logo
search
Conditional Access Problems

Recommended MFA Frequency for Healthcare Organizations in Entra ID

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

Healthcare organizations require guidance on configuring the appropriate multifactor authentication (MFA) frequency for both on-premises and external access to ensure sensitive data protection.

Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Configuring Conditional Access policies for healthcare staff accessing secure cloud and on-premises environments.
Observed behavior
Administrators need a risk-based strategy for MFA prompts rather than a rigid, one-size-fits-all frequency to balance strict security with user productivity.
Before you start

Ensure you have Conditional Access Administrator or Global Administrator privileges in your Microsoft Entra ID tenant before attempting to modify authentication policies.

Solution 1Recommended

Implement Risk-Based Conditional Access Policies

Instead of enforcing a static MFA frequency, utilize Microsoft Entra ID's risk-based signals to prompt for MFA dynamically when an actual risk is detected.

Microsoft Entra ID does not prescribe a universal MFA frequency. Over-prompting users can lead to MFA fatigue, where staff blindly approve requests, compromising security. Relying on dynamic risk assessment provides a safer approach.

1
Access Conditional Access

Log in to the Microsoft Entra admin center, expand the 'Protection' menu on the left sidebar, and click on 'Conditional Access'.

2
Define risk conditions

Create a new policy and configure the 'Conditions' section based on sign-in risk, user risk, network location, and device compliance status.

3
Set access controls

Under 'Grant', select 'Require multifactor authentication'. If a fixed timeframe is absolutely required by compliance, navigate to 'Session controls' and configure the 'Sign-in frequency' setting.

Contextual Awareness: By utilizing device status (e.g., compliant devices) and access context, administrators can drastically reduce unnecessary MFA prompts for trusted medical staff.
Free Microsoft Office alternative

Secure and Compliant Document Management with WPS Office

While configuring secure access policies in Entra ID, ensure your healthcare organization also utilizes a cost-effective, secure, and lightweight productivity suite. WPS Office provides exceptional compatibility with Microsoft Office formats while offering robust local file protection features.

  1. 1. Download WPS Office: Visit the official WPS website and download the installation package suitable for your enterprise devices.
  2. 2. Install and configure: Follow the lightweight installation wizard to deploy the suite across your healthcare organization.
  3. 3. Create and encrypt documents: Start creating and editing your Microsoft-compatible files, utilizing built-in encryption features for sensitive information.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation with fast loading times, ideal for medical staff on shared workstations.Supports enterprise-grade document encryption and restricted access settings to protect patient data.Highly cost-effective alternative for healthcare organizations looking to optimize their IT software budgets.
microsoft office alternative - wps office

Frequently Asked Questions

Why doesn't Microsoft recommend a fixed MFA frequency for all organizations?

Microsoft Entra ID shifts away from fixed intervals because frequent, static prompts can lead to MFA fatigue, causing users to accidentally approve fraudulent requests. Risk-based Conditional Access evaluates each login dynamically, offering better security and a smoother user experience.

What is considered a phishing-resistant MFA method?

Phishing-resistant MFA methods rely on cryptographic verification rather than shared secrets (like SMS codes or push notifications). Examples highly recommended for healthcare include FIDO2 security keys, Windows Hello for Business, and certificate-based authentication.

How do device status and compliance affect MFA frequency?

If a user accesses healthcare data from an Intune-compliant, corporate-managed device, Conditional Access policies can be set to reduce or bypass the frequency of MFA prompts, reserving stricter authentication for unmanaged or personal devices.

Can we set different MFA frequencies for on-premises versus external access?

Yes. Conditional Access allows administrators to define network locations. You can assign stricter sign-in frequency controls and require immediate MFA when users are accessing resources from external, untrusted networks, while relaxing policies on trusted internal networks.