Curious: what is the reason you’re sending an email to the user on connection?
aha nice question... the customer needs to be warned if someone connects to the vpn with its credentials.
We tried several times to make it understand that with VPN multi-factor authentication (username&password (AD) + machine authentication), if someone successfully connects to the site with its user, means that someone have stolen its credentials but, more important, someone have stolen its workstation (!)(lol)
coming back to the topic question: we are thinking about the possibility to add DynamicID (with mail) to the currently MFA, but discard the OTP, just to have only the mail sent to the user recipient but not considering the OTP as an authentication method. Is that possible to bypass DynamicID OTP even if configured?