MFA not prompted after setting

Francis 20 Reputation points
2023-10-28T03:46:05.21+00:00

Good day!

I want to test a new policy that requires Multifactor authentication after login. Therefore, I created a new test user on Microsoft Entra ID.

After that, In Entra ID, I created a new policy by going to Security > Protect > Conditional Access > Create new policy. In the “Create new policy” menu, after setting the policy name, selecting the user, I looked for “Microsoft Azure Management” under Target Resource but could not find it. Therefore, I selected the resource “Azure ID Identity Governance” instead, and selected “Require Multifactor authentication” under Grant. However, after logging in with the test account, I wasn’t prompted to register the second factor of authentication. I repeated the test by selecting the resources “Azure Credential configuration endpoint service” and “Office 365” , and “Require multifactor authentication strength” inside Grant, but got the same results.

Then, under Microsoft Entra ID > Users, I found the option “Per-User MFA”, After clicking on “Per-user MFA”, selecting the correct user and clicking “Bulk update”, I was correctly prompted for Multifactor authentication after login.

therefore, I would like to ask the following:

  • How can I configure multi factor authentication in the “Create new policy” menu? Especially, what shall I select under Target resource?
  • How can I setup multifactor authentication using powershell?

Thanks for your support.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2023-10-31T21:49:58.4833333+00:00

    @Francis ,

    The Conditional Access team also replied that you can apply the policy for the Microsoft Admin Portals instead. I'm still also waiting for confirmation about the name change though.

    User's image

    Cloud apps, actions, and authentication context in Conditional Access policy | Microsoft Learn


2 additional answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2023-10-30T22:02:14.7+00:00

    Hi @Francis ,

    I checked in my tenant and am seeing the same issue, so I reached out to the Conditional Access team to see if they can confirm whether the name changed.

    However, another engineer on my team has an older Conditional Access policy that he created for restricting access to Microsoft Azure Management. In that policy it looks like the cloud app referenced changed to Windows Azure Service Management API.

    Additionally, when navigating to the Enterprise Applications list and searching for Windows Azure Service Management, this redirects to the Microsoft Azure Management app.

    It looks like the name may have changed to Windows Azure Service Management API.

    User's image

    We are waiting on the Conditional Access team to confirm about this change and will update the thread once we hear back.

    0 comments No comments

  2. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2023-10-30T22:20:53.1833333+00:00

    @Francis

    Thank you for your post!

    As mentioned by Marilee, I was able to reproduce your issue and wasn't able see the Microsoft Azure Management cloud app. However, I did notice that when I went to an older CA policy - one that I created specifically for restricting access to Microsoft Azure Management, the cloud app referenced changed to Windows Azure Service Management API.

    Additionally, when navigating to the Enterprise Applications list and searching for Windows Azure Service Management, this redirected me to the Microsoft Azure Management app.

    User's image

    Once we hear back from the CA Policy team regarding this change, we'll update our documentation to help alleviate any future confusion for customers going forward.


    Additional Links:

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.