External Authentication Method

Marcos Correa 10 Reputation points
2025-02-12T16:59:27.5266667+00:00

We currently have Cisco DUO as an External authentication method for testing. I have followed the steps from Cisco DUO and added the application needed and authorized the admin approval for the app to communicate.

I have successfully set up a new testing policy that does require MFA, and enabled 'RequireMFADUO'

When I attempt to access office.com, I do not receive the prompt to choose the external authentication method(DUO). However if I were to open the web browser in private mode, I do receive the Cisco Duo.

I have tried excluding myself from Microsoft Authenticator, and all other authentication, under Authentication Methods on Entra ID. I then made sure the Microsoft enrollment campaign was disabled and it appears to be disabled. I do not want to fully disable Microsoft authenticator as there are a few users who do use the app.

Overall question: Why am I not able to receive the external authentication method as an MFA option when I attempt to access office.com?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,742 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,255 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Goutam Pratti 1,670 Reputation points Microsoft Vendor
    2025-02-14T10:05:35.49+00:00

    Hello @Marcos Correa ,

    Thank you for reaching out Microsoft Q&A.

    I Understand you configured Cisco DUO as an External authentication method for testing but When you attempt to access office.com, you do not receive the prompt to choose the external authentication method(DUO). However if I were to open the web browser in private mode, I do receive the Cisco Duo.

    Your regular browser session might be retaining some state or cookies that are causing it to default to Microsoft Authenticator instead of prompting for DUO. Clearing your browser cache and cookies might resolve the issue.

    If you're still experiencing the issue after clearing your browser cache and cookies, you should revoke all MFA sessions for the affected user. This is because the previous MFA for the Microsoft authenticator may be cached in the claim, preventing the MFA prompt from appearing. Ensure that all MFA sessions are revoked and then try again.

    For additional information and known limitations follow the document: https://duo.com/docs/microsoft-eam#create-the-duo-entra-id-application

    If you have any further questions or need additional assistance, please don’t hesitate to reach out.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.