How to configure MFA (in Azure B2C) for some App with enforcement once per day (not each time when log in)?

Viewed 271

Now I have configured B2C tenant with Enterprise app with MFA with "User flow", confirmation with email.

Everything is ok, but we need to use this Mfa just once per day, so when users will log in in the morning they have to use their login, password, and email to get a verification code just for the first time, and the rest of the day when they log out and log in again they should use just login (username) and pass.

So, how to configure MFA for this?

I saw "Sign in frequency" in conditional access settings, but the documentation wasn't much helpful. Any advice will be helpful, thank you.

1 Answers

we can manage authentication sessions with azure ad conditional access by configuring below options.

Configure sign-in frequency Sign-in frequency defines the time period before a user is asked to sign in again when attempting to access a resource. You can set the value from 1 hour to 365 days.

Configure persistent browser session This setting allows users to remain signed in after closing and reopening their browser window. We support two new settings: always persist or never persist. In both cases, you’ll make the decision on behalf of your users and they won’t see a “Stay signed in?” prompt.

You can find more information here as well as steps to configure sign-in frequency. https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-session-lifetime#user-sign-in-frequency-and-multi-factor-authentication

Related