
MattE.19965 (Customer) asked a question.
I have a user that has an admin account that we would like to get an MFA push every login. We have policies in place for on network AD SSO that login without a 2fa if the computer passes conditional access policies (On Net, and Azure ad joined)

Hi Matt Evans,
To ensure have a MFA push every login, you need to configure the Sign On policy accordingly.
You can achieve this by creating a new sign on policy for the admin user, by adding the user to the newly created group or by directly adding the group, if it already exists.
Also please note, this policy needs to be given the Priority 1 for it to have the impact on the admin user.
For further configuration details, refer to the below snap: