Third Party IDP and MFA

slvandewalle_gb
New Contributor III

Hey all,

We setup Microsoft as our IDP on Chromebooks at the end of last year. One thing that we didn't expect was that a user that has an MFA requirement in Microsoft seems to have to MFA at every login to a Chromebook. This makes sense in a way because if the MFA token is stored in the profile of the Chromebook it is encrypted until there is a successful login. Meaning that the token will remain encrypted until after you have signed in and gone though MFA.

Is anyone else experiencing MFA at each login to the Chromebook?

Has anyone found a way around that?

Thanks!

1 ACCEPTED SOLUTION

kaned
Contributor II

We set up IDP with a different vendor (Class link).  We also have the same issue.  

Yes, this is the expected behaviour.  I believe the only way to get around that (years ago) was to change the login screen from "Do not remember previous users" to "Remember previous users" or something like that.

See if this setting helps:  DeviceShowUserNamesOnSignin

I believe this was the answer years ago.

 

View solution in original post

1 REPLY 1

kaned
Contributor II

We set up IDP with a different vendor (Class link).  We also have the same issue.  

Yes, this is the expected behaviour.  I believe the only way to get around that (years ago) was to change the login screen from "Do not remember previous users" to "Remember previous users" or something like that.

See if this setting helps:  DeviceShowUserNamesOnSignin

I believe this was the answer years ago.