I have setup conditional access for someone to only prompt them for MFA if they are away from their office location.
This in itself it working perfectly, although maybe a little too well.
The person is using their own personal laptop, and not joined to the company network. When they use the local outlook app to connect, it as expected prompts for MFA, and after they authenticate, it logs them in. Now if they open Teams (as an example) it again prompts them for MFA, and if they authenticate, logs them in.
Is it possible to remove this 2nd authentication prompt? so that it can use the already provided credentials and MFA as a SSO?
I know within AD Connect there is the option to enable SSO, but this states that it only applies when on the company network.
Any ideas?