Entra External ID: MFA works in Azure Portal or any other site or in Azure ad B2C but not when signing in via External ID / CIAM user flow

Naman Gupta 0 Reputation points
2026-08-20T14:04:38.7266667+00:00

Hi,

We have users who get MFA when signing into the Azure Portal, but no MFA prompt when the same users sign in through our Entra External ID (CIAM) user flow.

Observed behavior

  • Azure Portal sign-in: MFA is triggered (Microsoft policies and/or SpendMend Conditional Access).
  • Same user → our External ID app / user flow (*.ciamlogin.com): User completes email + password (home-tenant password for guests) and is allowed in without another MFA challenge.

Our understanding so far:

  • Azure Portal is protected by Microsoft’s own policies and/or SpendMend Conditional Access, so MFA is required there.
  • The External ID user flow is a different auth path. If the External ID tenant does not require MFA and trusts MFA from the home tenant, the user may be allowed in without seeing another MFA prompt.

What we want

Confirm whether this is expected, and how to enforce MFA on the External ID application / user flow for:

  1. Local / customer accounts in the External ID tenant
  2. B2B guests from another Entra tenant (e.g. SpendMend / Nagarro)

Questions for Microsoft

  1. Is it expected that MFA satisfied for Azure Portal does not automatically apply as an MFA challenge on an External ID CIAM user flow?
  2. For External ID, should MFA be enforced via:
    • User flow authentication methods / MFA settings?
      • Conditional Access in the External ID tenant on our app?
        • Both?
        1. How do Cross-tenant access settings (MFA trust) affect this?
          • If MFA trust is enabled with the home tenant, can that suppress MFA on our External ID app?
  3. In Sign-in logs → Authentication details, which values should we expect when MFA is / isn’t required?
    • MFA not required
    • MFA satisfied by claim from external tenant
    • MFA challenged by resource tenant
  4. Please confirm recommended MFA setup specifically for an External ID (CIAM) customer tenant (not workforce-only B2B), for both local users and guests.Hi, We have users who get MFA when signing into the Azure Portal, but no MFA prompt when the same users sign in through our Entra External ID (CIAM) user flow.

    Observed behavior

    • Azure Portal sign-in: MFA is triggered (Microsoft policies and/or SpendMend Conditional Access).
      • Same user → our External ID app / user flow (*.ciamlogin.com): User completes email + password (home-tenant password for guests) and is allowed in without another MFA challenge.
    Our understanding so far:
    • Azure Portal is protected by Microsoft’s own policies and/or SpendMend Conditional Access, so MFA is required there.
      • The External ID user flow is a different auth path. If the External ID tenant does not require MFA and trusts MFA from the home tenant, the user may be allowed in without seeing another MFA prompt.

    What we want

    Confirm whether this is expected, and how to enforce MFA on the External ID application / user flow for:
    1. Local / customer accounts in the External ID tenant
      1. B2B guests from another Entra tenant (e.g. SpendMend / Nagarro)

    Questions for Microsoft

    1. Is it expected that MFA satisfied for Azure Portal does not automatically apply as an MFA challenge on an External ID CIAM user flow?
    2. For External ID, should MFA be enforced via:
      • User flow authentication methods / MFA settings?
        - Conditional Access in the **External ID tenant** on our app?
        
              - Both?
        
              1. How do **Cross-tenant access settings** (MFA trust) affect this?
        
                    - If MFA trust is enabled with the home tenant, can that suppress MFA on our External ID app?
        
                    1. In **Sign-in logs → Authentication details**, which values should we expect when MFA is / isn’t required?
        
                          - `MFA not required`
        
                                - `MFA satisfied by claim from external tenant`
        
                                      - `MFA challenged by resource tenant`
        
    3. Please confirm recommended MFA setup specifically for an External ID (CIAM) customer tenant (not workforce-only B2B), for both local users and guests.
Microsoft Security | Microsoft Entra | Other

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.