Enterprise application not prompting for MFA

dirkdigs 921 Reputation points
2022-05-18T21:10:35.627+00:00

How can i force my enterprise application (using SAML auth) to prompt for MFA every time ?

i tried creating a conditional access policy but that did not work .

I found this blurb from 2019 - this seems like the exact same issue . is this still the case 3 years later?

I just don't feel 100% comfortable with there not being a way to enforce 2FA even if the device is hybrid joined and is still within the 14 day Primary Refresh Token window.  It feels like with conditional access being an option I should be able to override the token in the event the user attempts to access this specific application.  

Is there a way to reset this Primary refresh token .

203381-image.png

Azure AD Conditional Access policies are not evaluated when PRTs are issued.  
  
  
Not Monitored
Not Monitored
Tag not monitored by Microsoft.
35,997 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. 2022-05-19T04:23:00.13+00:00

    Hello @dirkdigs , you can enforce re-authentication and MFA using User sign-in frequency for the specific application.

    Let us know if this answer was helpful to you or if you need additional assistance. If it was helpful, please remember to accept it so that others in the community with similar questions can more easily find a solution.