Error: Your account is not enrolled for multi-factor authentication. Please enroll to avail the service

Error: Your account is not enrolled for multi-factor authentication. Please enroll to avail the service

Issue description   

Users may encounter the error message "Your account is not enrolled for multi-factor authentication. Please enroll to avail the service" when trying to log in to ADSelfService Plus.

Possible cause 

  • MFA is enabled for ADSelfService Plus login, but the user has not enrolled in any MFA method.

Prerequisite 

  • Administrative access to the ADSelfService Plus portal.

Resolution  

Step 1: Configure forced MFA enrollment
The ADSelfService Plus administrator should:
  1. Log in to the ADSelfService Plus console.
  2. Navigate to Configuration > Self-Service > Multi factor Authentication > Advanced > Applications MFA.
  3. Enable the Force enrollment for not enrolled users after successful password verification setting.
  4. Click Save to apply the changes.
Step 2: Instruct user to complete MFA enrollment
Once forced enrollment is enabled:
  1. Ask the user to log in to the ADSelfService Plus portal using their AD credentials.
  2. After successful password verification, the user will be prompted to enroll for MFA.
  3. The user should follow the on-screen steps to configure the required authentication methods.
  4. After completing enrollment, the user will be able to log in successfully using MFA.

How to reach support                     

If the issue persists, contact our support team here.


                  New to ADSelfService Plus?