MFA
2 TopicsOutlook MFA issues, asks for "need password" and get blank screen
Hello everyone, Premier support is failing to make an progress, I have had a ticket open for a month now with no luck (Getting escalated to Tier 3 this morning). Here is the scenario We have Conditional Access rule that says if someone accesses Office 365 (All Office) from a Non-trusted Location require MFA. For most people it works fine but we have about 10% of the people who run into a really weird problem in outlook only, all other apps (Skype, Word, etc.) work fine. User opens outlook (2016 current monthly) and it shows the "need password" screen at the bottom and no email is sent/received, when we click on it we see a white box comes up and goes away, it does not give them the option. So kind of stuck there! When you go to File->Accounts and do a Sign-out and then try to sign-back in it comes up with the email window but as soon as you submit the email the window goes away and they stay signed out. Here is where it gets interesting, lets say you put someones email in there that works (but is also part of the same MFA rules), it takes that and then brings up the MFA prompt for original user. Once that user then presses approve (MS authentication app, push notifications) then it signs that user in and email starts flowing again. It seems to work for a couple of weeks and then stops again with the same prompt. We put in all the normal reg keys to enforce modern auth (EnableAdal -1, Alwaysusemsoauthforautodiscovery = 1, disableADALaptopWAmOverrride - 1,Disable AADWAM) but I think it may be something on the username side since putting in another username works.19KViews0likes5CommentsOutlook 2016 with MFA enabled MSA
Here's the basic question. Does Outlook 2016 support MFA enabled MSAs without requiring the use of App Passwords? In other words, is modern authentication (notification, text, call) capable when wiring up an MSA to Outlook 2016? Here is why I'm asking. I thought that the answer to this question was yes, but my recent experience is no. I am not talking about Office 365 Azure AD MFA enabled account. I understand the requirement on the Office 365 side to enable the tenant for modern authentication. I am talking about a consumer account (Hotmail.com, live.com, outlook.com). I am not talking about an MSA that is using a duplicate work account. This is a straight MSA. I've been working with customers to enable MFA on all Office 365 accounts. Many have existing MSAs that they use for personal email and they want those in Outlook 2016, side-by-side with their Office 365 email account. The Office 365 MFA experience is behaving as expected. I've established MFA on the MSA and it's functioning properly. MFA is active via the web and via mobile, but Outlook 2016 will not present the modern authentication screen when initially wiring up the MSA (using autodiscover, maybe manual would be different). The account can be configured, but it requires the use of an App Password. It's not that it won't work, but rather that App Passwords are really hard to explain to average users. App Passwords add a complexity and confusion that I try to avoid. I opened a ticket with Office 365 support, but it's slow going. We've spent the better part of two days just going back and forth agreeing on scope. They initially content that it's not within their scope. We've finally come to an agreement so I can move forward, but I find it interesting that a basic question of yes or no it works or doesn't has been so elusive. So I turn to the community. Have any of you, recently, connected an MFA enabled Microsoft Account (MSA) to Outlook 2016 (desktop) without having to use an app password? If there is documentation on this specific topic one way or the other, I can't find it. A link would be much appreciated. Thanks, Andy BaerstSolved58KViews0likes11Comments