Issue with PIM and MFA

David N 6 Reputation points
2022-09-21T20:02:50.623+00:00

We are moving are security to Privilege Identity Management and would like to force MFA when someone activates a role. The option is there see attachment but it does not work. If the user has already authenticated with MFA it will not force them to authenticate again.
Any help or suggestions here?

243643-image.png

Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,664 questions
0 comments No comments
{count} vote

3 answers

Sort by: Most helpful
  1. JimmySalian-2011 41,926 Reputation points
    2022-09-21T20:22:28.1+00:00

    Hi,

    Checkout the Conditional Access policy timeout frequency and persistent browser settings, explore that section - howto-conditional-access-session-lifetime

    concepts-azure-multi-factor-authentication-prompts-session-lifetime

    ==
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

  2. Vasil Michev 95,836 Reputation points MVP
    2022-09-22T06:53:19.877+00:00

    If the user has already succeeded an MFA challenge, the relevant claims will be stamped within the access token and honored by PIM and other services, so this is expected. If your idea is to always force MFA, there's no good solution currently - best wait for PIM to support authentication context.

    0 comments No comments

  3. David N 6 Reputation points
    2022-09-22T13:51:00.267+00:00

    If I implement CA policy there is no way to tie that to PIM activation right? The only option would be limiting MFA session of admins?
    Thanks
    David

    0 comments No comments