Hi @Matt Roberts,
Thank you for reaching out to the Microsoft Q&A Forum.
The error you're encountering, “clientapplications condition must specify the service principal”, typically occurs when you're trying to modify or remove a Conditional Access policy or multifactor authentication (MFA) setting in Microsoft Entra ID (formerly Azure AD), and the policy includes a clientApplications condition that lacks a defined service principal. This issue can arise especially when you're trying to disable MFA for a user account and the Conditional Access policy is misconfigured or too strict.
To assist you with more accuracy, could you provide me some additional information related to this issue?
- Have you tried excluding the user from Conditional Access policies? If so, you might be able to log in without needing to remove MFA.
- Have you ever revoked the user's MFA session before attempting access?
- Are you currently editing a Conditional Access policy that includes the
clientApplications condition?
- Is MFA being enforced through Conditional Access MFA or via legacy per-user MFA settings?
Once I have a clearer understanding of your current situation, I’ll be happy to assist you with greater accuracy. Please feel free to share any additional details you believe are relevant. Screenshots are especially helpful and much appreciated.
In the meantime, I recommend revoking MFA for the user as a first step. You can follow the step-by-step instructions provided in the official Microsoft documentation to do this safely and effectively: Manage authentication methods for Microsoft Entra multifactor authentication - Microsoft Entra ID |…
After revoking MFA, and the user account is still being enforced to use it, you can register your own phone number or device for that account. This will make future logins more convenient and manageable.
Alternatively, you can try excluding the user from Conditional Access policies, wait a few minutes to allow the changes to sync, and then proceed to remove MFA from their account.
Note: Please understand that our initial response does not always resolve the issue immediately. However, with your help and more detailed information, we can work together to find a solution.
I hope this information is helpful. Please follow these steps and let me know if it works for you. If not, we can work together to resolve this.
Thank you for your patience and your understanding. If you have any questions, please feel free to reach out.
I'm looking forward to your reply.
If the answer is helpful, click "Accept Answer" and vote positively. If you have more questions about this answer, click "Comment".
Note: Follow the steps in our documentation to enable email notifications if you want to receive email notifications related to this topic.
