Setup MFA Exclusion but It is not working

BmoreOs 141 Reputation points
2023-01-24T19:28:03.8566667+00:00

We have an account that we would like to use to send email notifications for a SaaS app. We input the SMTP settings and credentials for this account. MFA is excluded but errors occur. When logging into this account, MFA continues to ask for registration. I followed the below guide on how to setup exclusions, but it is not working.

[https://learn.microsoft.com/en-us/azure/active-directory/governance/conditional-access-exclusion

I saw one note to look under Security - Identity Protection but that is off due to us not having P2. Any ideas why this isn't working?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} vote

3 answers

Sort by: Most helpful
  1. BmoreOs 141 Reputation points
    2023-01-27T15:19:25.4733333+00:00

    Appreciate the help @Luke Murray

    Can't say that I am an expert so going slow with this. I tried to setup a policy that would exclude the My Signins app but it is not in any search I complete. I am hesitant on allowing all cloud apps as I know this account is tied to various things and I want security to remain for those.

    Our main conditional access policy requires MFA for all users, excluding one group with two accounts in it. That is working based on the screenshot above. I am little confused on how I would setup the additional policy strictly for the My signins app and those two user accounts. I would apply it to no users and only exclude the exclusion group...but that won't work with our original policy. Is there no way to exclude a group from MFA and a single app? Is it all apps or no apps tied to all users or no users? I have the ability to exclude a group from the policy but the ability to exclude certain apps for certain people.

    I read that Microsoft is getting rid of "App Passwords" to bypass MFA completely on 3/31, and it sounds like April Fools' Day is going to be terrible for those who are unaware. Hopefully I can figure this out to fix the SSO and data migration issues.

    1 person found this answer helpful.

  2. Luke Murray 11,436 Reputation points MVP Volunteer Moderator
    2023-01-24T20:56:27.6833333+00:00

    For Conditional Access, have a look at What if, and run through that account - it should indicate what policy could be effecting it.

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/what-if-tool

    Also check Per-User MFA and make sure this is turned off:

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates


  3. BmoreOs 141 Reputation points
    2023-01-27T03:52:25.1133333+00:00

    Digging more. I found this under the user sign ins. What is "My Signins" and how do I bypass that for just this account? I don't want to impact all users. Thanks

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.