[GH-ISSUE #899] FEATURE REQUEST: Excluded MFA Users #459

Closed
opened 2026-03-02 12:42:24 +03:00 by kerem · 2 comments
Owner

Originally created by @bbeamts on GitHub (Apr 25, 2022).
Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/899

Is your feature request related to a problem? Please describe.
In some situations service accounts may need MFA excluded for certain services. AD Sync is one example. Using standards to enforce MFA for all users is great, but there is no ability to exclude a single user or group from the policy and so MFA gets re-enabled every standards check.

Describe the solution you'd like
Ability to select/specify a set of excluded users from the standard/policy.

Originally created by @bbeamts on GitHub (Apr 25, 2022). Original GitHub issue: https://github.com/KelvinTegelaar/CIPP/issues/899 **Is your feature request related to a problem? Please describe.** In some situations service accounts may need MFA excluded for certain services. AD Sync is one example. Using standards to enforce MFA for all users is great, but there is no ability to exclude a single user or group from the policy and so MFA gets re-enabled every standards check. **Describe the solution you'd like** Ability to select/specify a set of excluded users from the standard/policy.
kerem 2026-03-02 12:42:24 +03:00
Author
Owner

@KelvinTegelaar commented on GitHub (Apr 25, 2022):

CIPP is made to only apply a secure configuration - The ADSync exclusion is already in place and a huge exception. We will not support making configurations less secure so this is a wontfix.

<!-- gh-comment-id:1108912269 --> @KelvinTegelaar commented on GitHub (Apr 25, 2022): CIPP is made to only apply a secure configuration - The ADSync exclusion is already in place and a huge exception. We will not support making configurations less secure so this is a wontfix.
Author
Owner

@bbeamts commented on GitHub (Apr 25, 2022):

Thanks for quick responses Kevin and sorry to have bombarded on a few of these (egg on my face). We have two tenants with MFA forced and ADSync is failing since enabling.

<!-- gh-comment-id:1108927135 --> @bbeamts commented on GitHub (Apr 25, 2022): Thanks for quick responses Kevin and sorry to have bombarded on a few of these (egg on my face). We have two tenants with MFA forced and ADSync is failing since enabling.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/CIPP#459
No description provided.