Hi @Heidi Vandezande
Thank you for posting your query on Microsoft Q&A.
I understand that you have applied a conditional access policy on all external users to use MFA. You implemented hardware tokens because you don't want to use their personal information with the verification methods.
When a new user logs in, he is prompted to use MFA since a conditional access policy is in place, which means "more information required".
Check to see if MFA is enabled for certain users using authentication methods other than the OATH Hardware token. If yes, exclude those users from the other authentication methods that take precedence over OATH Hardware tokens. and also Check to see if there was any another way where MFA is enabled for select users.
Hope this helps. Do let us know if you have any further queries.
------------
If this answers your query, do click `Accept Answer`
and `Yes`
.
Thanks,
B. Siri Chandana.