Azure AD guest invite seems to accept user without the first-time consent process?

Anonymous
2022-05-13T06:35:00.783+00:00

My application invites external users as guest to our tenant. I have test this with a couple of external users and it works fine. Once the user clicks on the invite link, they are prompted to the Accept/Cancel window. Through that process they are also able to add the guest account to their Authenticator App via Scan QR. However, for our main client once we send the invite link, the Accept/Cancel window does not come up. Rather, it appears it just accepts user and redirects to our App. Hence, the guest user does not have a chance to add the guest AD account to their Authenticator App. Do you know what is the issue and how it can be resolved? I have checked for ways to manually add the Guest AD Account to the authenticator app with no luck. The password of the original account does not work with the Guest AD Account and also I did not find a way on how the QR Scan code can be generated.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Answer accepted by question author
  1. Alfredo Revilla - Upwork Top Talent | IAM SWE SWA 27,526 Reputation points Moderator
    2022-05-20T00:45:29.217+00:00

    Hello @Anonymous , Accept/Cancel prompt should always appear unless the invitation has previously been accepted. Depending on the MFA configuration for your tenant some users may be required to enroll or not. The simplest way to enforce it is to Enabling security defaults. Another option, a more robust one, is to create a Conditional Access Policy that requires all external and guest users to do MFA.

    Let us know if this answer was helpful to you or if you need additional assistance. If it was helpful, please remember to accept it so that others in the community with similar questions can more easily find a solution.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.