Why is Azure portal warning about MFA not applied if we have Conditional Access policies active?

Guadalupe García 0 Reputation points
2024-08-29T15:35:08.4533333+00:00

Our Azure portal is warning about MFA not being applied when we have three different Conditional Access policies applied. One for all users, one for admins (all applications) and one for external and guest users.

These policies are configured to act under user risk, sign in risk (both incluiding from low to high risk) and location conditions granting access only when users complete multifactor authentication strenght we've previously configured.

These policies also have some account exceptions (two admins and a few application/device accounts).

I've found that Identity Protection Registration Policy is disabled. Could enabling it for all users affect the excepted accounts on my conditional access policies? Would this make the Azure Portal change the MFA status it's currently showing?

Captura de pantalla 2024-08-29 090238

Captura de pantalla 2024-08-29 085048

Captura de pantalla 2024-08-29 090319

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,692 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vasil Michev 105.7K Reputation points MVP
    2024-08-29T18:04:34.3566667+00:00

    Afaik Microsoft is publishing this message (and similar ones across all other available channels) indiscriminately, without taking into consideration the currently configured controls in the tenant. They simply want to make sure admins are familiar with the coming changes in order to avoid issues come Oct.

    Do note however that there will be no exceptions for said MFA enforcement - every user accessing an Azure admin endpoint will be subject to the requirement.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.