Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-21412: Prompted for Offline Passcode When Machine is Not Offline

Privilege Elevation Service ,  

2 October,19 at 04:47 PM

Problem: When elevating privileges on a Windows machine, the user is immediately prompted for Offline Passcode. However, the machine is not offline and MFA is not configured on this server. 

User-added image

Cause: Due to MFA not being configured on this server, the Identity Service is not initiated. In order for MFA to work on a Windows machine, the IWA root certificate needs to be pushed to the machine. The machine needs to be added to the correct role in the tenant and the Identity Service has to be initiated successfully. 

If a machine is not part of the role in the tenant, then when it goes to register itself to the tenant it fails. 

In this case, the elevated right in the zone has the "Require MFA" attribute populated. Instead of throwing an error, the agent prompts for Offline Passcode. 

Resolution: The right for privilege elevation should not require MFA on a server where the Identity Service has not been initiated. To fix this, remove the "Require MFA" on the right granting the privilege elevation. 

User-added image