> Should the SSO have just continued , basically bypassing > MFA? If you don't disable the check, it's behaving as intended. The check serves no purpose if one is going to just ignore it, ergo the option to just turn it off, but that's not the default. What you actually do in response to Duo failing is of course entirely up to you, as Steven said. -- Scott