Forum Widgets
Latest Discussions
Can't access Intune Company Portal from Android device after enabling Phishing resistant MFA
HI, Since I enabled Phishing resistant MFA in my tenant, I have been unable to access the company portal on my android phone. Login starts the auth process, but the app keeps telling me that it doesn't support pass keys. If this is the case, is the way that I can exclude the app from my CA policy to allow me to install apps that I have made available to the device? Kind Rgds Leeilmaestro7Mar 10, 2025Copper Contributor25Views0likes2CommentsDeactivating Option to change Profile Picture at myaccount.microsoft.com
As the title says. I would like to deactivate the option for users to change their profile picture at myaccount.microsoft.com. The profile picture at our company is synchronized to AD and via Entra Connect to Entra ID. Is there an option as an admin to deactivate that option without deactivating the entire portal? Kind Regards Christopher SiebertzCSIMar 09, 2025Copper Contributor184Views1like4CommentsAuthenticator App for visionOS Apple Vision Pro
Please add more options to visionOS version. I want to sign in with my personal account and synchronize my TOTP tokens and passwords into the visionOS so that I do not have to open my phone while wearing the headset (huge pain since the iphone app requires face unlock which does NOT work when wearing the headset). Also please support retina unlock in the visionOS app. Also support authenticator request approvals from inside the visionOS app.whatisinanameMar 09, 2025Copper Contributor60Views1like2CommentsUnlink a users workplace join account while device is also Entra ID joined
We have a number of users on Entra ID joined devices that were prompted to register their devices when signing into teams with another org account. My question has two parts - how can we programmatically remove the Workplace Join account and how do we avoid users from doing it again?ftroutMar 09, 2025Brass Contributor1.2KViews0likes4CommentsForce additional MFA for PIN WH4B
so got a request from one of my clients and if you think about it, its on the verge of being valid but an edge case... Lets say you implement WH4B and leverage PIN, how do you prevent someone shoulder surfing and leveraging the PIN on that device if they take it? Or restrict pin patterns? (the patterns I am looking into) I know Fido2 is the best way along with biometrics...but they were wondering if there was a way to reprompt MS Auth App for a code after login/reboot... I couldnt find anything on this but I did find forcing a mfa device revalidation via graph api Any able to accomplish this with the entra joined device?RussMeyer-EpikFeb 28, 2025Copper Contributor23Views0likes1CommentMFA Rollout Question(s)
Hi All I hope you are well. Anyway, I'm normally more active in the Intune space but I have been tasked with rolling out MFA to a lot of non technical users. One of the questions is: What if I forget my phone with the MS Authenticator app on it? I can't seem to find any documentation or clear answer to this. Any ideas? SKStuartK73Feb 24, 2025Iron Contributor44Views0likes3CommentsUser with hundreds of Interactive Sign-In log entries that are "Interrupted"
I have one user in our organization that has hundreds of Interactive Sign-in logs in EntraID that are marked as "Interrupted". I don't even know where to start with the user. Does anyone have a recommendation for isolating the cause of these logs? Recent entries are 95% related to Office Online Core SSO application.cmiarshvacFeb 21, 2025Brass Contributor287Views0likes4CommentsFederation Issues - No protocol handlers?
