Multiple Conditional Access Policies - 1 for browsers mfa every day and 1 for mobile/desktop clients mfa every 7 days - Being prompted every day

Bob-the-builder1409 0 Reputation points
2023-04-11T17:52:31.3266667+00:00

I have two Conditional Access Policies. One is to require users to perform MFA for browsers once every day and the other is to require users to perform MFA for mobile and desktop clients, once every 7 days. The issue is that we are being required to perform MFA every day with the 7 day policy, on mobile and desktop clients. The logs even show this. Why are we getting prompted when the sign-in frequency is set to 7 days on desktop and mobile clients?

User's image

Thanks!

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
25,016 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 157.2K Reputation points MVP Volunteer Moderator
    2023-04-11T18:03:47.82+00:00

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-conditions#client-apps

    Why a difference in policies? Whats the business case for a one day prompt versus 7? That sounds like a recipe for MFA fatigue the browser definition is pretty broad. Do the sign in logs show the daily prompt policy is triggered?

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.