Unable to disable 2FA for select users

Abrazos Tech Support 0 Reputation points
2025-03-21T22:24:36.4266667+00:00

Hello- I am deploying new Windows 11 laptops to my users. The new laptops are being joined to Entra and simultaneously being joined to inTune. For 2FA, I am using a single Conditional Access policy that is set to Require Authentication Strength of Multifactor Authentication. All users in the organization are included in the policy. In order to setup new PCs for users that are not onsite to verify their 2FA credential, I am adding the users, temporarily, to the Excluded Users in the Conditional Access policy. However, those does not seem to function. I am still being prompted for 2FA. Security Defaults and legacy MFA are disabled for the organization. Please advise.

p.s. It is outrageous that Microsoft requires a paid subscription to for Azure when THEIR service is not functioning properly.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marcin Policht 49,715 Reputation points MVP Volunteer Moderator
    2025-03-21T22:54:31.47+00:00

    Use the WhatIf functionality of Entra ID CA to validate your setup.

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/what-if-tool

    Btw. you might want so also keep in mind that MFA is becoming mandatory

    https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication?tabs=dotnet


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.