
hxfmn (hxfmn) asked a question.
Microsoft retired refresh and session token configuration on 1/30/2021.
One way to control the frequency of MFA to Office 365 is to use Azure conditional access policy but only if you have Azure AD Premium P1 license.
For those who do not have Azure AD premium license how are you dealing with MFA frequency when users access Office365?
Is your company good with requiring MFA during password change on Rich clients and mobile app?
Did you develop a script to revoke user's session?
Looking for elegant solution to force MFA every XX days.

Hi John Le ,
To force MFA for every XX days you can set a rule in the authentication policy (referred to as application policy )
For that navigate to Security > Authentication Policies in the okta admin console > Add Policy > Add Rule