Requesting MFA without having policy configured or enabled

Rodolfo aguiar 40 Reputation points
2024-10-10T16:20:39.94+00:00

Good morning!

I have a problem in my company. There is no MFA policy configured and there is no account enabled for MFA, but it is asking for MFA registration. Can you help me?

User's image

does not have SSPRUser's image I found this policy, but I can't change itUser's image

here it is disabledUser's image

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,172 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sandeep G-MSFT 19,761 Reputation points Microsoft Employee
    2024-10-14T06:10:04.0166667+00:00

    @Rodolfo aguiar

    Thank you for posting this in Microsoft Q&A.

    As I understand users are getting prompted for MFA registration while trying to access Azure resources.

    This can happen in multiple scenarios,

    Check and confirm if security defaults is enabled.

    1. Login to Azure portal with Global admin credentials.
    2. Access Microsoft Entra ID blade.
    3. Access Properties on the left side of the page.
    4. Click on Manage Security Defaults and confirm if it is disabled.

    Prompt can come due to registration campaign in Entra ID as well. Registration campaign to set up Microsoft Authenticator app is pushed by Microsoft recently.

    As we always believe Microsoft authenticator app method is the stronger than SMS and Phone methods.

    Below is the article that we have categorized and listed depending on the authentication methods for MFA.

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods#authentication-method-strength-and-security

    Follow steps to check and confirm registration campaign settings,

    • Login to https://entra.microsoft.com/ using global administrator credentials.
    • Click on Protection blade on the left pane and then select "Authentication methods".
    • Click on registration campaign and Edit button on the top. User's image
    • Now under state you can click on the drop down option and you will see options to disable registration campaign. User's image
    • By default "Microsoft managed" is selected.
    • You can also add group of users whom you do not want to get authenticator app installed.

    For more information you can refer below article,

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/how-to-mfa-registration-campaign#enable-the-registration-campaign-policy-using-the-microsoft-entra-admin-center

    Let us know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.