Providing secure, identity-based access to private apps and resources without traditional VPNs
Hello @Shala Senadheera,
It is possible that the MFA was not asked during activation because the MFA requirement is already satisfied. It could happen if the user has just performed MFA sometime back for any other resource or for Entra portal login. So if you already have a Conditional access policy enforcing MFA globally in your tenant or for admin portal logins user may not be promted to perform MFA again while activating the role.
To confirm if you've configured MFA for role activation correctly or not, you can check the settings for the role in PIM, please refer the screenshot.
Now to check if MFA was a requirement or not during the role activation, you can view the audit log of the user who was activating the role look for PIM service and check the details. Like in the below screenshot you can see the field IsAuthenticatedWithMfa to be "YES" which means MFA was a requirement, but the user was not prompted to complete MFA as it was already previously satisfied.