Hello @jamiecw,
Thank you for posting your query on Microsoft Q&A.
From your description, it seems that your organization’s users are experiencing MFA prompt every time when accessing Dynamics ERM application.
Given the policy details you shared, I see that you have set the sign-in frequency to 30 days in your conditional access policy. Unexpected MFA prompts can occur when the "Sign-in Frequency" and "Remember MFA on trusted devices" settings are enabled in your tenant. For more information, please refer to the document on Configuring authentication session controls
Since MFA prompts are not expected behavior, please check whether the "Remember MFA on trusted devices" setting is enabled. You can verify this by navigating to Microsoft Entra ID >> Users >> Per-User MFA >> Service Settings, or by logging into this page: https://account.activedirectory.windowsazure.com/UserManagement/MfaSettings.aspx
If "Remember MFA on trusted devices" is enabled, try disabling it and observe if the issue persists. If that didn't resolve your issue, please let me know.
I hope this information is helpful. Please feel free to reach out if you have any further questions.
If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.
Thanks,
Raja Pothuraju.