Skip to main content

Cornell University

Changes to Authentication Process for Microsoft Admin Portals

This article applies to: Authentication

CIT is implementing the following features for authentication to Microsoft Admin Portals, including Azure, Entra, Intune, and M365:

New Multifactor Authentication

Microsoft now requires MFA for their admin portals. You will receive an additional prompt during login as outlined below:

  1. Open the admin portal logon page.
  2. Enter your admin username.
  3. Enter your password. A Verification Required window will display.
Verification Required window with arrow pointing to Continue button.
  1. Click Continue.
  2. Verify with Duo.

Submit a ticket to the IT Service Desk if you experience any issues with the verification process.

10-hour Session Limit

An authentication token’s lifetime is now limited to 10 hours. This means you will be prompted to re-authenticate after 10 hours from when you initially logged in. This is not an inactivity timeout – the timeout can occur even when you are actively working in a portal.

Troubleshooting

Customers have reported a number of errors when trying to log in. Identity Management is aware of these errors and is working with the vendor to diagnose the problem.

 If you receive one of the errors below, or an error that's similar, try the following options:

  • If available, click the Sign in again button. Several attempts may be necessary to succeed.
  • If no Sign in again button is available, please wait 15 minutes before attempting to log in again.
A "sign-in failed" error window.
Conditional access policy failure error message
Interaction required error.

 

Comments?

To share feedback about this page or request support, log in with your NetID

At Cornell we value your privacy. To view
our university's privacy practices, including
information use and third parties, visit University Privacy.