Repository navigation
Conversation
Entra can accept an MFA code but repeat the challenge when the final sign-in request lacks page continuation context. This leaves affected users unable to reach AWS.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Some users can enter a valid MFA code but saml2aws asks for another code instead of completing sign-in. This change returns the additional sign-in details Microsoft supplied, allowing the accepted MFA step to carry through to AWS.
It does not skip or weaken MFA. Older Entra sign-in responses remain supported.
Why this matters
Affected users are blocked from AWS even though Microsoft accepts their verification code. We reproduced this with an account subject to a stricter MFA policy and confirmed the corrected flow completes in the same environment.
Validation
Context
Addresses #1072.
This is a focused follow-up to #1468, which identified the same missing sign-in details alongside additional authentication changes. This PR isolates the validated MFA-loop fix and adds regression coverage. Thank you to @beardtm for identifying the original fix direction.