Quick troubleshooting view
The user is constantly re-demanded to authenticate or validate MFA.
- Conditional Access
- tokens/cookies
- MFA method failing
- Test Private Browser
- Read Sign-in-news
- Check MFA methods
- Correcting policy CA
- Revoking sessions if necessary
- Reregister MFA method
Contextual technician plan
Clear local cache.
“Test Private Browser” should produce an observation that clearly confirms or rules out “Conditional Access”.
If the observation is normal, lower “Conditional Access” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Conditional Access” first. Related action: Correcting policy CA.
Identify applied policy.
“Read Sign-in-news” should produce an observation that clearly confirms or rules out “tokens/cookies”.
If the observation is normal, lower “tokens/cookies” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “tokens/cookies” first. Related action: Revoking sessions if necessary.
Control record.
“Check MFA methods” should produce an observation that clearly confirms or rules out “MFA method failing”.
If the observation is normal, lower “MFA method failing” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “MFA method failing” first. Related action: Reregister MFA method.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Climb before changing a global Conditional Access rule.
The user is constantly re-demanded to authenticate or validate MFA.
Causes probables
- Conditional Access
- tokens/cookies
- MFA method failing
Diagnostic étape par étape
- 1
Test Private Browser
Clear local cache.
- 2
Read Sign-in-news
Identify applied policy.
- 3
Check MFA methods
Control record.
Solutions possibles
- Correcting policy CA
- Revoking sessions if necessary
- Reregister MFA method
Climb before changing a global Conditional Access rule.