Skip to main content
Version: 2.1.1-preview

MT.1061 - Device registration MFA control conflicts with Conditional Access policies

Overview​

When MFA is required during device registration in Conditional Access policies, it must be disabled in the Entra ID Device settings.

When both are enabled, the conditional access policy with the "Register device" user action will not work as expected.

Remediation action:​

When a Conditional Access policy is configured with the Register or join devices user action you must disable tenant-wide multifactor requirement for device registration. Otherwise, Conditional Access policies with this user action are not properly enforced.

  1. Open Entra - Device Settings.
  2. Set Require Multifactor Authentication to register or join devices with Microsoft Entra to No.

Test Metadata​

FieldValue
Test IDMT.1061
SeverityMedium
SuiteMaester
CategoryCA
PowerShell testTest-MtDeviceRegistrationMfaConflict
TagsCA, Maester, MT.1061

Source​

  • Pester test: tests/Maester/Entra/Test-ConditionalAccessBaseline.Tests.ps1
  • PowerShell source: powershell/public/maester/entra/Test-MtDeviceRegistrationMfaConflict.ps1