Home

MFA causing multiple issues

%3CLINGO-SUB%20id%3D%22lingo-sub-1251390%22%20slang%3D%22en-US%22%3ERe%3A%20MFA%20causing%20multiple%20issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1251390%22%20slang%3D%22en-US%22%3E%3CP%3ENeither%20Teams%20nor%20Outlook%20requires%20app%20passwords%2C%20only%20old%20versions%20(Office%202010%2C%202013)%20do.%20If%20you%20are%20seeing%20the%20%22legacy%22%20auth%20prompt%2C%20make%20sure%20that%20modern%20auth%20is%20enabled%20*both*%20service-%20and%20client-side.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1255841%22%20slang%3D%22en-US%22%3ERe%3A%20MFA%20causing%20multiple%20issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1255841%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BThank%20you%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20now%20set%20modern%20auth%20and%20outlook%20clients%20now%20prompting%20with%20modern%20auth%20login%20page.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStill%20need%20to%20see%20if%20anyone%20else%20facing%20other%20issues%20as%20listed%20above%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1250131%22%20slang%3D%22en-US%22%3EMFA%20causing%20multiple%20issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1250131%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20community%20members%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20hope%20I%20am%20posting%20at%20the%20right%20board.%3C%2FP%3E%3CP%3EFacing%20few%20issues%20with%20MFA%20enabled%20%26amp%3B%20enforced%20for%20our%20users.%3C%2FP%3E%3COL%3E%3CLI%3EUsers%20facing%20issues%20to%20login%20to%20MS%20Teams%20%26amp%3B%20Outlook.%20Some%20users%20even%20with%20an%20app%20password%20set%2C%20prompted%20for%20password%2C%20same%20with%20Teams.%20%3CSTRONG%3E*SOLVED%3A%20Thanks%20to%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3Bsuggestions%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3EOn%20Teams%2C%20users%20see%20a%20modern%20authentication%20page%20and%20at%20the%20same%20time%20an%20app%20password%20page%20for%20login%20couple%20of%20times.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%3CLI%3EUsers%20OS%20not%20upgrading%20to%20Win%2010%20Enterprise.%20Got%20a%20response%20from%20MS%20support%20that%20this%20is%20an%20ongoing%20issue%20as%20per%26nbsp%3B%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fprotect-eu.mimecast.com%2Fs%2FqMhkC6BrRi13QKtm90Nh%3Fdomain%3Ddocs.microsoft.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fwindows-10-subscription-activation%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%230000FF%22%3E'An%20issue%20has%20been%20identified%20with%20Hybrid%20Azure%20AD%20joined%20devices%20that%20have%20enabled%20multi-factor%20authentication%20(MFA).%20If%20a%20user%20signs%20into%20a%20device%20using%20their%20Active%20Directory%20account%20and%20MFA%20is%20enabled%2C%20the%20device%20will%20not%20successfully%20upgrade%20to%20their%20Windows%20Enterprise%20subscription.%20To%20resolve%20this%20issue%2C%20the%20user%20must%20either%20sign%20in%20with%20an%20Azure%20Active%20Directory%20account%2C%20or%20you%20must%20disable%20MFA%20for%20this%20user%20during%20the%2030-day%20polling%20period%20and%20renewal.'%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FFONT%3E%3C%2FP%3E%3C%2FLI%3E%3CLI%3EUsers%20devices%20not%20registering%20to%20Hybrid%20Azure%20AD%3C%2FLI%3E%3CLI%3EConditional%20Access%20Policy%20restricting%20SharePoint%20online%20for%20unmanaged%20devices%20causing%20to%20lock%20down%20managed%20devices%20as%20well%20due%20to%20device%20registration%20data%20not%20syncing%20to%20Azure.%20(For%20now%2C%20we%20have%20kept%20this%20policy%20to%20report%20only%20mode%2C%20as%20due%20to%20the%20MFA%20issue%2C%20some%20devices%20are%20not%20showing%20as%20Hybrid%20Azure%20AD%20registered%20even%20if%20it%20shows%20as%20that%20on%20the%20portal)%20but%20this%20is%20causing%20risk%20of%20data%20exposure%20from%20unmanaged%20devices)%3C%2FLI%3E%3C%2FOL%3E%3CP%3ECurrent%20workaround%20for%201%20to%204%20is%20to%20disable%20MFA%2C%20(3rd%20issue%20workaround%20suggested%20by%20MS%20support%20was%20to%20let%20the%20user%20login%20to%20the%20computer%20using%20their%20email%20id%20and%20password%20rather%20than%20the%20local%20AD%20credential%2C%20but%20this%20rarely%20works%20and%20we%20depend%20on%20our%20MFA%20disable%2Fenable%20workaround%20instead)%20let%20the%20user%20login%20to%20portal%20and%20then%20while%20they%20are%20logged%20in%2C%20enable%20%26amp%3B%20enforce%20MFA%20again%2C%20generate%20a%20new%20app%20password%20(as%20the%20old%20one%20gets%20cleared%20when%20you%20disable%20MFA)%20and%20then%20wait%20for%20few%20minutes%20(app%20password%20doesn't%20seems%20to%20be%20immediately%20accepted%20by%20Outlook%2FTeams)%20and%20apply%20it%20to%20the%20clients.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20facing%20these%20issues%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1250131%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1308605%22%20slang%3D%22en-US%22%3ERe%3A%20MFA%20causing%20multiple%20issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1308605%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20still%20seeing%20Teams%20not%20working%20in%20certain%20W10%20machines%20after%20enabling%20MFA.%20Anyone%20else%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Dear community members,

