logo
search
MFA Security Issues

How Mandatory MFA Affects Microsoft 365 Federated Domains

Emma BrownEmma Brown Sep 27, 2026 869 views

Question details

Understand how Microsoft 365 mandatory multifactor authentication (MFA) requirements apply to users in domains federated with an external identity provider.

How Mandatory MFA Affects Microsoft 365 Federated Domains
Product
Microsoft 365 / Microsoft Entra ID
Device & OS
not provided
Scenario
Administrators need to configure external identity providers and Microsoft Entra ID to ensure MFA claims are correctly passed and mandatory authentication requirements are met.
Observed behavior
Mandatory MFA requirements enforced by Microsoft apply to federated identities, requiring correct configuration to prevent double-prompting or authentication failures while supporting Conditional Access exclusions.
Before you start

Ensure you have Global Administrator or Security Administrator access to Microsoft Entra ID and administrative access to your external identity provider before modifying authentication configurations.

Solution 1Recommended

Configure MFA Claims for Federated Domains in Entra ID

Adjust settings in both your external identity provider and Microsoft Entra ID to successfully pass and accept MFA claims, satisfying Microsoft's mandatory MFA requirements.

To prevent users from being prompted for multifactor authentication by both your external identity provider and Microsoft Entra ID, you must configure the federation settings. This ensures Entra ID recognizes the MFA claim sent by the external provider as a valid satisfaction of the MFA requirement.

1
Verify external identity provider settings

Log in to your third-party identity provider's administration console and verify that it is configured to issue an MFA claim (such as 'http://schemas.microsoft.com/claims/authnmethodsreferences') upon successful multifactor authentication.

2
Configure Entra ID federated domain settings

Access the Microsoft Entra admin center, navigate to Identity > Hybrid management > Azure AD Connect > Federated domains. Update the federated domain settings to accept the MFA claim by configuring the 'federatedIdpMfaBehavior' property to 'acceptIfMfaDoneByFederatedIdp'.

3
Review Conditional Access policies

Navigate to Microsoft Entra ID > Protection > Conditional Access. Ensure that your policies acknowledge external MFA claims and evaluate if specific Conditional Access exclusions or risk-based rules need adjustment based on the new mandatory rollout.

4
Test the authentication flow

Open a private browsing window and attempt to log in to Microsoft 365 using a test user account from the federated domain. Confirm that the external identity provider handles the MFA and Microsoft Entra ID grants access without a secondary MFA prompt.

Configure MFA Claims for Federated Domains in Entra ID
Seamless Authentication Achieved: By properly configuring the federated IdP MFA behavior, your users will experience a smooth login process while remaining fully compliant with Microsoft's mandatory MFA security requirements.
Free Microsoft Office alternative

Simplify Your Document Workflow with WPS Office

Managing complex cloud identity and MFA configurations in Microsoft 365 can be time-consuming. If you need a reliable, hassle-free desktop office suite for your daily document needs, WPS Office provides a lightweight, highly compatible alternative for creating, editing, and sharing files locally without complex cloud authentication barriers.

  1. 1. Download the installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install the software: Run the installer and follow the simple on-screen instructions to set up WPS Office on your device in minutes.
  3. 3. Open your files instantly: Launch WPS Office and directly open your existing DOCX, XLSX, or PPTX files to start working offline or online immediately.
Seamless format compatibility with Microsoft Word, Excel, and PowerPoint filesEdit documents locally without being interrupted by complex mandatory cloud MFA promptsLightweight, fast installation with low system resource requirementsAll-in-one suite featuring an advanced built-in PDF editor
microsoft office alternative - wps office

Frequently Asked Questions

Will federated users be prompted twice for MFA?

If Microsoft Entra ID is not configured to recognize the MFA claim from your external identity provider, users may face double MFA prompts. Configuring the 'federatedIdpMfaBehavior' setting allows Entra ID to trust the external MFA.

Is an MFA claim from our federated identity provider sufficient?

Yes, an MFA claim from a properly configured external identity provider is generally sufficient to satisfy Microsoft Entra ID's mandatory MFA requirements, provided the Entra ID tenant is configured to accept it.

Do Conditional Access exclusions still apply under mandatory MFA?

In many scenarios, Conditional Access exclusions or risk-based rules will remain available where permitted by Microsoft. However, you should frequently check the current Microsoft documentation for specific rollout details and exceptions.