A cloud-based identity and access management service for securing user authentication and resource access
Hello Luca Castelli
Thanks for contacting MS Q&A. I will be able to help you with resolving your issues.
Seems this is a known issue with the setup. This timeout is not configurable via the extension or registry settings, and it's been a known limitation since its earlier versions.
- The NPS Extension for Azure MFA invokes a call to Azure AD to validate the 2FA.
- If no response (approval/denial) is received within 20 seconds, the NPS Extension terminates the authentication as failed.
- This 20-second window is not configurable and is enforced by the Microsoft Azure MFA SDK used by the extension.
Although you can't increase the timeout directly, here are a few workarounds you might consider:
1. Enable “Push Notification” Only MFA
If users are relying on entering a code or approving via a slow device, they may miss the 20-second window. Enforcing push notifications can speed up their experience.
- Educate users to enable notifications on their Microsoft Authenticator app.
- Disable other methods (like phone call/SMS or code-based entry) from the MFA settings in Entra ID.
This ensures the approval can be made instantly with a tap.
Siri