Fix Azure Entra–Google Federation -- 2

Job ID: 39915980

Budget: $30 – $250 USD

I recently federated our Azure Entra ID (formerly Azure AD) with Google Workspace for Education so that students can use a single set of credentials. Since turning it on, Conditional Access seems to be forcing MFA in a way that blocks Android-only students from adding their school Gmail accounts to their phones.

I need someone who can:

• Inspect the existing Entra ID ↔ Google SAML/OIDC federation setup and verify claims, certificates, and authentication policies.
• Adjust or create Conditional Access policies so that student logins are streamlined—no unnecessary MFA prompts when they register Gmail on Android—while staff policies remain untouched.
• Provide a clear rollback and testing plan, including a short step-by-step checklist I can repeat if we update certificates later.
• Walk me through the change in a brief call or concise document so I understand what was modified.

Experience with Azure Entra ID Conditional Access, SAML federation, and Google Workspace for Education is essential. If you can get students logging in smoothly again without compromising overall security, let’s get started.