Users being logged out once MFA enabled

CH_FL 1 Reputation point
2022-03-11T16:17:31.847+00:00

After enabling MFA on users accounts and applying conditional access policy we identified some users experiencing the following issues

  1. When reviewing email on the Outlook App on IOS they view a pop up about a new message but then the email does not appear in app until they log back in again
  2. Also IOS users getting prompted multiple times a day for MFA when the conditional policy is once a day

Are there any correlations to the frequency of login requirements to the conditional access policy?

just curious if others experienced these issues and how they resolved them

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,377 questions
{count} votes

3 answers

Sort by: Most helpful
  1. CH_FL 1 Reputation point
    2022-03-14T00:59:22.867+00:00

    182538-image.png

    We changed sign in frequency to 7 days. Initially it was every day. When it was every day users complained they were having issues many times a day being prompted and then not seeing apps in their mobile Outlook app. Images of the settings added.

    182565-image.png

    0 comments No comments

  2. risolis 8,701 Reputation points
    2022-03-14T01:38:56.497+00:00

    Hello @CH_FL

    I just wanted to add a few details on this one.

    -The following settings, such as Remember MFA and Remain signed-in, can result in prompts for your users to authenticate too often.

    • Keep the Remain signed-in option enabled and guide your users to accept it.

    -A user might see multiple MFA prompts on a device that doesn't have an identity in Azure AD. Multiple prompts result when each application has its own OAuth Refresh Token that isn't shared with other client apps

    -You can try to click the option "Revoke sessions" and test it

    -Use the "Trusted devices" option

    Regards,

    0 comments No comments

  3. CH_FL 1 Reputation point
    2022-03-14T12:29:57+00:00

    Thank you all so much
    We do have the option "Show option to remain signed in" enabled but we can encourage users to check it.
    Will have a look at the other suggestions "application has its own OAuth Refresh Token that isn't shared with other client apps" and "conditional access policy settings"

    0 comments No comments