Trouble with MFA Prompts on Macbook for AVD Users

0
23
Asked By TechSavvy123 On

I'm experiencing an issue with a user who is accessing Azure Virtual Desktop (AVD) from a Macbook. She claims she never receives the two-factor authentication (2FA) prompt during login. When I try to revoke her multifactor authentication settings, the action fails through the portal. I can revoke her sessions, but not the multifactor authentication ones, which results in a failure message. Has anyone else encountered this problem? Could it be related to a recent service outage?

5 Answers

Answered By NetworkingPro92 On

So, just to clarify, it sounds like the user may not be getting the 2FA prompt, but other users are fine. You mentioned that for your environment, if a session times out, it prompts for 2FA for the Windows app, right? There's typically a token lifetime of about 90 days. Maybe there's something specific happening with the Macbook setup.

Answered By DataGuru56 On

First, check the user's sign-in logs in Entra to see if conditional access was bypassed for them. It's possible that the option to revoke MFA sessions is no longer valid after the transition to per-user MFA, which might explain the error you're encountering.

Answered By SupportHelper99 On

I put in a ticket with Microsoft regarding the MFA sessions, and they mentioned that the option to revoke MFA is tied to whether the user is enabled or enforced in per-user MFA. It seems like the right move now is to use the 'Revoke sessions' feature instead. I hope this helps clear things up!

Answered By MFAExpert42 On

This issue seems to have been common for a few weeks now, and while it doesn't directly link to the outage on October 29th, it's worth considering. The way MFA sessions are revoked has indeed changed lately, and Microsoft is now recommending using 'Revoke sessions' instead, as the per-user MFA option has been retired.

Answered By CloudNinja87 On

I had a similar issue where a user accidentally reported the MFA prompt as malicious. You might want to check if the user is blocked on the admin side; there's a page on Microsoft Entra that can help with that.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.