MFA Frequency Guide

MFA is required for all users

This article explains the frequency settings for Multi Factor Authentication (MFA).  As well as the frequency of prompts per application/device. 

What Users will Experience with Default MFA Settings:

Default Settings for Applications: For each desktop and mobile application used, you will be prompted for MFA once until you perform one of the actions listed below, then you will receive the MFA prompt again.

Default Settings for Browsers: For each browser you use, you will be prompted for MFA once and as long as you say "yes" to stay signed in, you will not receive an MFA prompt until you perform one of the actions below. If you select "no" on stay signed in, then you will be required to complete MFA again after you close your browser window.

ITS recommends selecting “yes” to the browser prompt below, to receive fewer authentication requests and stay signed into your regularly used device. Otherwise, users will be prompted again for MFA when you close and reopen your browser.

List of Example Actions that will Cause Microsoft to Prompt for MFA: 

  • The maximum number of days between sign-ins is met for high priority systems, such as mySeattleU and the VPN (see MFA sign-in frequency chart below)

  • Switching to a new browser 

  • Switching to a new device  

  • If a device, browser, or Office desktop/mobile application is not used for 90 days or more  

  • Resetting your SU password  

  • Clearing browser cookies (or using a browser that is setup to clear cookies after it is closed or is setup not to save any cookies) 

  • Not selecting “Yes” on the “Keep me signed-in” pop-up box  

  • Signing out of a Microsoft 365 application  

  • Using an incognito/private browser window  

  • Having two or more Microsoft school or work accounts registered with your windows device  

  • ITS revoking MFA sessions if your device is lost or stolen 

  • Your MFA settings are cleared and require you to re-register with MFA  

  • When Microsoft prompts you to “Allow my organization to manage this device” 

  • Microsoft verifying your password recovery information is still correct once every 180 days 

  • Microsoft labels the user as a risky user based on sign-in activity and will prompt MFA again to ensure security

Exceptions to MFA Default Settings: 

Individual applications can have their own MFA prompt frequency outside of the default setting. These are used when systems contain highly sensitive information. The non-default frequencies are noted in the table below and vary based on the application. 

An application owner can request a sign in frequency different from the default experience if they desire.  A custom sign-in frequency for an application can range from once per hour to once per 365 days. 

Applications Setup to Use MFA: 

Application 

MFA Frequency 

Adobe Creative Cloud 

Default 

Atlassian 

Default 

Axiom 

Default 

Azure Portal 

Default 

BeyondTrust 

7 days 

BitBucket 

Default 

Bookings (Microsoft) 

Default 

Campus Labs 

Default 

Canvas 

Default 

CareerShift 

Default 

Colleague UI 

7 days 

Confluence 

Default 

Curriculog

Default

EngageSU

7 days

Delve (Microsoft) 

Default 

Directory Update Form

Default

DocuSign 

7 days 

eAccounts 

Default 

Excel (Microsoft) 

Default 

EZProxy 

Default 

Flow / Power Automate (Microsoft) 

Default 

Forms (Microsoft) 

Default 

GivePulse 

Default 

GlobalProtect VPN

7 days

Handshake 

Default 

iParq 

Default 

Jira Service Desk 

Default 

Jira Software 

Default 

LinkedIn Learning

Default

Maxient 

Default 

Megamation 

Default 

Microsoft 365 Admin Center 

1 hour

mySeattleU

7 days

OneDrive (Microsoft) 

Default 

OneNote (Microsoft) 

Default 

OrgSync / ConnectSU 

Default 

Outlook (Microsoft) 

Default 

PeopleGrove 

Default 

Pharos / Redhawk SOAR 

Default 

Planner (Microsoft) 

Default 

Power Apps (Microsoft) 

Default 

Power BI (Microsoft) / InformSU 

Default 

PowerPoint (Microsoft) 

Default 

PowerShell Connections 

Each time the script is executed 

Primo / Library System 

Default 

Privileged (priv-*) Accounts

1 hour

Project (Microsoft) 

Default 

Raiser’s Edge NXT 

7 days

Safari Books 

Default 

SharePoint (Microsoft) 

Default 

Slate

7 days 

SoftDocs 

Default 

Solarwinds

Default

Statuspage 

Default 

Stream (Microsoft) 

Default 

Sway (Microsoft) 

Default 

Teams (Microsoft) 

Default 

Terminal Four 

7 days

TimelyMD

Default

To Do (Microsoft) 

Default 

Trello 

Default 

TutorTrac 

Default 

Whiteboard (Microsoft) 

Default 

Word (Microsoft) 

Default 

Yammer (Microsoft) 

Default 

Zoom 

Default 

Please Note all priv and super accounts will be prompted for MFA once every hour for all applications and systems setup to use Azure MFA.  This will overrule any application MFA frequency setting.