且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

条件访问不会提示用户输入MFA

更新时间:2023-12-01 23:50:40

因此,当您的用户从您信任的位置外部登录时,系统会提示他们输入MFA。完成MFA挑战后,他们将被授予访问权限。


根据WhatIF结果,MFA要求是"满意"的。 - 因此用户已被授予访问权限。


由于您提到用户在从不受信任的位置登录时需要MFA受到质疑,因此在这种情况下条件访问策略存在冲突。


 


Hi,

Hoping someone has seen this and can point me in the right direction.

We have a couple of conditional access policies set up in AAD, one that blocks users that arent on a trusted site and another that allows users access from untrusted locations if MFA is applied. Users are assigned one policy or the other not both. The block policy works fine, but the MFA policy allows the user to connect regardles of location.

The What IF tool shows the users getting the policy correctly based on IP:


Windows10_Allow_Untrusted_MFA

So when your users are logging in from outside your trusted locations, they are prompted for the MFA. Once the MFA challenge is completed, they would be granted access.

As per the WhatIF results, the MFA requirement is "satisfied" - hence the users have been granted access.

Since you mentioned that you need the users to be MFA challenged when they are logging in from untrusted locations, the conditional access policy in this case is in conflict.

 


登录 关闭
扫码关注1秒登录
条件访问不会提示用户输入MFA
发送“验证码”获取 | 15天全站免登陆

相关阅读

推荐文章