question

DaniloZappa-8300 avatar image
0 Votes"
DaniloZappa-8300 asked JarvisSun-MSFT answered

AUTOPILOT auth problem MFA 3rd part (no microsoft MFA)

Hi all,
i'm implementing Microsoft Intune and Autopilot in a tenant configured with MFA not Microsoft (Wathguard Authpoint).
I'm receiving error during login processo after first step of OOBE process.
Anyone have any ideas?

When access on portal.office.com or Modern auth App, login process function correctly but redirect login to new web pages.... on autopilot trocedure receive only an error.

Thk
Danilo

mem-intune-generalmem-autopilot
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

RahulJindal-2267 avatar image
0 Votes"
RahulJindal-2267 answered

What is the error? Have you tried disabling MFA for the enrolling user to rule out other possible issues and test for rest of the provisioning process in general?

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JarvisSun-MSFT avatar image
0 Votes"
JarvisSun-MSFT answered

@DaniloZappa-8300 Thanks for posting in our Q&A forum.
To clarify this issue, we appreciate your help to check where did you enforce the MFA. Did you enable the MFA in users in Azure AD portal or enable the MFA in the conditional access?

If you enable the MFA in users in Azure AD portal, it is suggested to try to disable it temporarily.
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings#enable-and-disable-verification-methods

And if you enable the MFA in the conditional access, it is recommended to try to exclude the Microsoft Intune Enrollment and Microsoft Intune cloud apps from the MFA conditional access policy. Also, it is needed to set "Devices to be Azure AD joined or Azure AD registered require Multi-Factor Authentication" to "No" in Azure AD portal. These settings will bypass the MFA.
https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa#create-a-conditional-access-policy



If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.