How to Disable Guest User MFA

If your practice has Multi-Factor Authentication enabled (MFA) guest users (clients) may be required to setup MFA when logging into Collaborate for the first time. If your practice would prefer not to use MFA for guest users, but retain it for internal users, refer to the guidance in this article.

Note: The following instructions are best performed an IT professional, or by someone in your practice who has advanced knowledge of the policies implemented on your Microsoft Tenant. Incorrect configuration of these settings may result in all users being locked out of your Microsoft tenancy. FYI will not take any responsibility for incorrect configuration.

Conditional Access Rules

Conditional Access rules are used to control the login flow of users within your Microsoft tenant. Your practice may have multiple rules configured, and it is important to understand how each rule interacts with the other to avoid unexpected consequences.

To identify the rule/s that are applied when guest users login:

  1. Go to https://portal.azure.com and login as the Microsoft Administrator.
  2. Select Microsoft Entra ID.
    2990_Microsoft_Entra_ID_Icon.gif
  3. From the left hand menu, scroll down to the Monitoring section and select Sign-in logs.
    2992_Monitoring_signin_logs.gif
  4. Search for the email address of the guest user account you wish to check. The details of the sign-ins for the user account will display.
    Tip: Click Add filters and select User to search for a specific user.

    2993_Add_filter_search_user_login.gif

  5. The sign-in details will display for the selected user. Click on an entry to display the details.

    2995_Display_logins_for_specific_user.gif

  6. In Activity Details: Sign-ins select Conditional Access. This will display all policies applied to the login.

    2996_Display_Activity_Details_signins.gif
  7. Once the policy has been identified, it can be adjusted.

    Important: This section covers the changing of Conditional Access policies - if you are unfamiliar with how these work, refer to your IT Professional.

  8. From the left hand menu locate the Manage section and select Security.2997_Manage_Security.gif
  9. From the Protect section select Conditional Access.
    2998_Protect_Conditional_Access.gif
  10. Select Policies and select the policy you wish to change.
    2999_Select_MFA_Policy.gif
    The properties for the policy will be displayed.

  11. Click Specified users included and then select the Exclude tab.

  12. Select the following categories to exclude Guest Users (clients) from the policy
    3000_Exclude_users.gif
  13. Click Save.
    If your practice has a single MFA policy applied for guest user accounts, this will disable the MFA prompt for external users. Internal users will still be prompted to enter MFA when logging in. If guest users are still receiving a prompt to setup MFA, return to Step 6 and look at the details of the sign-in to identify any other policies that may be applied.
Was this article helpful?
0 out of 0 found this helpful