B2C Conditional Access for Sign-In Flow Not Working

Nick Branstein 1 Reputation point
2022-07-29T21:27:38.237+00:00

I have a very simple conditional access policy defined that is set to grant for users within a specific group: 226300-image.png

In my recommended SignIn flow I have MFA Enforcement set to Conditional and Enforce Conditional Access Policies selected:
226371-image.png

I have several difference users set in this group however, in all cases when the policy is evaluated it always shows PolicyDoesNotApplyReporting : 226345-image.png

Even if I turn the policy on then MFA is never enforced for these user that go through this SignIn Flow.

I've been through the documentation numerous times and I am not sure what I am missing here. Thanks!

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2022-08-02T20:58:30.133+00:00

    Hi @Nick Branstein , have you tried to see if it works if you select Cloud Apps? You currently have "No Cloud Apps" selected. The CA policy is granting access for all the users in the group (after MFA), but the CA Policy isn't going to enforce MFA on sign-in to the Azure Portal, since you'd need to add the Microsoft Azure Management cloud app. Having no cloud apps selected also explains why if you turn on the CA policy, MFA is never enforced for any of the users in the group.

    Please let me know if this helps!

    Best,
    James

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.