Managing MFA for Share User Accounts

Robert Cameron 0 Reputation points
2023-12-19T20:38:38.55+00:00

An organization has recently moved from a hybrid environment to a full Azure/Intune environment with the exception of one server to run authentication through AD on a DC so it's still technically hybrid. Among many new things to figure out is how to provide ways for users to login when accessing shared accounts without having to rely on another employees phone number/authenticator app.

As an example, there is a computer lab that all uses one student account. ******@xxxx.com. When trying to login the employee is asked to setup authentication. But with a full classroom this would require 30 different people to put in 30 different contact methods and generate 30 different codes all at once. I've put ******@XXXX.com into two different areas to just outright disable MFA but that still doesn't seem to work.

  1. In the conditional access policies on intune devices, under the "Require multifactor authentication for all users" template, the rest of the company is assigned included, but this account has been put under excluded
  2. In Entra, under security > authentication methods > authentication policies > microsoft authenticator I've added the user to a group and have excluded the group.

but in both instances, they are still prompted to setup information to "keep it safe".

Safety means nothing without access.

Any ideas?

Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 157.4K Reputation points MVP Volunteer Moderator
    2023-12-19T22:15:24.0466667+00:00

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.