Hello @Pawan Venugopal,
Thank you for posting your query on Microsoft Q&A.
Based on your description, I understand that you are looking for a solution to re-authenticate users using only MFA, without requiring both Password and MFA, for an Azure AD B2C application. You mentioned that you were able to prompt re-authentication by adding the "prompt=login
" parameter in your request, even when the user had a valid session with Azure AD B2C. Please correct me if I’m wrong.
The "prompt=login
" parameter forces users to enter their credentials, bypassing single sign-on. However, this revokes both first-factor (password) and second-factor (MFA) sessions with Azure. Currently, it is not possible to achieve re-authentication with only MFA in Azure AD B2C or Microsoft Entra.
I recommend submitting this feature request on the Microsoft Feedback Portal. It’s an excellent way to highlight the importance of this feature for your organization. You can provide details on how this change would benefit your use case, as Microsoft product engineers regularly review feedback there.
I hope this information is helpful. Please feel free to reach out if you have any further questions.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Thanks,
Raja Pothuraju.