Hello, everyone. In today’s article I’ll bring a simple tip that can help support engineers identify users having trouble registering for MFA.
During the rollout of MFA in a corporation, users may be blocked by the administrator or have their accounts blocked when reporting fraud during an MFA validation contact in Azure.
Possible symptoms
To make it easier and simulate some errors that may be reported by users, I forced an MFA block on a user in my lab through the fraud report.
In the figure below we can confirm that the user chrystal@ulyneves.com is blocked for MFA:

With the user blocked for MFA, they may receive one of the errors below, depending on which interface is being used to add MFA information:
1 – On the MFA registration page aka.ms/mfasetup the error shown is: We’re sorry, we ran into a problem. Please select “Next” to try again.

2 – On the user’s profile security info page, the message shown is: You are blocked from performing this operation. Please contact your administrator for help.

3 – In the Microsoft Authenticator app, when trying to add the account during the MFA registration process, you’ll receive an error while scanning the QR code: Activation failed. Make sure that push notifications are enabled on the phone and your Activation Code is not wrong, expired or formerly used.

Checking whether the user is blocked
To confirm whether the errors above are caused by a user blocked for MFA, simply access the menu Azure AD > Security > Multi-Factor Authentication > Block/unblock users or use this link.
As we can see, the user chrystal@ulyneves.com is blocked. Let’s click Unblock.

Let’s provide the reason for the unblock and click OK.

Testing access with the unblocked user
Now let’s test access with the unblocked user by accessing the address https://aka.ms/mfasetup
After following the steps to register the MFA information, we no longer receive the errors mentioned previously.

Quick tip
The setting responsible for automatically blocking users who report fraud is called Automatically block users who report fraud and is available in the menu Azure AD > Security > Multi-Factor Authentication > Fraud alert.

If you don’t want users to be blocked for MFA due to fraud, simply disable this option by switching the toggle to Off.
Summary
In today’s article, I explained how to identify and handle errors related to MFA blocking in the Microsoft Entra ID portal. I also explained how to disable the option that automatically blocks users who report fraud, in case the administrator doesn’t want to use this option.
I hope this content has helped enrich your knowledge of Microsoft Entra multifactor authentication.
Did you like the post? Like it and share it. 🙂
If you have any suggestions or comments, let us know.
[ ]’s
Ulysses Neves
