Hi @Nattawut Teerajarukul , according to this docs article this behaviour is by design, therefore a full re-auth is triggered using sign-in frequency: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-session-lifetime#user-sign-in-frequency-and-multi-factor-authentication
Maybe you could solve the challenge with Conditonal Access policies which trigger MFA when accessing a certain cloud app or by other conditions.