Privileged Identity Management - Role Activation MFA Settings Check

Anonymous
2025-04-30T06:15:10.84+00:00

Hi,

I am experiencing an issue verifying MFA feature in PIM. I have set up Azure MFA in certain role activations. However, when I tried to activate my Exchange Administrator role from Eligible status, it did not ask for any other authentication method. Could anyone please clarify me what is the reason for that case? How can I clarify that MFA is setup correctly.

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra Private Access
0 comments No comments

Answer accepted by question author
Jyotishree Moharana 1,945 Reputation points Microsoft External Staff Moderator
2025-04-30T16:59:41.7133333+00:00

Hello @Shala Senadheera,

It is possible that the MFA was not asked during activation because the MFA requirement is already satisfied. It could happen if the user has just performed MFA sometime back for any other resource or for Entra portal login. So if you already have a Conditional access policy enforcing MFA globally in your tenant or for admin portal logins user may not be promted to perform MFA again while activating the role.

To confirm if you've configured MFA for role activation correctly or not, you can check the settings for the role in PIM, please refer the screenshot.
User's image

Now to check if MFA was a requirement or not during the role activation, you can view the audit log of the user who was activating the role look for PIM service and check the details. Like in the below screenshot you can see the field IsAuthenticatedWithMfa to be "YES" which means MFA was a requirement, but the user was not prompted to complete MFA as it was already previously satisfied.

User's image

User's image

Was this answer helpful?


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.