This issue sounds like an issue that our users started to report, only it alternates between a modern authentication prompt and the old style one, while the Azure sign in logs alternate between the application “Microsoft Office” and “Microsoft Authentication Broker” (possibly not in that order).
Weird thing is it’s only affecting people working remotely (which makes sense, due to the conditional access policies with location-based exclusions, but makes nailing down the contributing factors more annoying).
We have just finished ruling out two potential causes for our issue with another couple still on the list to work through (all of which are actual issues that need fixing, whether or not they’re causing this - mostly things like outdated AAD Connect versions and fragments of legacy Azure AD computer registrations that pre-date our hybrid joins, etc). I currently have a lot of variables and not much clarity, plus a generally tech-unsavvy userbase in often distant timezones, and underdeveloped support function for troubleshooting and gathering proper data for me to work with, so it’s pretty slow going.
Glad we are not alone here and will be watching his thread closely for updates!!