External Authentication Method

Marcos Correa 10 Reputation points
2025-02-12T16:59:27.5266667+00:00

We currently have Cisco DUO as an External authentication method for testing. I have followed the steps from Cisco DUO and added the application needed and authorized the admin approval for the app to communicate.

I have successfully set up a new testing policy that does require MFA, and enabled 'RequireMFADUO'

When I attempt to access office.com, I do not receive the prompt to choose the external authentication method(DUO). However if I were to open the web browser in private mode, I do receive the Cisco Duo.

I have tried excluding myself from Microsoft Authenticator, and all other authentication, under Authentication Methods on Entra ID. I then made sure the Microsoft enrollment campaign was disabled and it appears to be disabled. I do not want to fully disable Microsoft authenticator as there are a few users who do use the app.

Overall question: Why am I not able to receive the external authentication method as an MFA option when I attempt to access office.com?

Microsoft 365 and Office Install, redeem, activate For business Windows
Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Goutam Pratti 6,170 Reputation points Microsoft External Staff Moderator
    2025-02-14T10:05:35.49+00:00

    Hello @Marcos Correa ,

    Thank you for reaching out Microsoft Q&A.

    I Understand you configured Cisco DUO as an External authentication method for testing but When you attempt to access office.com, you do not receive the prompt to choose the external authentication method(DUO). However if I were to open the web browser in private mode, I do receive the Cisco Duo.

    Your regular browser session might be retaining some state or cookies that are causing it to default to Microsoft Authenticator instead of prompting for DUO. Clearing your browser cache and cookies might resolve the issue.

    If you're still experiencing the issue after clearing your browser cache and cookies, you should revoke all MFA sessions for the affected user. This is because the previous MFA for the Microsoft authenticator may be cached in the claim, preventing the MFA prompt from appearing. Ensure that all MFA sessions are revoked and then try again.

    For additional information and known limitations follow the document: https://duo.com/docs/microsoft-eam#create-the-duo-entra-id-application

    If you have any further questions or need additional assistance, please don’t hesitate to reach out.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.