When i enable "Remember Multi-Factor Authentication", i get the "don't ask again for X days" prompt when i login as a "member", but not when i login as a "guest". why not?
⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@jaffadog Thank you for your feedback . We will investigate and update further.
@jaffadog I am working internally with the product team on your issue and update you as soon as hear back from the team. Thanks for your patience.
This is because that setting is only in force for users inside your directory. The guest user's directory would have to have the same setting enforced.
This is because that setting is only in force for users inside your directory. The guest user's directory would have to have the same setting enforced.
Hi @MicrosoftGuyJFlo. Whether users are subject to MFA or not is determined by CA policies in my tenant. These policies may apply to all users regardless whether they are members or guests. When guest users are subject to an MFA policy in my tenant they have to complete MFA registration in my tenant - and complete an MFA challenge proffered by my tenant. This whole experience is focused on _my_ tenant, and is completely decoupled on what the disposition of this guest account is in it's home tenant. Whether this guest account is subject to MFA or even registered with MFA in its home tenant is not actually relevant. So why would the guest account's home tenant "remember me" configuration be relevant here?
I opened a support request on this issue and understand there is a design impediment preventing use of MFA "remember me" with guest accounts. I have opened a feedback item here ( please up-vote 👍 ).
In the meantime, I recommend the docs be updated to make it clear that MFA "remember me" only applies to members and not guests.
Thanks!
Most helpful comment
please-close