MFA enforced when accessing Security Info from my account

Cristobal Fallas 30 Reputation points
2023-10-18T16:19:01.5433333+00:00

This is the scenario:

  • Security Defaults are disabled
  • All CA polices are in Read Only Mode
  • MFA is not enforced in the Legacy MFA portal
  • User is enabled for combined registration and MFA methods such as phone and authenticator app have been added to the user account.

When a user attempts to access "Security Info" section within "My Account" it is always prompted to complete MFA; however, there is not policy enabled for this enforcement. I cannot find any Microsoft official document indicating that this is the default or expected behavior for the Combined registration.

does anyone know why this is happening? Being this the case, the Conditional access policy for "Securing Information Registration" becomes pointless.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,185 questions
0 comments No comments
{count} votes

Accepted answer
  1. Domooney-MSFT 2,606 Reputation points Microsoft Employee
    2023-10-19T10:10:32.7933333+00:00

    Hi @Cristobal Fallas

    Thank you for posting your query on Microsoft Q&A.

    If a user already has at least one MFA method configured then they will always be prompted for MFA when accessing the "Security Info" portal. This is to prevent any bad actor from adding / removing MFA methods for the user with just their password. This would subsequently allow them to access other resources that are configured to require MFA.

    The Conditional Access policies for "Securing Information Registration" become more useful for first time registration of MFA methods, i.e only allowing MFA to be registered from a hybrid or compliant device, or only inside the corp network.

    I hope this helps, but if you have any further queries just let me know.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.