Jump to content

Recommended Posts

Posted

Morning All

 

As the title suggests I am looking to setup MFA enabled SSO for Arbor by using Azure Conditional Access, this is instead of needing to use the Arbor 3rd party app based solution, as some of our staff do not wish to use a personal device for MFA and have MFA tokens instead.

 

When authorising Arbor SSO within Azure I had to grant permission to the Enterprise Application "arbor-sso-production", I have created a Conditional Access rule based on this Application as I can see that user login sessions are being logged against this application. My theory being this should prompt for MFA and by doing a What If analysis, it says my newly created rule will be applied and request for MFA; however, the real world experience is that MFA is not being prompted for and the browser session is passed straight through. I have tried this on an private browsing session to ensure there are no session tokens from before I introduced the policy but I'm getting nowhere. Has anyone got this setup correctly and mind sharing any insights?

Posted
Do you have any other conditional access policies in place that could be taking priority? Such as bypass MFA for sign-ins originating from the schools IP address? If you do, you might need to put an exclude rule on those to force the MFA.
Posted
I do have other CA policies, but they target specific accounts or applications. I was deliberately testing from my mobile to ensure no such policies got in the way except for the one I am testing.
Posted
If you check the sign in logs on AzureAD for your test user you should be able to get some more details on if the policy is trying to apply conditional access and why it passes/fails.
Posted

Yes, I had a look at the sign-in logs but unfortunately there isn't much there; well, there is, but nothing pointing to it trying to apply the CA policy. Looking at it from the Application side, and going to it's CA page, there are 3 CA policies listed for this app:

 

1. Global Admin MFA (prompts GA users for MFA for any login session).

2. Modern Auth (Enforces modern Auth for all login sessions)

3. My Arbor Test Policy.

 

So the application is (correctly) aware of what CA policies may affect it depending on who logs in. All of my sign in requests just list as single factor auth in the logs, suggesting that I may have the policy wrong, I've been over it several times and it is very simple, I don't see how it could be wrong.

  • 4 weeks later...
Posted
Not yet, I was going to log it with their support this week to see if there was any known way around it. I don't want to use their MFA as it necessitates an app and we have a number of staff using MFA tokens / fobs.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...