Share via

Modification Entra CA policy for mfa causing users logged out

usman moavia 5 Reputation points
2025-11-06T14:33:14.1466667+00:00

Hi, Recently, I have modified conditional access policy for internal users to require mfa i just excluded one users but after that users are keep on logging out which is also causing conditional access bypass alert on sentinel. I changed the CA policy again to setup sign in frequency to 30 days and checked the persistent browser session to always but it doesn't resolved my issues

Microsoft Security | Microsoft Entra | Microsoft Entra ID

3 answers

Sort by: Most helpful
  1. usman moavia 5 Reputation points
    2025-11-10T11:39:09.4+00:00

    still waiting for support

    Was this answer helpful?

    0 comments No comments

  2. usman moavia 5 Reputation points
    2025-11-07T11:03:00.6066667+00:00

    I am considering a solution that may be causing problem i haven't tested yet.

    If i just update stsrefreshtoken this will update the timestamp and will assign token according to current CA policy configuration. I believe as default sign in frequency by Microsoft is 90 days and modification were done like 2-3 weeks ago so the token assigned to users are old ones with previous configuration that maybe causing this problem. Lastly, i would re-register authentication methods for the users that are facing this problem.

    Can you please review my proposed solution and validate if its good

    Was this answer helpful?

    0 comments No comments

  3. usman moavia 5 Reputation points
    2025-11-07T09:52:00.2866667+00:00

    Hi,

    first of all our environment i all cloud and we are using Entra for access control only we are not managing devices from here. Secondly MFA scope is set to All cloud apps, its for outlook aswell. I noticed most of the failures are triggering by non interactive attempts. Regarding users a subset of users are facing this problem causing Sentinel to trigger alert "Attempt to Bypass Conditional Acesss in Entra ID" and most common error is "["50078: Other MFA required in Azure AD"," MFA required in Azure AD"]"

    Please help me out in this it is really getting frustrating because its almost three weeks i am hitting my head to resolve this

    Here is screenshots for my CA policy:

    User's image

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.