Scenario
A user is excluded from a prompt path, but existing sessions or cached tokens still behave as if MFA is required.
Recommended Resolution Path
- Confirm the live policy evaluation in sign-in logs after the group change.
- Have the user fully sign out and restart the session rather than relying on partial token refresh.
- Check whether another Conditional Access policy still applies.
- Document the expected propagation and session cache behavior for support staff.
Technician Notes
Confirm the result, document the root cause, and record any preventative action worth standardizing.
- Log in to post comments
Subjects