question

AmarSoni-3950 avatar image
0 Votes"
AmarSoni-3950 asked ·

MFA Auth App not giving Approve / reject prompt for UPN Suffix

Hello Guys,

Having a weird issue. We've implemented Azure MFA via NPS Extension on an on premise NPS Server and have our AD synced up with Azure. We're using it for RD Gateway MFA security and testing it via multiple locations it's been working pretty good for some users.

We had our users verify MFA trigger via Microsoft Authenticator App.

We have one UPN suffix with our domain. Our domain is XYZ.com and UPN Suffix is XYZCompany.com

The problem we're having is with couple of users is having UPN suffix for email address requirement and whey they are trying to do login to RDGateway server it is not prompting for Approve or Reject on Authenticator application

This issue occurred only when we trying to access RDGateway so user with UPN like user@XYZ.com (Domian Name) is getting prompt for approve / reject on RDGateway but user like user@XYZCompany.com is not getting prompt for approve / reject.

Other then that all users are having proper approve / reject prompt for all office 365 application and logins. We have issue only with RD Gateway.

Thank you,

ASoni

azure-ad-multi-factor-authentication
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

MarileeTurscak avatar image
0 Votes"
MarileeTurscak answered ·

This can happen if the account is not being recognized during the primary authentication. Can you please share the logs from the vent viewer on the server where you have the NPS role configured? These will give us a better idea of what might be causing the issue.

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-errors

If you prefer, you can send these to me at AzCommunity@microsoft.com.

· 1 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Please let me know if you were able to get the answer you need or if I somehow may have missed your email

0 Votes 0 ·