ADFS MFA failing for some users

Phil Ready 1 Reputation point
2020-07-29T07:27:31.073+00:00

We are running 2012R2 ADFS with Azure MFA. The MFA handover seems to be failing for some users. They can successfully logon to Microsoft 365 Apps using MFA, but when trying to logon to On-premises or other Cloud Apps (RDWEB, Zoom, Oracle) they get prompted for MFA but their phone number is not already there and when they add their phone number, they receive the text code but then Federation Services gives a fail and there is nowhere to enter the text code.

This is only happening for some users. Other users don't have this issue.

I have had some success with choosing other method and changing the MFA method to phone call and entering the same cell phone number.

I tried removing their phone number from Authentication methods in portal.azure.com and selected 'Require re-register MFA'. This helped some users, but I still have the problem with others. Also, there must be somewhere else where the phone numbers for MFA when using ADFS are stored, as after removing phone number and requiring re-register MFA in Azure, I have seen users still offered the text to xxx xxx 1234 when logging in. Just with ADFS Apps/Services though, M365 Apps ask them to setup a method.
Does ADFS store MFA info? Where? How can I diagnose this more?
Regards
Phil

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,222 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,528 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. 2020-07-29T21:01:10.83+00:00

    Please Create an Azure support request to better address the issue.

    0 comments No comments