Aug 30 2021
08:56 AM
- last edited on
Jan 14 2022
03:25 PM
by
TechCommunityAP
Aug 30 2021
08:56 AM
- last edited on
Jan 14 2022
03:25 PM
by
TechCommunityAP
Hello all
I have enabled PIM for Azure AD roles. Below you can see we are requiring mfa when activating the GA role. I am noticing that after the time expires on the role, when i go back in to activate the role i am not getting prompted for mfa. I even restarted my device opened the browser and i wasnt prompted when i elevated. Any suggestions on why this is happening is appreciated
Aug 30 2021 09:47 AM
Solution@Skipster311-1 Hello, I'm pretty sure that you only get prompted per session and not activation. So you should look for your sign-in frequency settings.
Sep 08 2021 09:53 AM - edited Sep 08 2021 09:54 AM
Sep 08 2021 09:53 AM - edited Sep 08 2021 09:54 AM
This is interesting.
TLDR: It sounds like shortening sign-in frequency may be the best way to protect all Admin roles if there is a concern about an unauthorized person commandeering an administrator's unlocked workstation and elevating permissions/roles within a session.
*** Original ticket/request ***
I recently opened a ticket after reading https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-re... and testing to verify that AAD PIM ONLY requires MFA if the account has not already MFA'd when "On activation, require Azure MFA" is enabled.
However, I would be curious to know whether it would be possible to require MFA at the time of the request and not just accept the previous MFA authentication/session as sufficient for this request.
The business case being if a user who has Admin role eligibility either fails to lock his workstation OR has his browser session hijacked, I would like JIT MFA to kick in to prevent privilege escalation.
Sep 08 2021 11:40 PM
Feb 15 2024 10:15 PM
create a CA policy with authentication context and MFA strength --> push MFA and select session frequency every time and apply to users and test.
Mar 19 2024 06:45 AM
@mamirn - do you have any documentation or steps on how to achieve this? everything I have found has been vague and not helpful.
Aug 30 2021 09:47 AM
Solution@Skipster311-1 Hello, I'm pretty sure that you only get prompted per session and not activation. So you should look for your sign-in frequency settings.