Office 365 Multi-Factor Authentication
22/04/2016

How often will you be prompted for MFA in Outlook for Office 365?




When using Multi-factor authentication in Office 365 something that is good to understand is how often you can expect to be prompted to enter the second factor.


Microsoft Office 365 session timeouts article below explains how this works in the Azure Active Directory with modern authentication section: Session timeouts for Microsoft Office 365



When you successfully authenticate you will receive a access token and a refresh token to be able access Office 365 services . The access token is only valid for an hour and then the refresh token is used to obtain a new access token if the initial authentication is still valid.



The Refresh token is valid for 14 days but if you are continuously using your mailbox during this period it can last up to 90 days.



So it could be you are not asked for Multi-factor authentication again for up to 90 days in Outlook.



Things that could force you to re-authenticate:



  • If you sign in and out again in Office clients
  • Don't login for 14 days on that device
  • Change your password
  • Administrators can apply conditional policies to restrict the resource the user is trying to access
  • Swap between Office 365 accounts


More information on how to enabled modern authentication in Office 365 can be found below:


How modern authentication works for Office 2013 and Office 2016 client apps

Cobweb MD Michael Frisby looks ahead to ...
17/12/2018

Cobweb MD Michael Frisby looks ahead to ...

17/12/2018
the trends in developments in cloud and advances in technology likely to continue in 2019 and new topics to lo...
Papa John’s UK moves to Microsoft Office...
12/12/2018

Papa John’s UK moves to Microsoft Office...

12/12/2018
A Cobweb Customer for five years, Papa John's UK operation has moved from Hosted Exchange to Office 365.
6 steps to help getting started with Mic...
30/11/2018

6 steps to help getting started with Mic...

30/11/2018
Azure is Microsoft’s set of cloud services, to enable businesses to “build, manage and deploy applications on ...