Skip to content

fix(aad): Complete Entra MFA sign-in - #1538

Open
icirellik wants to merge 1 commit into
Versent:masterfrom
icirellik:fix/aad-mfa-continuation
Open

icirellik wants to merge 1 commit into
Versent:masterfrom
icirellik:fix/aad-mfa-continuation

Conversation

@icirellik

Copy link
Copy Markdown

Summary

Some users can enter a valid MFA code but saml2aws asks for another code instead of completing sign-in. This change returns the additional sign-in details Microsoft supplied, allowing the accepted MFA step to carry through to AWS.

It does not skip or weaken MFA. Older Entra sign-in responses remain supported.

Why this matters

Affected users are blocked from AWS even though Microsoft accepts their verification code. We reproduced this with an account subject to a stricter MFA policy and confirmed the corrected flow completes in the same environment.

Validation

  • Added automated coverage for current and older Entra response shapes
  • Full test suite, build, static checks, and race checks pass

Context

Addresses #1072.

This is a focused follow-up to #1468, which identified the same missing sign-in details alongside additional authentication changes. This PR isolates the validated MFA-loop fix and adds regression coverage. Thank you to @beardtm for identifying the original fix direction.

Entra can accept an MFA code but repeat the challenge when the final
sign-in request lacks page continuation context. This leaves affected
users unable to reach AWS.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant