Excessive 2FA prompts , certain Windows 10 Dell laptops

Mario Marrese 0 Reputation points
2024-01-19T11:13:50.7233333+00:00

Hello, We have a group of devices that are experiencing excessive 2FA prompts , i.e. When logging into their laptop in the morning, a windows 10 notification appears suggesting there is a problem with their “work and school account”. Edge and OneDrive will not be logged in , however Outlook would normally be online. Once they click on the “FIX NOW” prompt, the laptop doesn’t prompt 2FA again for that day. However they will likely experience the same problem with their “work and school account” the following day. The same users will not experience this behaviour on their mobile device, where Microsoft authentication caching and SSO works smoothly.

It's quite frustrating for them to keep authenticating on their laptop each morning. Not all devices in our 100 device estate is experiencing this issue – this is regardless of working from home or in the issue. There is no clear pattern to what could be triggering, apart of the errors in the AAD logs (see below) User's image

We use the same AV products across our device estate and do not believe this is causing the issue This happens pretty much every day. We have exhausted all troubleshooting. E.g...

  • Cleared TPM via Windows 10
  • Repaired Windows DISM /Online /Cleanup-Image /RestoreHealt
  • Reinstalled ADD broker plugin
  • Cleared cached Windows logins
  • Disconnected from AD and rejoined onto AD
  • Reinstalled Office -Disabled Bitlocker
  • All devices have the latest Windows 10 updates and feature updates. plus a whole heap of stuff. The conditional access policy is set to refresh token every 180 days. Raised this with MS support, who have been completely hopeless. Here are sign in attempts on Azure for this particular user User's image

Can anyone advise what could be causing this problem and the fix, as its been going on for a while, and about 50% of our device estate is suffering.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
371 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,669 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,367 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Akshay-MSFT 17,641 Reputation points Microsoft Employee
    2024-01-22T13:13:05.7+00:00

    @Mario Marrese

    Based upon above error it seems like user authentication is successful but device authentication is not happening. Kindly try the following steps and let me know the status:

    Thanks

    Akshay Kaushik