Discrepancy in Sign in frequency behavior for many users.

Sundram Sontirkey 97 Reputation points
2024-07-09T09:04:03.2533333+00:00

Hi,

I am working on a Entra environment. Team has created two CA policy. Basically, it has sign frequency setup for 18 hours. It includes hybrids joined devices only.

Technically all the users included in the group should be getting sign-in prompt after 18 hours.

However, we can see only few users are getting those prompts not the others. We need to identify why there is such discrepancy and fix this. Additionally, we have SSO setup working perfectly.

Please let me know what else can be checked to identify the issue and fix.

Thanks in advance for you response.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,192 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Raja Pothuraju 4,505 Reputation points Microsoft Vendor
    2024-07-10T10:25:40.89+00:00

    Hello @Sundram Sontirkey,

    Thank you for posting your query on Microsoft Q&A.

    Based on your description, your team has created two Conditional Access policies and set the sign-in frequency to 18 hours, which applies only to Microsoft Entra hybrid joined devices. You've observed that re-authentication occurs for some users after 18 hours, while for others it does not. For testing you can have one CA policy rather than having two policies enabled for SIF.

    To investigate this behavior, I recommend referring to the document that provides examples of sign-in frequency scenarios. The users who are not re-authenticating may fall into one of the scenarios described there.

    https://video2.skills-academy.com/en-us/entra/identity/conditional-access/concept-session-lifetime#user-sign-in-frequency

    A diagram showing how Sign in frequency and MFA work together.

    Please review the flowchart provided in the document to determine why these users did not trigger re-authentication based on the current time minus the authentication instant time. You can verify this by checking the Entra sign-in logs for the specific user.

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    Please Accept the answer if the information helped you. This will help us and others in the community as well.

    Thanks,
    Raja Pothuraju.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.