To configure the frequency of MFA, edit the "domain_policy.json" file in a text editor and change the following MFA policy options in the specific scenarios, such as "azuread\online\MfaPolicy"

OptionScenarioRemarks
loginMfa.skipHoursLastMfaBoot up loginSpecify a period in hours since last MFA at boot-up login. During this period, MFA will not be prompted  for boot-up login.
uacMfa.skipHoursLastMfaElevated AccessSpecify a period in hours since last MFA boot-up login. During this period, MFA will not be prompted for elevated access.
uacMfa.skipMinutesLastUacElevated AccessSpecify a period in minutes since last MFA for elevated access. During this period, MFA will not be prompted for elevated access.
unlockMfa.skipHoursLastMfaScreen UnlockSpecify a period in hours since last MFA boot-up login. During this period, MFA will not be prompted for screen unlock.
unlockMfa.skipMinutesLastLockScreen UnlockSpecify a period in minutes since last MFA for screen unlock. During this period, MFA will not be prompted for screen unlock.


  • No labels