Hi All, It's been a number of years since I've federated a domain with Entra, i'm flipping this back in a home environment to complete some testing. Would appreciate some troubleshooting thoughts. What from memory was a quick task, I've spent waaaaay to long on this today. I've rebuilt the environment a number of times with the same outcome. Install ADFS (Enabled the sign-in page). Install WAP. Generate Let's Encrypt certificate and provide to the servers. Port Forward 443 to the WAP server. Use Entra Connect to Federate the domain (AD FS Config looks good and generated as Microsoft Office 365 Identity Platform) WAP is configured via AAD Connect (Blank but seems alright talking back to ADFS) I can hit https://adfs.domain.com/adfs/ls/idpinitiatedsignon.aspx and authenticate with UPN internally/externally. I can hit https://adfs.domain.com/FederationMetadata/2007-06/FederationMetadata.xml internally/externally. I also setup IAMShowcase to test (SAML 2.0 Test Service Provider) and published the app via the WAP, worked fine for SP and IDP initiated flows. Interestingly enough, I am chucked the following error from the ADFS redirection with M365 authentication: Error details: MSIS7065: There are no registered protocol handlers on path /adfs/ls/ to process the incoming request. This raises an error on the ADFS server ID#364, I've rebuilt a few times and havent been able to find much in troubleshooting. Would love to hear if someone else has seen something similar, i'm at a bit of a loss here. Encountered error during federation passive request. Additional Data Protocol Name: Relying Party: Exception details: Microsoft.IdentityServer.Web.IdPInitiatedSignonPageDisabledException: MSIS7012: An error occurred while processing the request. Contact your administrator for details. at Microsoft.IdentityServer.Web.Protocols.Saml.IdpInitiatedSignOnRequestSerializer.ReadMessage(WrappedHttpListenerRequest httpRequest) at Microsoft.IdentityServer.Web.Protocols.Saml.HttpSamlMessageFactory.CreateMessage(WrappedHttpListenerRequest httpRequest) at Microsoft.IdentityServer.Web.Protocols.Saml.SamlContextFactory.CreateProtocolContextFromRequest(WrappedHttpListenerRequest request, ProtocolContext& protocolContext) at Microsoft.IdentityServer.Web.Protocols.Saml.SamlProtocolHandler.CreateProtocolContext(WrappedHttpListenerRequest request) at Microsoft.IdentityServer.Web.PassiveProtocolListener.GetProtocolHandler(WrappedHttpListenerRequest request, ProtocolContext& protocolContext, PassiveProtocolHandler& protocolHandler) at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context) Get-MgFederatedDomainFederationConfiguration -Identity Domain.com ActiveSignInUri : https://adfs.domain/adfs/services/trust/2005/usernamemixed IssuerUri : http://domain/adfs/services/trust/ MetadataExchangeUri : https://adfs.domain/adfs/services/trust/mex PassiveSignInUri : https://adfs.domain/adfs/ls/ PreferredAuthenticationProtocol : wsFed SignOutUri : https://adfs.domain/adfs/ls/SolvedMiikeJan 31, 2025Brass Contributor589Views1like15CommentsProvide accounts for Microsoft Authenticator centrally
In our IT department, we manage our mobile devices with Microsoft Intune. We have a group of maintenance employees who need access to production machines on the shopfloor using mobile devices. The access to these machines are static users or OTP-based access. Now I would like to provide all maintenance employees and their mobile devices with the Microsoft Authenticator and provide all accesses for these machines as preconfigured accounts. Is this possible with Intune or another option? I don't want to make the Microsoft Authenticator app available to the maintenance staff (we've already managed that), but rather defined accounts for all Microsoft Authenticator clients.Bordon0116Jan 23, 2025Copper Contributor34Views1like1CommentAuthenticator app issue
I am trying to log into Outlook and Teams on my iphone. When I try to enter in Username & PW, I get forced to open authenticator app, which asks for the same log in details I try to enter into Teams and Outlook, then it asks me to enter an authenticator app code which I cannot access as the current window prevents it from opening. I go back and have to start the whole process again. I just seem to go around in circles and end up in the same spot. i am the admin for the account , so i am unable to reset anything.nagacvJan 19, 2025Copper Contributor229Views0likes2Comments
Resources
Tags
- Authentication326 Topics
- office 365213 Topics
- security153 Topics
- admin61 Topics
- Identity57 Topics
- multi-factor authentication48 Topics
- exchange42 Topics
- Azure AD41 Topics
- Microsoft 365 Apps36 Topics
- hybrid35 Topics