Conditional Access - MFA enabled all users - external user blocked

VMAX_Lapras 25 Reputation points
2024-01-08T16:12:21.5866667+00:00

Hello there.

We have recently gone through the legacy > new MFA migration as per the recommended process.

We have enabled authentication methods that correspond with what we had in legacy.

There is an external user (account created with an address not part of our tenant) who is getting blocked by the MFA all users policy however.

The authentication methods we have in place are here.

authentication_methods

The error the person is receiving is here. I have tried resetting the MFA settings.

Untitled

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. !Daniel Bradley 1,071 Reputation points MVP
    2024-01-09T15:57:03.92+00:00

    Hi @VMAX_Lapras

    I see you have posted a screenshot of your Authentication Strength; the error suggests the user does not meet the policy.

    In Microsoft Entra, expand Protection > Authentication methods. Then under Monitoring, select User registration details.

    From that page, find the user and see the methods they have registered and the default.

    You could reset their MFA method and direct them to aka.ms/mfasetup to set up an appropriate method.

    Let me know!


    https://www.linkedin.com/in/danielbradley2/

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.