microsoft / microsoft/terminal

Azure Cloud Shell Fails to connect when you have multiple tenants and 1 of them requires MFA

Open
#12,458 2 comments 0 reactions 0 assignees View on GitHub
Area-AzureShell Help Wanted Issue-Bug Priority-2 Product-Terminal
Dominant language
C++
Stars
105k
Forks
9.6k
Avg merge
3d 17h
Merged PRs (30d)
29

Description

I have several Azure AD tenants attached to my account.

When starting cloud shell, I can choose my tenant however, a terminating error appears when one of the other tenants needs MFA and exits instead of continuing to sign in to the chosen tenant.

Steps to Reproduce:

Have an Azure AD account that is used in multiple tenants.

1. Start the Azure Cloud Shell Connector
2. Proceed with the device sign in
3. Choose the tenant that you wish sign in with

You will see an error for the other tenants about requiring MFA even though it is not the tenant you are trying to use.

![image](https://user-images.githubusercontent.com/18618111/153442576-89c3bb28-1c60-46ed-b101-76333c4fbe3b.png)

The only workaround is to sign in to each tenant and then go back and sign in to the tenant you intended to in the first place.

When you do this through shell.azure.com you simply get a warning for each tenant that needs to be refreshed but you end up signed in to the correct tenant.

Contributor guide

Open the contributing guide

Research direction

Start at the Azure Cloud Shell Connector device-sign-in flow and reproduce with an account spanning tenants, including one requiring MFA. No file or test is named; done means selecting one tenant completes sign-in while MFA requirements in other tenants produce warnings rather than terminating the connection, matching shell.azure.com.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
authentication, cloud
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.