Action required: Enable multifactor authentication for your tenant by 15 October 2024

Steven Knoll 0 Reputation points
2024-08-22T18:46:34.77+00:00

We received an email that our tenant is required to have MFA enabled for sign in to Azure portal, Microsoft Entra admin center, and Intune admin center. We ran the powershell to identify users and authentication methods. The powershell returned users do not have MFA enabled, so we do not comply with the upcoming action requirements.

We have a conditional access policy that applies to all users and all cloud services. The policy integrates Duo MFA with our sign in to Microsoft services.

Why is our conditional access policy not sufficient? Must we enable Microsoft Authenticator in addition to Duo MFA so we comply - but this requires two MFA components which seems like overkill.

Thanks for your support!

Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Marcin Policht 49,640 Reputation points MVP Volunteer Moderator
    2024-08-22T19:54:09.76+00:00

    As per https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication

    If you're using a federated Identity Provider (IdP), such as Active Directory Federation Services, and your MFA provider is integrated directly with this federated IdP, the federated IdP must be configured to send an MFA claim.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

  2. Raja Pothuraju 23,465 Reputation points Microsoft External Staff Moderator
    2024-08-30T21:26:07.03+00:00

    Hello @Steven Knoll,

    Thank you for posting your query on Microsoft Q&A.

    From your description, I understand that you’re referring to the recent announcement about MFA enforcement, particularly the mandatory multifactor authentication for Azure and other administration portals starting on October 15, 2024. You’re asking whether this enforcement will support third-party MFA providers like DUO.

    If you’re using a third-party MFA provider (DUO) for second-factor authentication and have configured it through the Conditional Access Custom Controls preview, it will not satisfy the new MFA requirements. To continue using your external solution with Microsoft Entra ID, you should migrate to the External Authentication Methods (EAM) preview.

    If your DUO MFA is already configured through the External Authentication Methods preview, it will support the upcoming MFA enforcement requirements.

    You’ll need to verify how your DUO configuration is set up in your tenant—whether it’s configured through Custom Controls (Preview) or External Authentication Methods (Preview).

    Please refer to the screenshot below for guidance on verifying the configuration.

    If your DUO MFA is set up through Custom Controls (Preview), you can find it under Entra ID > Security > Conditional Access > Custom Controls (Preview).

    User's image If your DUO MFA is set up through External Authentication Methods (EAM) Preview, it will be visible under Entra ID > Security > Authentication Methods > Policies > External (Preview).User's image

    Please verify your setup. If it’s not configured under the External Authentication Methods blade, refer to the following document for instructions on setting up your MFA, and contact DUO support for the required details.

    Additional Resources:

    For more information, please refer to the following articles.

    Planning for mandatory multifactor authentication for Azure and other administration portals

    Manage an external authentication method in Microsoft Entra ID (Preview)

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,
    Raja Pothuraju.


  3. Steven Knoll 0 Reputation points
    2024-09-12T19:33:19.8466667+00:00

    @Raja Pothuraju thanks for the detailed write-up. I am reviewing and will accept the solution if it solves the requirement.

    On a related note, Duo released a public response to Microsoft's MFA requirement:
    https://app.securitymsp.cisco.com/e/es?s=4673582&e=5530&elqTrackId=f57670e4f88240b889e171d9ac910a39&elq=ced3f4981e0c412eac119b6963a041a4&elqaid=164&elqat=1&elqak=8AF592110737E270874B97AEB04677C0A221422511A09A2CBC97399D002ACD60F015


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.