Conditional mfa access policy not applying

Peter Dufwa 6 Reputation points
2022-06-20T17:15:44.037+00:00

Hello,
I Am trying to get an conditional access policy to apply for logging on to an oauth enabled application. I Have created a very specific policy that should be applied when a specific user logs on to the specific cloud app. When testing the policy with the "What If", "what is" says the policy is to be applied but in real life it is not.

Any help would be much appreciated.

Regards
Peter

Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Peter Dufwa 6 Reputation points
    2022-07-05T09:58:32.267+00:00

    Hi,
    Yes it is answered here https://www.reddit.com/r/AZURE/comments/s1wx6b/oauth2_w_registered_application_not_working/, and is seems to be some kind of issue with Oauth2.0 and conditional access policies.

    Regards
    Peter

    1 person found this answer helpful.

  2. Manu Philip 20,206 Reputation points MVP Volunteer Moderator
    2022-06-20T17:56:38.697+00:00

    The user might have authenticated already using the browser and that is one of the reason why you see that MFA is not applying. In order to verify the MFA login events, you can go to the user blade as shown below and see, if any MFA events are being registered there.
    212996-image.png

    Also, check if you are able to see the OATH verification code is logged as the authentication method in Authentication details tab as below:
    213073-image.png

    ----------

    --please don't forget to upvote and Accept as answer if the reply is helpful--


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.