Skip to content

Conversation

juntakata
Copy link

To properly configure a federation, PreferredAuthenticationProtocol option is required. This is explained in Create internalDomainFederation as below. As the sample cmdlet is missing this parameter. I added it to the example.

image

Also, most customers want to handle MFA at their IdP. The example has -FederatedIdpMfaBehavior "rejectMfaByFederatedIdp" set that means MFA done in their IdP is blocked by Entra ID. I would like to change it to "acceptIfMfaDoneByFederatedIdp" to cover more popular user scenarios.

@juntakata juntakata requested a review from a team as a code owner August 20, 2025 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant