In CAM we have an Authenticator defined that looks for the 'mobile' field in AD to request a token via 2FA Starling.
If we create a new user in AD allowed to logon to CAM with that mobile field populated with a valid phone number - it works
If we update that mobile field in AD, with a different phone number, it can take up to an hour before Defender as a Service starts sending tokens to the new number. In the meantime it sends to the 'old' phone number