logo
search
Conditional Access Problems

Fix Conditional Access Register Security Information Not Triggering MFA

Algirdas JasaitisAlgirdas Jasaitis Sep 30, 2026 869 views

Question details

The user needs to resolve an issue where a Microsoft Entra Conditional Access policy fails to prompt for MFA when users register new security information.

Fix Conditional Access Register Security Information Not Triggering MFA
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Users are adding authentication methods via My Sign-Ins > Security info, but the configured Conditional Access policy is not enforcing MFA or blocking access as expected.
Observed behavior
The Conditional Access policy targeting the 'Register security information' user action does not apply during the method registration flow, allowing users to bypass the intended MFA requirement.
Before you start

Ensure you have Conditional Access Administrator or Security Administrator privileges in your Microsoft Entra ID tenant to review and edit policies.

Solution 1Recommended

Review Policy Configuration and Sign-in Logs

Use the Microsoft Entra What If tool and sign-in logs to identify why the policy is not being applied to the registration flow.

A Conditional Access policy might not apply due to misconfigured exclusions, missing conditions, or being set to report-only mode. Analyzing the sign-in logs will reveal exactly which policies are evaluated and applied during the security info registration.

1
Open Conditional Access settings

Log in to the Microsoft Entra admin center, navigate to 'Protection', and select 'Conditional Access'.

2
Verify user actions

Open your specific policy, go to 'Target resources' (or Cloud apps or actions), and ensure 'User actions' is selected with the 'Register security information' checkbox enabled.

3
Check policy enforcement state

Scroll to the bottom of the policy settings and verify that 'Enable policy' is set to 'On' rather than 'Report-only' or 'Off'.

4
Analyze sign-in logs

Navigate to 'Identity' > 'Monitoring & health' > 'Sign-in logs'. Find the user's registration event, click the 'Conditional Access' tab, and check if the policy was 'Not Applied' or if another policy satisfied the MFA claim.

5
Run the What If tool

In the Conditional Access menu, click 'What If'. Select the specific user and set the user action to 'Register security information' to simulate the flow and see if your policy triggers.

Review Policy Configuration and Sign-in Logs
Authentication Strength: Ensure your grant controls and authentication strength configurations support the specific method the user is attempting to register.
Free Microsoft Office alternative

Document Your IT Security Policies with WPS Office

While troubleshooting Microsoft Entra Conditional Access requires Azure portal administration, you can seamlessly document your organization's security configurations, compliance reports, and IT guides using WPS Office. It is a powerful, free alternative to Microsoft Office.

  1. 1. Download the software: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install WPS Office: Run the installer and follow the on-screen instructions to complete the setup in minutes.
  3. 3. Create your IT documentation: Open WPS Writer to start drafting your Entra ID configuration guides and save them in standard .docx or PDF formats.
Completely free to use with a lightweight, fast installation process.Excellent compatibility with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Familiar tabbed user interface, allowing IT professionals to transition instantly.Built-in PDF editing tools for securing and distributing Conditional Access manuals.
microsoft office alternative - wps office

Frequently Asked Questions

What does the 'Register security information' action do in Conditional Access?

This user action targets the specific process when users attempt to register authentication methods for self-service password reset (SSPR) or multifactor authentication (MFA) via the My Sign-Ins portal.

Why does my Conditional Access policy show as Report-only?

Report-only mode allows administrators to evaluate the impact of a policy without enforcing it or blocking user access. To make the policy trigger MFA, you must edit the policy and change the 'Enable policy' toggle from 'Report-only' to 'On'.

How do I check which Conditional Access policies applied to a user?

You can check this by navigating to Microsoft Entra ID > Sign-in logs. Select a specific sign-in event and click the 'Conditional Access' tab to view a detailed breakdown of which policies were applied, not applied, or evaluated in report-only mode.