<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007L3lG3CAJOkta Classic EngineMulti-Factor AuthenticationAnswered2026-04-01T09:00:20.000Z2021-12-11T02:40:46.000Z2021-12-11T14:50:04.000Z

9v3r9 (9v3r9) asked a question.

Outlook desktop client MFA

For some reason MFA isn't being prompted in accordance to the Okta app sign in policy for Outlook desktop only. We have modern auth enabled on our tenant but it seems like it only prompts MFA for the initial setup and never after. We would like for the MFA prompt to come up after 8 hour sessions for those off the network.

For those who have Okta and uses Outlook desktop client, how does it work for you guys?


  • k5fuw (k5fuw)

    This issue isn't on the Okta side, it's Microsoft, and you'll see the same behavior in the Outlook web client. Users will only get an MFA prompt when the service provider (Microsoft) requests authentication and redirects the user to Okta. Microsoft is caching that first login on the user's machine, using that [cookie?] on subsequent logins, never redirecting the client to Okta, therefore no MFA prompt from Okta. I've experienced this behavior for all Azure/O365 services - Exchange, sharepoint, OneDrive, Azure console, etc. Lately, it seems to only redirect to Okta for authentication after I change my password in Active Directory.

     

    I recently saw someone on reddit mention that this behavior could be modified with a conditional access policy in Azure to shorten the period between authentications, but I haven't had time to research or test that claim. If anyone else has, I'd love to hear about it.

    Expand Post
This question is closed.
Loading
Outlook desktop client MFA