Search code examples
azurevpnopenvpn

Azure VPN login happens with out MFA


I have configured Virtual network gateway with Azure AD authentication OpenVPN SSL tunnel. While connecting via AzureVPN application using my office mail ID i'm not asked for MFA even though it is enforced by Administrator to ask MFA when ever a user logs in, plus i'm not even prompted for my password also. Why is this happening is it by design like this?


Solution

  • So If a User(AD Member) login from Azure AD registered, Azure AD joined, Hybrid Azure AD joined device they'll not be prompted for MFA since MFA token is already claimed(they'll be asked if token not claimed) if MFA is still needed then conditional access needs to be applied.

    enter image description here

    or Click on use different account so that new token is needed to be claimed and MFA is prompted.

    Security reader role should be enough to access almost all the part of the this application.