Managing external identities to enable secure access for partners, customers, and other non-employees
Guest user, that has accepted invitation, is getting stuck with an MFA prompt that is not useful before he is asked to register for MFA.
We invite guest users to access some of our services using SSO. We have MFA turned on as required. We have invited a user from a local college. Their college utilizes Microsoft. When they accept the invitation, they are prompted to login through their college system. They utilize Duo push. Once they get past the college login pages, they come over to our Entra for the MFA step, but instead of prompting them to register for Authenticator like it usually does, the system just prompts this person to enter their MFA code (which they don't have because they haven't even registered yet).
I even deleted their profile in our directory and re-invited them, to no avail, the same behavior occurs. I added their mobile phone to their MFA profile so that they would be given an option to use another MFA method, but they still don't get any links to other methods. I can see in the audit logs that they accepted the invitation, but I don't see anything else in the sign-in or audit logs coming from their side.
I am not sure if the issue is on our side of microsoft or on the college system side of Microsoft, but there seems to be some kind of disconnect. Their college IT admin didn't see anything amiss. We have several other guest users from the same college that have no problems, so wanting to figure out what additional troubleshooting steps we can do to try to resolve the issue (either on our side or the college system side). Any suggestions would be appreciated. Thank you.