foofighterjim Posted September 26, 2022 Posted September 26, 2022 Morning All As the title suggests I am looking to setup MFA enabled SSO for Arbor by using Azure Conditional Access, this is instead of needing to use the Arbor 3rd party app based solution, as some of our staff do not wish to use a personal device for MFA and have MFA tokens instead. When authorising Arbor SSO within Azure I had to grant permission to the Enterprise Application "arbor-sso-production", I have created a Conditional Access rule based on this Application as I can see that user login sessions are being logged against this application. My theory being this should prompt for MFA and by doing a What If analysis, it says my newly created rule will be applied and request for MFA; however, the real world experience is that MFA is not being prompted for and the browser session is passed straight through. I have tried this on an private browsing session to ensure there are no session tokens from before I introduced the policy but I'm getting nowhere. Has anyone got this setup correctly and mind sharing any insights?
IT_JB Posted September 26, 2022 Posted September 26, 2022 Do you have any other conditional access policies in place that could be taking priority? Such as bypass MFA for sign-ins originating from the schools IP address? If you do, you might need to put an exclude rule on those to force the MFA.
foofighterjim Posted September 26, 2022 Author Posted September 26, 2022 I do have other CA policies, but they target specific accounts or applications. I was deliberately testing from my mobile to ensure no such policies got in the way except for the one I am testing.
IT_JB Posted September 26, 2022 Posted September 26, 2022 If you check the sign in logs on AzureAD for your test user you should be able to get some more details on if the policy is trying to apply conditional access and why it passes/fails.
free780 Posted September 26, 2022 Posted September 26, 2022 There are some options yu can change in the CA policy depending on licensing. https://learn.microsoft.com/en-us/azure/active-directory/authentication/concepts-azure-multi-factor-authentication-prompts-session-lifetime
foofighterjim Posted September 26, 2022 Author Posted September 26, 2022 Yes, I had a look at the sign-in logs but unfortunately there isn't much there; well, there is, but nothing pointing to it trying to apply the CA policy. Looking at it from the Application side, and going to it's CA page, there are 3 CA policies listed for this app: 1. Global Admin MFA (prompts GA users for MFA for any login session). 2. Modern Auth (Enforces modern Auth for all login sessions) 3. My Arbor Test Policy. So the application is (correctly) aware of what CA policies may affect it depending on who logs in. All of my sign in requests just list as single factor auth in the logs, suggesting that I may have the policy wrong, I've been over it several times and it is very simple, I don't see how it could be wrong.
ful56_uk Posted October 19, 2022 Posted October 19, 2022 Did you ever manage to sort this out as I am experiencing the samething, just not triggering mfa on the app for arbor.
foofighterjim Posted October 19, 2022 Author Posted October 19, 2022 Not yet, I was going to log it with their support this week to see if there was any known way around it. I don't want to use their MFA as it necessitates an app and we have a number of staff using MFA tokens / fobs.
ful56_uk Posted October 19, 2022 Posted October 19, 2022 yeah same reason as me why i dont want to use there mfa
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now