Session control in Conditional Access that makes users authenticate again once a configured period has passed.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Sign-in frequency in context, with comparison tables and the common traps.
Terms in this definition
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- Remember MFA on trusted devices
An older per-browser MFA bypass: a persistent cookie means no second prompt for a chosen number of days. Microsoft now steers you towards the sign-in frequency control in Conditional Access instead.
- Require risk remediation
Leaves it to ID Protection to decide how a risky user is fixed, either reauthentication or a secure password change, regardless of how they sign in. Selecting it also adds sign-in frequency set to Every time and an authentication strength.
- Session controls
Conditional Access controls, for example app-enforced restrictions and sign-in frequency, that constrain a session. They do not enforce MFA.