MFA automatically enabled on Azure AD B2C tenant

Filip Goris 21 Reputation points
2020-01-07T17:47:48.14+00:00

I recently added an Azure AD B2C tenant to an existing subscription.

Whenever I want to manage that tenant on portal.azure.com, I have to verify my account:

MFA

After clicking Next I can only select Mobile app from the dropdown to verify my account. There is no option to verify by phone.

Since this tenant is new, I first have to register it in Microsoft Authenticator by selecting Set up:

Additional Security Verification

This brings up an error message without Correlation ID or timestamp:

Mobile app configuration unavailable

There are no Conditional Access policies. In fact, I cannot dis-/enable MFA since this tenant does not have Azure AD Premium. Nor does the Azure AD tenant holding the subscription from which this AD B2C tenant was created.

Conditional Access Policies

MFA is only required when trying to manage the AD B2C tenant through portal.azure.com, not on other applications

Questions:

  • How can I disable MFA for this AD B2C tenant? And why was it enabled in the first place?
  • If MFA cannot be disabled, how can I register my device or phone number?

Thx,

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,633 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,383 questions
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,301 Reputation points
    2020-03-06T05:37:54.597+00:00

    @Filip Goris Looks like this is happening because of Security defaults in your tenant. To check if Security defaults are enabled, navigate to:

    Azure Portal > Azure AD > Properties > Click on manage security defaults link

    Note: For tenants created on or after October 22nd, 2019, it’s possible you are experiencing the new secure-by-default behavior and already have security defaults enabled in your tenant.

    Refer to https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/concept-fundamentals-security-defaults for more details.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept as answer" wherever the information provided helps you to help others in the community.


1 additional answer

Sort by: Most helpful
  1. Frank Hu MSFT 81 Reputation points
    2020-01-07T20:26:03.63+00:00

    Hey @Filip Goris this doesn't sound right and it looks like there must be some sort of issue going on here.

    If you're still having an issue here, please email AzCommunity[at]microsoft[dot]com and I can enable a one time free support ticket. Please provide your Azure Subscription GUID and a reference to this thread. And hopefully we can get you on the right path again soon. 

    Please see : https://blogs.msdn.microsoft.com/mschray/2016/03/18/getting-your-azure-subscription-guid-new-portal/

    On how to get a subscription GUID.

    In addition to that once you are able to resolve your issue with the support engineer, please post your response on this thread so that future readers will be able to benefit from your solution. 

    0 comments No comments