 

I hope I am posting at the right board.

Facing few issues with MFA enabled & enforced for our users.

  1. Users facing issues to login to MS Teams & Outlook. Some users even with an app password set, prompted for password, same with Teams. *SOLVED: Thanks to @Vasil Michev suggestions
  2. On Teams, users see a modern authentication page and at the same time an app password page for login couple of times.

  3. Users OS not upgrading to Win 10 Enterprise. Got a response from MS support that this is an ongoing issue as per 

    https://docs.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation

     

    'An issue has been identified with Hybrid Azure AD joined devices that have enabled multi-factor authentication (MFA). If a user signs into a device using their Active Directory account and MFA is enabled, the device will not successfully upgrade to their Windows Enterprise subscription. To resolve this issue, the user must either sign in with an Azure Active Directory account, or you must disable MFA for this user during the 30-day polling period and renewal.'

  4. Users devices not registering to Hybrid Azure AD
  5. Conditional Access Policy restricting SharePoint online for unmanaged devices causing to lock down managed devices as well due to device registration data not syncing to Azure. (For now, we have kept this policy to report only mode, as due to the MFA issue, some devices are not showing as Hybrid Azure AD registered even if it shows as that on the portal) but this is causing risk of data exposure from unmanaged devices)

Current workaround for 1 to 4 is to disable MFA, (3rd issue workaround suggested by MS support was to let the user login to the computer using their email id and password rather than the local AD credential, but this rarely works and we depend on our MFA disable/enable workaround instead) let the user login to portal and then while they are logged in, enable & enforce MFA again, generate a new app password (as the old one gets cleared when you disable MFA) and then wait for few minutes (app password doesn't seems to be immediately accepted by Outlook/Teams) and apply it to the clients.

 

Anyone facing these issues?

3 Replies
Highlighted

Neither Teams nor Outlook requires app passwords, only old versions (Office 2010, 2013) do. If you are seeing the "legacy" auth prompt, make sure that modern auth is enabled *both* service- and client-side.

Highlighted

@Vasil Michev Thank you

 

I've now set modern auth and outlook clients now prompting with modern auth login page. 

 

Still need to see if anyone else facing other issues as listed above

Highlighted

@Vasil Michev 

We are still seeing Teams not working in certain W10 machines after enabling MFA. Anyone else?