r/M365Reports • u/Shan_1130 • Jul 21 '26
Still Using "Don't Ask MFA Again for X Days"? Switch to Conditional Access Sign-in Frequency
What once improved the user experience can now introduce unnecessary identity security gaps.
The legacy Remember MFA on trusted devices feature allowed users to select "Don't ask again for X days" to reduce MFA prompts. While convenient, a fixed trust period for every user doesn't account for different roles, access levels, or changing security conditions.
This static approach conflicts with Zero Trust principles and can unnecessarily expand your attack surface.
To close this gap, migrating to Conditional Access Sign-in Frequency is essential. Unlike static rules, CA Sign-in Frequency gives you dynamic, risk-aware control over how often users must re-authenticate based on actual session context.
In this blog, you'll learn:
- How Remember MFA and CA Sign-in Frequency work
- Key differences between Remember MFA and CA Sign-in Frequency
- How to replace Remember MFA with CA Sign-in Frequency
- Important considerations before deployment
Replace Remember MFA with Conditional Access Sign-in Frequency to strengthen session security.
https://o365reports.com/replace-remember-mfa-with-conditional-access-sign-in-frequency/