Aufforderung zur Anlegung des MFA obwohl dieser schon aktiviert ist

Frederik Rier 41 Zuverlässigkeitspunkte
2025-10-20T19:16:29.2733333+00:00

Hello everyone, based on the CIS Benchmark, I created a few Conditional Access policies. These policies are intended to trigger MFA, but not on a permanent basis.

Issue description: Every time I log in, I have to enter my MFA once. After that, I have to confirm my device for MFA approval. Once confirmed, I am taken back to the login screen, log in again, and then I have to confirm my MFA device once more.

Here is a Screenshot:

Benutzerbild

My CA-Policies:

Overview:Benutzerbild

MFA for administrative roles:

Benutzerbild

MFA for all users:

Benutzerbild

Has anyone an Idea why this is happening?

Thank you,

xxxxx

Rollenbasierte Zugriffssteuerung in Azure
Rollenbasierte Zugriffssteuerung in Azure

Ein Azure-Dienst für die präzise Zugriffsverwaltung für Azure-Ressourcen, mit dem Sie Benutzer*innen ausschließlich die Berechtigungen erteilen können, die sie für ihre Arbeit benötigen

0 Kommentare Keine Kommentare

Antwort, die vom Frageautor angenommen wurde
Vivian-HT 17,900 Zuverlässigkeitspunkte Externe Microsoft-Mitarbeiter Moderator
2025-10-21T02:31:51.73+00:00

Since you wrote your question in English, I will also provide the answer in English, even though the portal interface appears in German.

Dear @Frederik Rier,

Thank you for posting your question in the Microsoft Q&A forum.

According to your audit logs and screenshots. After reviewing the entries, we noticed repeated MFA-related callbacks (POST UserAuthMethodSecurityInfoRegistrationCallback) and multiple updates to user security information. Moreover, please noted that Admins will always be prompted for MFA at least once per session (by design)

However, repeated prompts after successful login strongly suggests that the issue is not a failure of MFA itself, but rather:

  • Overlapping Conditional Access policies (e.g., MFA for all users and MFA for administrative roles both applying to the same account).
  • Missing session persistence settings, which causes Azure AD to treat each login as a new session.

Before giving you the best solution, could you please confirm these questions below to help me diagnose the issue more effectively: 

  • Are repeated MFA prompts happening for all users, or only for administrative accounts?
  • Since you are using business account, are you the admin in your company?

In the meantime, here are some steps I recommend you try which helping for narrowing down and investigating the issue:

Step 1. Use the “What If” Tool

The Conditional Access What If policy tool helps you understand the result of Conditional Access policies in your environment. It can be useful when simulating uncommon scenarios, enabling you to design more comprehensive security policies. Instead of manually testing your policies with multiple sign-ins, this tool helps you simulate a sign-in for a user or service principal. The simulation estimates how your policies affect this sign-in and generates a report.

You can find the What If tool in the Microsoft Entra admin center > Entra ID > Conditional Access > Policies > What If, simulate sign-in for the affected user to confirm which policies apply.

For more information, please refer to Troubleshoot Conditional Access Policies with the What If Tool (English) and Beheben von Problemen mit Richtlinien für bedingten Zugriff mit dem What-If-Tool (German)

Step 2. Exclude Users to Narrow Down

  • Temporarily exclude the affected user from one policy at a time to narrow down which one (For example: Start with MFA for all users. Then test with MFA for administrative roles).
  • Observe if repeated MFA stops after excluding a specific policy.

Step 3. Check Regular User Behavior

Test with a non-admin account:

  • If regular users only see MFA once, the issue is specific to admin policies.
  • If they also experience repeated MFA, session settings need adjustment.

Step 4. Configure Session Controls

Add Sign-in frequency (e.g., 90 days) and Persistent browser session to your CA policies.

For more information, please refer to Conditional Access: Session (English) and Bedingter Zugriff: Sitzung (German).

Step 5. Enable “Remember MFA on Trusted Devices”

For more information, please refer to Microsoft Entra recommendation: Minimize MFA prompts from known devices (English) and Microsoft Entra -Empfehlung: Minimieren von MFA-Eingabeaufforderungen von bekannten Geräten

I hope this information is helpful. Please follow these steps and let me know if it works for you. If not, we can work together to resolve this.

Please understand that our initial response does not always resolve the issue immediately. However, with your help and more detailed information, we can work together to find a solution.

Thank you for your patience and your understanding. If you have any questions, please feel free to reach out.

I'm looking forward for your reply.


If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".   

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

Antwort akzeptieren01 Antwort

War diese Antwort hilfreich?


0 zusätzliche Antworten

Sortieren nach: Neueste

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.