Fix Conditional Access Register Security Information Not Triggering MFA
Question details
The user needs to resolve an issue where a Microsoft Entra Conditional Access policy fails to prompt for MFA when users register new security information.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Users are adding authentication methods via My Sign-Ins > Security info, but the configured Conditional Access policy is not enforcing MFA or blocking access as expected.
- Observed behavior
- The Conditional Access policy targeting the 'Register security information' user action does not apply during the method registration flow, allowing users to bypass the intended MFA requirement.
Ensure you have Conditional Access Administrator or Security Administrator privileges in your Microsoft Entra ID tenant to review and edit policies.
Review Policy Configuration and Sign-in Logs
Use the Microsoft Entra What If tool and sign-in logs to identify why the policy is not being applied to the registration flow.
A Conditional Access policy might not apply due to misconfigured exclusions, missing conditions, or being set to report-only mode. Analyzing the sign-in logs will reveal exactly which policies are evaluated and applied during the security info registration.
Log in to the Microsoft Entra admin center, navigate to 'Protection', and select 'Conditional Access'.
Open your specific policy, go to 'Target resources' (or Cloud apps or actions), and ensure 'User actions' is selected with the 'Register security information' checkbox enabled.
Scroll to the bottom of the policy settings and verify that 'Enable policy' is set to 'On' rather than 'Report-only' or 'Off'.
Navigate to 'Identity' > 'Monitoring & health' > 'Sign-in logs'. Find the user's registration event, click the 'Conditional Access' tab, and check if the policy was 'Not Applied' or if another policy satisfied the MFA claim.
In the Conditional Access menu, click 'What If'. Select the specific user and set the user action to 'Register security information' to simulate the flow and see if your policy triggers.

Open an Azure Support Request
If the policy is correctly configured but still fails to trigger, the issue may require tenant-level diagnostics from Microsoft Support.
Document Your IT Security Policies with WPS Office
While troubleshooting Microsoft Entra Conditional Access requires Azure portal administration, you can seamlessly document your organization's security configurations, compliance reports, and IT guides using WPS Office. It is a powerful, free alternative to Microsoft Office.
- 1. Download the software: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the installer and follow the on-screen instructions to complete the setup in minutes.
- 3. Create your IT documentation: Open WPS Writer to start drafting your Entra ID configuration guides and save them in standard .docx or PDF formats.

Frequently Asked Questions
What does the 'Register security information' action do in Conditional Access?
This user action targets the specific process when users attempt to register authentication methods for self-service password reset (SSPR) or multifactor authentication (MFA) via the My Sign-Ins portal.
Why does my Conditional Access policy show as Report-only?
Report-only mode allows administrators to evaluate the impact of a policy without enforcing it or blocking user access. To make the policy trigger MFA, you must edit the policy and change the 'Enable policy' toggle from 'Report-only' to 'On'.
How do I check which Conditional Access policies applied to a user?
You can check this by navigating to Microsoft Entra ID > Sign-in logs. Select a specific sign-in event and click the 'Conditional Access' tab to view a detailed breakdown of which policies were applied, not applied, or evaluated in report-only mode.




