E-mail MFA is Being Requested While it is Turned Off in the MFA Settings

Overview
When a user tries to log in to our application, the e-mail MFA flow is triggered. Our security settings have e-mail MFA turned off, so the user should not be prompted with the e-mail MFA flow. 
Cause
When Adaptive MFA is triggered for users without an MFA factor enrolled, they will be prompted to complete an Email challenge before being asked to enroll in an MFA factor. This is outlined in our Adaptive MFA documentation, which includes a handy flow diagram:



Adaptive MFA flow
 
Solution
This behaviour is expected when Adaptive MFA is triggered for a user without an existing MFA enrollment. 

Recommended content

No recommended content found...