microsoft / microsoft/terminal
Azure Cloud Shell Fails to connect when you have multiple tenants and 1 of them requires MFA
- Dominant language
- C++
- Stars
- 105k
- Forks
- 9.6k
- Avg merge
- 3d 17h
- Merged PRs (30d)
- 29
Description
I have several Azure AD tenants attached to my account.
When starting cloud shell, I can choose my tenant however, a terminating error appears when one of the other tenants needs MFA and exits instead of continuing to sign in to the chosen tenant.
Steps to Reproduce:
Have an Azure AD account that is used in multiple tenants.
1. Start the Azure Cloud Shell Connector
2. Proceed with the device sign in
3. Choose the tenant that you wish sign in with
You will see an error for the other tenants about requiring MFA even though it is not the tenant you are trying to use.

The only workaround is to sign in to each tenant and then go back and sign in to the tenant you intended to in the first place.
When you do this through shell.azure.com you simply get a warning for each tenant that needs to be refreshed but you end up signed in to the correct tenant.
Contributor guide
Research direction
Start at the Azure Cloud Shell Connector device-sign-in flow and reproduce with an account spanning tenants, including one requiring MFA. No file or test is named; done means selecting one tenant completes sign-in while MFA requirements in other tenants produce warnings rather than terminating the connection, matching shell.azure.com.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- authentication, cloud
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100