## TL;DR
When the VPN accepts the password but the two-factor prompt never appears, the breakdown is between the VPN server and the MFA provider: RADIUS challenge handling, push delivery, or the client swallowing the prompt. Trace the RADIUS exchange and test the MFA path directly.

## The query
```text
vpn two-factor prompt never appears at login
```

## Use this when
- VPN login hangs after the password with no MFA prompt
- push approvals work for other apps but not VPN
- migrated MFA provider and VPN prompts stopped

## Not for
- password rejected (fix credentials first)
- MFA prompt appears but approvals fail
- VPN client not launching at all

## Steps
1. Check the VPN server logs for the RADIUS exchange to see whether a challenge was sent. Expected output: you see whether the server issued the challenge
2. Test the MFA path directly, such as triggering a push from the MFA admin console. Expected output: push delivery confirmed working or broken
3. Verify the RADIUS shared secret matches on both the VPN server and the MFA server. Expected output: secrets match
4. Check the VPN client version handles RADIUS challenges; some older clients swallow the prompt. Expected output: client version supports the challenge flow
5. Confirm the user's MFA enrollment is active and the right device is targeted. Expected output: enrollment healthy
6. Retry the VPN login and watch both the server log and the user's device. Expected output: the prompt appears and the login completes

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_MwVv8rQTNYlBjesNs1_9dw
