Enabling Reauthentication with MFA during Intune enrollment
The default configuration for user sign-in frequency in Azure Active Directory is a rolling window of 90 days. But there are scenarios where organizations may require a fresh authentication every time a user performs specific actions. Based on customer feedback, Microsoft have introduced Sign-in frequency option Every time in addition to existing periodic frequency of hours and days. With this new capability, organization can now re-verify identity, device, and any other Conditional Access conditions for high-risk scenarios like - User risk Session risk Microsoft Intune device enrollment I wanted to test this new feature for Intune enrollment and shall be covering my experience in this blog. Let's get started. 1. Head over to Microsoft Endpoint Manager admin center . 2. Select Endpoint Security > Conditional Access > New Policy. 3. Provide a Name. 4. Under Users and groups, choose Specific users included and select the users or groups that you want to targe...