ForcePoint Posted September 11, 2020 Posted September 11, 2020 I have setup conditional access for someone to only prompt them for MFA if they are away from their office location. This in itself it working perfectly, although maybe a little too well. The person is using their own personal laptop, and not joined to the company network. When they use the local outlook app to connect, it as expected prompts for MFA, and after they authenticate, it logs them in. Now if they open Teams (as an example) it again prompts them for MFA, and if they authenticate, logs them in. Is it possible to remove this 2nd authentication prompt? so that it can use the already provided credentials and MFA as a SSO? I know within AD Connect there is the option to enable SSO, but this states that it only applies when on the company network. Any ideas?
aicrd Posted September 11, 2020 Posted September 11, 2020 When logging into Outlook/Teams you are prompted to let your organisation manage your device. If you select yes, you'll automatically be logged into all the office apps on your device.
free780 Posted September 11, 2020 Posted September 11, 2020 You can if you configure intune with MAM so the intune app or company portal does the SSO. You need the intune licence to so this. Or Azure P2 which only does MFA if its a new device/location.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now