How to Fix Repeated MFA Prompts When Opening Dynamics ERM
Question details
Users are continuously prompted for multifactor authentication (MFA) every time they open Dynamics ERM, ignoring established sign-in frequency policies and single sign-on settings.

- Product
- Dynamics ERM / Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Accessing Dynamics ERM in an environment configured with a 30-day Conditional Access sign-in frequency, Windows Hello for Business, and trusted network locations.
- Observed behavior
- The system bypasses the 30-day token lifetime and trusted location policies, forcing the user to complete MFA interactively on every launch, often associated with sign-in error 1400001.
Ensure you have administrative access to the Microsoft Entra ID portal to review sign-in logs and verify the exact error code (such as 1400001) triggered during the authentication attempts.
Review Sign-in Logs and Escalate to Microsoft Entra ID Support
Because this issue involves complex interactions between Dynamics ERM, Microsoft Entra ID, and specific sign-in errors (like 1400001), the most effective solution is to collect log data and escalate to the dedicated Microsoft Entra ID team.
Sign-in error 1400001 and repetitive MFA prompts usually indicate that the application is failing to receive or process the Primary Refresh Token (PRT) correctly. The Microsoft Entra ID Q&A team has the specialized tools required to trace these backend authentication failures.
Log in to the Azure Portal as an administrator. Navigate to 'Microsoft Entra ID' and select 'Sign-in logs' from the Monitoring section.
Filter the logs by the affected user and the Dynamics ERM application. Look for authentication failures, specifically noting error code 1400001 or Conditional Access policy interruptions.
Click on the failed sign-in event and copy the Correlation ID, Timestamp, and the specific Conditional Access policies applied during the session.
Navigate to the official Microsoft Entra ID Q&A forum or open a Microsoft Support ticket. Provide the Correlation ID, error code, and your current CA configuration (30-day frequency, Windows Hello, Trusted Locations) for advanced investigation.

Try WPS Office for a Hassle-Free Document Experience
While resolving enterprise authentication loops in Dynamics ERM and Microsoft Entra ID requires specialized IT support, your daily document tasks shouldn't be complicated. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office, completely free from complex enterprise sign-in hurdles.
- 1. Visit the WPS Office Website: Go to the official WPS Office website to download the latest version.
- 2. Install the Suite: Run the lightweight installer and follow the on-screen prompts to set up the software on your device.
- 3. Start Working Instantly: Open Writer, Spreadsheets, or Presentation and start editing your documents immediately without complex login requirements.

Frequently Asked Questions
Why does my 30-day Conditional Access frequency not work for Dynamics ERM?
Dynamics ERM may not properly inherit the Primary Refresh Token (PRT) from the device, or the session might be flagged by Continuous Access Evaluation (CAE), which can override the 30-day setting and demand immediate re-authentication.
What does sign-in error 1400001 mean in Microsoft Entra ID?
Error 1400001 generally indicates an issue where the application is unable to process or validate the MFA claim required by the token, forcing the system to prompt the user for interactive authentication again.
Does Windows Hello for Business satisfy MFA requirements for Conditional Access?
Yes, Windows Hello for Business provides strong, multi-factor authentication and typically satisfies Conditional Access MFA claims. However, specific app integration bugs or token anomalies can sometimes prevent the claim from being passed successfully to apps like Dynamics ERM.




