How to configure an MFA-enabled service account

If your service account is MFA-enabled, you need to use either the Conditional Access or Trusted IP feature in Microsoft 365 to bypass MFA.

Note: To use Conditional Access or Trusted IPs, you need an Azure AD Premium P1 license.

Steps to configure trusted IPs

  1. Log in to portal.azure.com using your Global Administrator credentials.
  2. Click Azure Active Directory under Azure services.
  3. Choose Security from the left pane.
  4. Click MFA under the Manage category in the left pane.
  5. Choose the Additional cloud-based MFA settings option.
  6. In the new window that opens, navigate to the trusted IPs section.
  7. Select the Skip multi-factor authentication for requests from federated users on my intranet option.
  8. In the text box, enter the IP address of the machine in which you have installed RecoveryManager Plus.
  9. Click Save.

Steps to configure conditional access

To configure conditional access,

  1. Log in to portal.azure.com using your Global Administrator credentials.
  2. Click Azure Active Directory under Azure services.
  3. Choose Security from the left pane.
  4. Click Conditional Access under the Protect category in the left pane.
  5. Click New Policy.
  6. Provide a name for the policy.
  7. Click Users and groups option.
  8. Select the Exclude tab.
  9. Select the Users and groups check box, and choose the RecoveryManager Plus users for whom MFA should not be enforced.
  10. Click Select.
  11. Under the Access controls section, click Grant.
  12. Select the Grant access radio button and the Require multi-factor authentication check box.
  13. Click Select.
  14. Click Create and then Save.

You can now proceed to add your Microsoft 365 tenant to RecoveryManager Plus using the automatic configuration method or the manual method.

Copyright © 2023, ZOHO Corp. All Rights Reserved.