Microsoft Entra ID のSSO利用時の挙動について

Maeda_K 0 評価のポイント
2026-09-17T02:28:39.0633333+00:00

Microsoft Entra ID のSSO利用時の挙動について、ご教示いただきたいです。

一部ユーザーで、あるエンタープライズアプリケーションへSSOログインする際、アプリケーションを選択するたびに Windows Hello for Business の認証(PIN・顔認証等) が求められます。

一方で、同一テナント内の別ユーザーでは、同じ条件付きアクセスが適用されているにもかかわらず、追加認証を求められずSSOできています。

サインインログの「認証の詳細」を比較すると、以下の差異がありました。

認証を求められるユーザー

  • Windows Hello for Business
  • Previously satisfied(MFA requirement satisfied by multi-factor authentication claim)

認証を求められないユーザー

  • Previously satisfied(First factor requirement satisfied by claim in the token)
  • Previously satisfied(MFA requirement satisfied by claim in the token)

トークンによるシームレスSSOを実施したいです。

同様の事象を経験された方や、確認すべき箇所をご存じの方がいらっしゃいましたらご教示いただけますと幸いです。

よろしくお願いいたします。

※毎回認証を求められるユーザーの端末でdsregcmd /statusコマンド実行し、一部抜粋しました。

+----------------------------------------------------------------------+

| SSO State |

+----------------------------------------------------------------------+

            AzureAdPrt : YES

  AzureAdPrtUpdateTime : 2026-09-16 05:29:43.000 UTC

  AzureAdPrtExpiryTime : 2026-09-30 05:29:42.000 UTC

   AzureAdPrtAuthority : https://login.microsoftonline.com/5d0b27a9-c583-41e4-xxxxxxxxxx

 AcquirePrtDiagnostics : PRESENT

  Previous Prt Attempt : 2026-09-16 05:38:02.796 UTC

        Attempt Status : 0xc00000d0

         User Identity : [email protected]

       Credential Type : Password

        Correlation ID : bfc9b074-a918-4cc3-b356-01bxxxxxxxx

          Endpoint URI : https://login.microsoftonline.com/5d0b27a9-c583-41e4-xxxxxxxxxxxxx/oauth2/token

           HTTP Method : POST

            HTTP Error : 0x0

           HTTP status : 400

     Server Error Code : invalid_request

Server Error Description : AADSTS90002: Tenant 'xxxxx.local' not found. Check to make sure you have the correct tenant ID and are signing into the correct cloud. Check with your subscription administrator, this may happen if there are no active subscriptions for the tenant. Trace ID: 545cb48b-9cbb-49fb-bd24-xxxxxxxxxxxxx Correlation ID: bfc9b074-a918-4cc3-b356-xxxxxxxxxxxxxxxxxx Timestamp: 2026-09-16 05:38:02Z

         EnterprisePrt : NO

EnterprisePrtAuthority :

             OnPremTgt : YES

              CloudTgt : YES

     KerbTopLevelNames : .windows.net,.windows.net:1433,.windows.net:3342,.azure.net,.azure.net:1433,.azure.net:3342
Azure ロールベースのアクセス制御
Azure ロールベースのアクセス制御

Azure リソースに対してきめ細かいアクセス管理を提供する Azure サービス。業務の遂行に必要な権限のみをユーザーに付与できるようになります。

0 件のコメント コメントはありません

1 件の回答

並べ替え方法: 古い順
  1. takeig 0 評価のポイント
    2026-09-17T02:47:21.1666667+00:00

    記載の内容を見る限り、条件付きアクセスそのものよりも、問題が発生しているユーザーの端末でPRTを使用したSSOが正常に再利用できているかを確認した方がよいと思います。 記載の内容から、AzureAdPrt : YESのため、PRT自体は取得されていますが、その後のPRT取得または更新処理で[email protected]が使用され、EntraIDへの要求が失敗しています。

    Previous Prt Attempt : 2026-09-16 05:38:02.796 UTC

    User Identity : [email protected]

    Credential Type : Password

    HTTP status : 400

    Server Error Code : invalid_request

    AADSTS90002: Tenant 'xxxxx.local' not found.

    .localのUPNがEntraIDへの認証要求に使用され、「AADSTS90002: Tenant 'xxxxx.local' not found.」となっているため、この部分が影響している可能性があると思います。 そのため、まず正常なユーザーと問題が発生しているユーザーで、以下を比較してみてはいかがでしょうか。

    • whoami /upnの結果
    • AD側のUPN
    • EntraID側のUPN
    • dsregcmd /status の User Identity、AzureAdPrt、AzureAdPrtAuthority

    この回答は役に立ちましたか?


お客様の回答

質問作成者は回答に "承認済み"、モデレーターは "推奨" とマークできます。これにより、ユーザーは作成者の問題が回答によって解決したことを把握できます。