A cloud-based identity and access management service for securing user authentication and resource access
Thank you for your response. If I uncheck the "remember multifactor authentication on trusted device" under Security/MFA/Other Cloud MFA settings the check box for do not ask again will vanish. We have used SSO with MFA for up to a year now in testing with the IT department staff and went wide scale on it last month. During all this testing the Other Cloud MFA settings where checked and things worked as one would expect.
Two weeks ago I unchecked this box as I was not able to setup a second conditional access policy for a specific app and a specific set of users to have a more stringent do not ask date policy (sign-in frequency). The new sign in frequency was not being enforced. That is why I removed the check box under other cloud MFA settings and once I did that the do not ask checkbox went away.
It is not just not showing the check box the sign-in frequency setting is being ignored as we have our normal policy set to 14 days for everyone and 1 day for the IT center. When the other cloud MFA settings is not checked it does not remember period. I have personally opened a browser logged into one of the cloud apps and am prompted for MFA with no do not ask box. I satisfy that MFA prompt and then close the browser launch the same browser and login and once again am prompted for MFA with out the do not ask box. The browser is not set to clear cookies when quitting and the behavior instantly goes back to what is expected when the other cloud MFA settings is enabled. The do not ask box reappears and if checked the browser will not ask for the specified period of time.