614705%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-614705%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F174439%22%20target%3D%22_blank%22%3E%40Oliver%20Kieselbach%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Esorry%2C%20i%20meant%20iOS%20%26amp%3B%20Android%20Enrollment.%3C%2FP%3E%3CP%3E(By%20the%20way%3A%20The%20mentioned%20setting%20is%20active%20in%20my%20tenant%20config.)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-614716%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-614716%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3A)%3C%2Fimg%3E%20ah%20okay.%20Android%20and%20iOS%20should%20not%20be%20affected%20from%20this%20setting.%20Did%20you%20have%20several%20CA%20policies%20active%20in%20your%20tenant%3F%20Did%20you%20try%20to%20use%20the%20CA%20%22What%20if%22%20feature%20to%20check%20if%20you%20might%20be%20affected%20under%20certain%20conditions%20which%20then%20might%20include%20the%20%22Microsoft%20Intune%20Enrollment%22%20app%20as%20mentioned%20in%20the%20article%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-622227%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-622227%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F174439%22%20target%3D%22_blank%22%3E%40Oliver%20Kieselbach%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20this%20moment%20there%20are%20only%202%20CAs%20active%3A%3C%2FP%3E%3CP%3EOne%20is%20for%20administrators%20and%20one%20is%20for%20ActiveSync%20(Blocking%20of%20the%20native%20ios%26amp%3Bandroid%20app%2C%20to%20gently%20%22push%22%20the%20use%20of%20the%20Outlook%20App.%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20at%20this%20moment%20i%20don't%20have%20any%20idea.%20%3A%5C%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-622235%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-622235%22%20slang%3D%22en-US%22%3EDo%20those%20users%20have%20MFA%20enabled%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Faccount.activedirectory.windowsazure.com%2Fusermanagement%2Fmultifactorverification.aspx%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faccount.activedirectory.windowsazure.com%2Fusermanagement%2Fmultifactorverification.aspx%3C%2FA%3E%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-622236%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-622236%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F345481%22%20target%3D%22_blank%22%3E%40hskovgaard%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20know%20that%20some%20users%20use%20MFA%2C%20but%20they%20don't%20appear%20in%20this%20list%20from%20your%20link.%3C%2FP%3E%3CP%3EWhat%20should%20account.activedirectory.windowsazure.com%20effect%3F%20When%20i%20look%20into%20this%20no%20user%20has%20MFA%20enabled%2C%20even%20if%20i%20know%20some%20registered%20for%20MFA.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-622241%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-622241%22%20slang%3D%22en-US%22%3EIt's%20the%20%22old%22%20way%20of%20enabling%20MFA.%20If%20you%20enable%20here%2C%20then%20the%20user%20is%20always%20required%20to%20use%20MFA%20no%20matter%20what%20a%20CA%20rule%20says.%3CBR%20%2F%3E%3CBR%20%2F%3EAnother%20thing%20to%20check%20is%20to%20see%20if%20there%20is%20anything%20setup%20in%20Azure%20AD%20Identity%20Protection%20regarding%20MFA%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-622273%22%20slang%3D%22en-US%22%3ERe%3A%20Require%20MFA%20for%20Intune%20device%20enrollments%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-622273%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F345481%22%20target%3D%22_blank%22%3E%40hskovgaard%3C%2FA%3E%26nbsp%3BThank%20for%20your%20explanation.%3C%2FP%3E%3CP%3EIn%20Identity%20Protection%20i've%20set%20up%20the%20Sign-in%20risk%20policy%20to%20require%20MFA%20when%20risk%20level%20is%20high.%20(We%20want%20to%20%22tighten%22%20that%20to%20medium%20risk%20level.)%3C%2FP%3E%3CP%3EAt%20this%20point%20we%20do%20not%20enforce%20our%20users%20to%20register%20for%20MFA.%20(Azure%20AD%20Identity%20Protection%20-%26gt%3B%20Configure%20-%26gt%3B%20MFA%20registration)%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Hi,

 

belonging to the following MS docs i'm wondering why some of my users need to provide MFA while enrolling their device, even if i have not set up the conditional access as descibed in the MS Docs, yet.

https://docs.microsoft.com/en-us/intune/multi-factor-authentication

 

Thank you in advance.

Regards

Patrick

8 Replies

Hi @PatrickF11,

 

some of them could mean only Windows 10? Then it might be the case that you are enforcing MFA on AADJ like this:

 

SNAG-0000.png

 

best,

Oliver

Hi @Oliver Kieselbach 

 

sorry, i meant iOS & Android Enrollment.

(By the way: The mentioned setting is active in my tenant config.)

@PatrickF11 

 

:) ah okay. Android and iOS should not be affected from this setting. Did you have several CA policies active in your tenant? Did you try to use the CA "What if" feature to check if you might be affected under certain conditions which then might include the "Microsoft Intune Enrollment" app as mentioned in the article?

@Oliver Kieselbach 

At this moment there are only 2 CAs active:

One is for administrators and one is for ActiveSync (Blocking of the native ios&android app, to gently "push" the use of the Outlook App. ;)

 

So at this moment i don't have any idea. :\

Hi @hskovgaard,

 

i know that some users use MFA, but they don't appear in this list from your link.

What should account.activedirectory.windowsazure.com effect? When i look into this no user has MFA enabled, even if i know some registered for MFA.

It's the "old" way of enabling MFA. If you enable here, then the user is always required to use MFA no matter what a CA rule says.

Another thing to check is to see if there is anything setup in Azure AD Identity Protection regarding MFA?

@hskovgaard Thank for your explanation.

In Identity Protection i've set up the Sign-in risk policy to require MFA when risk level is high. (We want to "tighten" that to medium risk level.)

At this point we do not enforce our users to register for MFA. (Azure AD Identity Protection -> Configure -> MFA registration)

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
38 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies