Share via

When I use a custom redirect URI such as schema://app, the application signs in without showing the DUO MFA prompt, and the user is logged in directly to the resource. Why no Conditional Access policy is applied ?

SB 0 Reputation points
2026-02-10T19:57:33.75+00:00

When I use a custom redirect URI such as schema://app, the application signs in without showing the DUO MFA prompt, and the user is logged in directly to the resource. In this flow, no Conditional Access policy is applied.

However, when I use the redirect URI as http://localhost, the DUO MFA prompt is displayed, and the Conditional Access policy is evaluated and enforced correctly.

How does Microsoft Entra ID evaluate Conditional Access policies based on the redirect URI, and why does the behavior differ between a custom URI scheme and http://localhost?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 159.9K Reputation points MVP Volunteer Moderator
    2026-02-10T21:53:17.6233333+00:00

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.