multifactor authentication error 'clientapplications' condition must specify the service principal

Matt Roberts 45 Reputation points
2025-10-17T15:37:27.33+00:00

updating multifactor authentication error clientapplications condition must specify the service principal

I need to remove multifactor authentication for staff who have left the company so I can get into their email and archive it for legal purposes. For YEARS we have simply removed the multi factor, logged into their laptop and moved their email, now today I get this error

Outlook | Windows | Classic Outlook for Windows | For business

Answer accepted by question author

Nathan H 75 Reputation points
2025-10-22T18:38:42.2266667+00:00

We ran into this same issue and I just confirmed a solution:

The issue: When MS started phase 1 of switching from MFA Per User to CA they created the CA that is causing the issue. Since then, they have changed/added a couple of options and as of 10/1 they started enforcing that Client Apps change they made. The catch is even though they updated the options (and subsequently the necessity of the one in the error) the Microsoft created CA is not editable.

The Solution: Duplicate the Microsoft rule and add the missing option. Below are fast and dirty steps.

  1. Click on the Microsoft CA and click Duplicate.
  2. Close the CA and refresh the CA List until the new one appears. (It will have the same name but it will be marked as user created).
  3. Open the new CA.
  4. Click Conditions under Assignments
  5. Click the link under Client Apps.
  6. Click Yes for configure and select the covered apps (I chose all).
  7. Save everything while also turning the CA on.
  8. Turn the Microsoft created CA off.
  9. Refresh the CA listing and ensure the MS CA is off and the duplicate is on.

I hope this helps.

Was this answer helpful?

0 comments No comments

Answer accepted by question author

Alexis-NG 17,905 Reputation points Microsoft External Staff Moderator
2025-10-17T17:27:57.66+00:00

Hi @Matt Roberts,

Thank you for reaching out to the Microsoft Q&A Forum.

The error you're encountering, “clientapplications condition must specify the service principal”, typically occurs when you're trying to modify or remove a Conditional Access policy or multifactor authentication (MFA) setting in Microsoft Entra ID (formerly Azure AD), and the policy includes a clientApplications condition that lacks a defined service principal. This issue can arise especially when you're trying to disable MFA for a user account and the Conditional Access policy is misconfigured or too strict.

 

To assist you with more accuracy, could you provide me some additional information related to this issue?

  • Have you tried excluding the user from Conditional Access policies? If so, you might be able to log in without needing to remove MFA.
  • Have you ever revoked the user's MFA session before attempting access?
  • Are you currently editing a Conditional Access policy that includes the clientApplications condition?
  • Is MFA being enforced through Conditional Access MFA or via legacy per-user MFA settings?

Once I have a clearer understanding of your current situation, I’ll be happy to assist you with greater accuracy. Please feel free to share any additional details you believe are relevant. Screenshots are especially helpful and much appreciated.

 

In the meantime, I recommend revoking MFA for the user as a first step. You can follow the step-by-step instructions provided in the official Microsoft documentation to do this safely and effectively: Manage authentication methods for Microsoft Entra multifactor authentication - Microsoft Entra ID |…

After revoking MFA, and the user account is still being enforced to use it, you can register your own phone number or device for that account. This will make future logins more convenient and manageable.

Alternatively, you can try excluding the user from Conditional Access policies, wait a few minutes to allow the changes to sync, and then proceed to remove MFA from their account.

 

Note: Please understand that our initial response does not always resolve the issue immediately. However, with your help and more detailed information, we can work together to find a solution. 

I hope this information is helpful. Please follow these steps and let me know if it works for you. If not, we can work together to resolve this. 

Thank you for your patience and your understanding. If you have any questions, please feel free to reach out. 

I'm looking forward to your reply. 


If the answer is helpful, click "Accept Answer" and vote positively. If you have more questions about this answer, click "Comment".

Note: Follow the steps in our documentation to enable email notifications if you want to receive email notifications related to this topic.

User image

Was this answer helpful?

0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Matt Roberts 45 Reputation points
    2025-10-23T13:26:51.4233333+00:00

    Thank you for the information, using both methods we have been able to find a quick work around as well as a permanent solution.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.