Wait for ReplayService altough Replay Protection Level is disabled #372
-
Hey, we've experienced (at least in my eyes) a strange behaviour. We've set the "Replay Protection Level" to "Disabled" and I would therefore expect, that no replay protection is enabled at all. But as soon as the second ADFS server is not available, the MFA validation takes ~15s and you can see the following message in the event logs:
Is that the expected behaviour? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Yes, for some features, it is imperative to restart the MFA service on each ADFS server. |
Beta Was this translation helpful? Give feedback.
-
3.1.2508.0 |
Beta Was this translation helpful? Give feedback.
Hello, I just ran a test with my 2019 platform in SQL mode.
No problem, I was able to replay the TOTP code from two separate computers, without any messages in the event log.
If you are in AD DS mode, check or force the "Synchro" between your Primary server and your Secondary servers.