How Mandatory MFA Affects Microsoft 365 Federated Domains
Question details
Understand how Microsoft 365 mandatory multifactor authentication (MFA) requirements apply to users in domains federated with an external identity provider.

- Product
- Microsoft 365 / Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Administrators need to configure external identity providers and Microsoft Entra ID to ensure MFA claims are correctly passed and mandatory authentication requirements are met.
- Observed behavior
- Mandatory MFA requirements enforced by Microsoft apply to federated identities, requiring correct configuration to prevent double-prompting or authentication failures while supporting Conditional Access exclusions.
Ensure you have Global Administrator or Security Administrator access to Microsoft Entra ID and administrative access to your external identity provider before modifying authentication configurations.
Configure MFA Claims for Federated Domains in Entra ID
Adjust settings in both your external identity provider and Microsoft Entra ID to successfully pass and accept MFA claims, satisfying Microsoft's mandatory MFA requirements.
To prevent users from being prompted for multifactor authentication by both your external identity provider and Microsoft Entra ID, you must configure the federation settings. This ensures Entra ID recognizes the MFA claim sent by the external provider as a valid satisfaction of the MFA requirement.
Log in to your third-party identity provider's administration console and verify that it is configured to issue an MFA claim (such as 'http://schemas.microsoft.com/claims/authnmethodsreferences') upon successful multifactor authentication.
Access the Microsoft Entra admin center, navigate to Identity > Hybrid management > Azure AD Connect > Federated domains. Update the federated domain settings to accept the MFA claim by configuring the 'federatedIdpMfaBehavior' property to 'acceptIfMfaDoneByFederatedIdp'.
Navigate to Microsoft Entra ID > Protection > Conditional Access. Ensure that your policies acknowledge external MFA claims and evaluate if specific Conditional Access exclusions or risk-based rules need adjustment based on the new mandatory rollout.
Open a private browsing window and attempt to log in to Microsoft 365 using a test user account from the federated domain. Confirm that the external identity provider handles the MFA and Microsoft Entra ID grants access without a secondary MFA prompt.

Simplify Your Document Workflow with WPS Office
Managing complex cloud identity and MFA configurations in Microsoft 365 can be time-consuming. If you need a reliable, hassle-free desktop office suite for your daily document needs, WPS Office provides a lightweight, highly compatible alternative for creating, editing, and sharing files locally without complex cloud authentication barriers.
- 1. Download the installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install the software: Run the installer and follow the simple on-screen instructions to set up WPS Office on your device in minutes.
- 3. Open your files instantly: Launch WPS Office and directly open your existing DOCX, XLSX, or PPTX files to start working offline or online immediately.

Frequently Asked Questions
Will federated users be prompted twice for MFA?
If Microsoft Entra ID is not configured to recognize the MFA claim from your external identity provider, users may face double MFA prompts. Configuring the 'federatedIdpMfaBehavior' setting allows Entra ID to trust the external MFA.
Is an MFA claim from our federated identity provider sufficient?
Yes, an MFA claim from a properly configured external identity provider is generally sufficient to satisfy Microsoft Entra ID's mandatory MFA requirements, provided the Entra ID tenant is configured to accept it.
Do Conditional Access exclusions still apply under mandatory MFA?
In many scenarios, Conditional Access exclusions or risk-based rules will remain available where permitted by Microsoft. However, you should frequently check the current Microsoft documentation for specific rollout details and exceptions.




