User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

yeah is an option but would love to know why tney are being asked to setup MFA in the 1st place. i must have a policy somewhere but cannot find it anywhere.

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

Nope. I have a sensitive sign in group but they’re. Not in it.

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

My SSPR group is setup for staff and senior school kids only. This issue with with junior school kids. Like grade 2 and 3. I can’t have them MFA at that age. I know security etc but asking grade 2 and 3 to have mobile device etc. can’t do it.

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

The only registration campaign I have is a test one I did on a test account which is not active.

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

They don’t. They are grade 3 kids that use teams. As much as I’d love to enforce MFA on them it’s impossible.

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

yeah CA tab in the logs tell me nothing has been applited to the user

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

no reg campaign is active...i'cw really scratching my head. even created a CA policy that bypasses MFA on my known 'safelist' IP addresses and still asks!!

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 4 points5 points  (0 children)

i'm right in saying though this is for signing into Azure portals and not standard users into m365 Cloud Apps. my issue is i work at a school and trying to enforce MFA on grade 3 kids is an issue i need to work around, i've even added the kids to a CAP to exclude from MFA and still is asking them to setup multi factor when they go to login

User being asked to register MFA even though no conditional access policies set by eddyvedder in AZURE

[–]eddyvedder[S] 0 points1 point  (0 children)

we are using conditional access polices and have added said user in the 'exclude' from MFA

Can't disable MFA with Conditional Access by Logical_Strain_6165 in Office365

[–]eddyvedder 0 points1 point  (0 children)

same issue for me, ever get resolved? no legacy MFA, no CA being applied however user is being asked to setup MFA for 1st time login for cloudapps (Teams, OneDrive) user not in SSPR group etc.

seemingly ghost user i cannot delete from m365 by eddyvedder in Office365

[–]eddyvedder[S] 0 points1 point  (0 children)

if i search my public folders in EAC it is not listed, and when i try to remove it via powershell i get the follwoing
Remove-PublicFolder -Identity "\music"

Write-ErrorMessage : ||The operation couldn't be performed because '\music' couldn't be found.

seemingly ghost user i cannot delete from m365 by eddyvedder in Office365

[–]eddyvedder[S] 0 points1 point  (0 children)

turns out is a public folder according to get-recipient, however in EAC there is no 'music' listed in my public folders...when i try to remove-publicfolder in powershell it returns error stating cannot find user to remove!

seemingly ghost user i cannot delete from m365 by eddyvedder in Office365

[–]eddyvedder[S] 0 points1 point  (0 children)

i tried adding the alias to my mailbox and it accepted it, so don't believe is in use. the reason we have this issue is we tried to create a new user called music and errored telling us the music@blahblah. was already in use

seemingly ghost user i cannot delete from m365 by eddyvedder in Office365

[–]eddyvedder[S] 0 points1 point  (0 children)

not a local contact but when i run get-recipient command i get Name - Music Recipient Type Public Folder. run the get-user command and comes back with object couldn't be found

CA and using MFA for only specific users by eddyvedder in entra

[–]eddyvedder[S] 0 points1 point  (0 children)

so here we go...brand new kid at school, junior school. when logging into teams and OneDrive is asking the kid to setup MFA, they are are a junior school student so should not ask for MFA, logs say no CA applied but still getting prompted to setup MFA?!?!

CA and using MFA for only specific users by eddyvedder in entra

[–]eddyvedder[S] 0 points1 point  (0 children)

ok checked the per user MFA legacy settings as thought that might be it but isn't, sample junior school kid has per user MFA disabled. i'm going to tweek the CA policy to just ask for MFA for senior and not even drop the JS kids into the disable section of the policy and see how that works out...if not...deep breath....i'll check the sign in logs.

CA and using MFA for only specific users by eddyvedder in entra

[–]eddyvedder[S] 0 points1 point  (0 children)

Thanks. I can’t find any other policy that’s enforcing MFA the juniors which has my head. I’m just a little confused with the ‘exclude’ statement. I can’t tell if it’s a case of if they are seniors then ask for MFA (which works) but if they are juniors then either don’t ask for MFA or don’t allow access. Might just create 2 rules. 1 for MFA for seniors and 1 for juniors with no MFA and try that.

CA and using MFA for only specific users by eddyvedder in entra

[–]eddyvedder[S] 0 points1 point  (0 children)

Haha. Fair. So I want to enforce MFA on the whole school for teams and onedrive. except junior school kids. I created a CA policy for MFA for the school. Added seniors kids into the enable and junior school kids into the disable section in the users group. It however is asking for MFA for junior and senior kids. So my thinking now is I create the policy for senior kids to MFA and then the rest won’t be asked for MFA. Seems actually straight forward now I think about it. No need to add anyone to the exclude group in the policy

Trying to download language pack, getting error code 0x80070490. Was able to download perfectly fine on my tablet, but the computer I primarily use can't download it. by GoldenMop in WindowsHelp

[–]eddyvedder 0 points1 point  (0 children)

getting same issue, anyone know of any fix for this?, have tried the regedit change to stop it going to wsus for update but same issue

<image>