Problem: When elevating privileges on a Windows machine, the user is immediately prompted for Offline Passcode. However, the machine is not offline and MFA is not configured on this server.
Cause: Due to MFA not being configured on this server, the Identity Service is not initiated. In order for MFA to work on a Windows machine, the IWA root certificate needs to be pushed to the machine. The machine needs to be added to the correct role in the tenant and the Identity Service has to be initiated successfully.
If a machine is not part of the role in the tenant, then when it goes to register itself to the tenant it fails.
In this case, the elevated right in the zone has the "Require MFA" attribute populated. Instead of throwing an error, the agent prompts for Offline Passcode.
Resolution: The right for privilege elevation should not require MFA on a server where the Identity Service has not been initiated. To fix this, remove the "Require MFA" on the right granting the privilege elevation.