Share via

Inconsistent MFA behaviors

JKM 0 Reputation points
2026-02-25T13:45:10.3+00:00

We have all of our users on Intune joined devices. They're all in the office where the office IPs are whitelisted. They're all applied to the same conditional access policies.

Some users will get no MFA prompts at all while in office. Others who are also in office will get MFA prompts. Some getting them 3 times a day. Entra logs show consistently show "Token Protection - Sign In Session Status" as 1002 when the user gets prompted.

This only happens when using Google Chrome. Any ideas? Let me know if you need more information.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
    2026-02-25T14:12:27.0966667+00:00

    Any help from:

    https://www.michaelvink.com/l/conditionalaccesstokenprotection/

    If you are using token protection in a CA policy consider disabling the policy and testing

    https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-token-protection

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.