Forum Widgets
Latest Discussions
Azure AD SSPR Password write back issue
Hi all, A company I work for have issues with the reset password function with AD Connect. In the SSPR audit logs in Azure AD, we face on 'Reset password (self-service)' the status reason 'OnPremisesAdminActionRequired', with a follow up event log within the AD connect server: event ID: 33004 with error "hr=80230626, message=The password could not be updated because the management agent credentials were denied access" I face this issue before and this was causing because the AD DS connector account did not have the right permissions. In this case this is not. What I have done so far: - Updated AD Connect from 2.0.89.0 to 2.0.91.0 - enforced TLS 1.2: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-tls-enforcement - Checked AD DS connecter account 'MSOL_xxxxxxxx' permissions: https://docs.microsoft.com/en-us/azure/active-directory/authentication/troubleshoot-sspr-writeback#verify-that-azure-ad-connect-has-the-required-permissions - the user do not have the options 'password never expires' or 'user cannot change password' configured - Let AD connect talk to another DC dc02 instead of dc01 - Checked connection to SSPR service from DC's : Test-NetConnection -ComputerName ssprdedicatedsbprodscu.servicebus.windows.net -Port 443 - The action 'Change password (self-service)' are successful (via my account portal) , only action 'Reset password (self-service)' face this issue (via passwordreset.microsoftonline.com) -- both use the same OnPremisesAgent ->> AADConnect Have anyone a idea what else I can try more? Regards, RicardoSolvedvand3rlindenJul 09, 2026Brass Contributor26KViews0likes13CommentsDevice Bound Session Credentials Edge
Hi everyone, For a customer i did some research about token protection within M365. I did find a lot information what to configure within M365 to get a multi layer protection (CA, Identity Protection, device compliance, etc). What i didn't found was a solution for token/cookie protection from the browser, until i found this article: https://en.ittrip.xyz/windows/edge/edge-147-device-bound#index_id0 This article states that edge 147 supports Device Bound Session Credentials which makes it much harder to do a off-device replay of a cookie. It also is saying: If you buy rather than build, ask your identity provider or SaaS vendor a direct question: do you have a roadmap for Device Bound Session Credentials or an equivalent browser-session binding model? So my question is: Does M365 (via the browser) supports Device Bound Session Credentials or will it be supported any time soon? Hope you have a nice day! Regards, MJSolvedmarkjanbakkerJul 01, 2026Tin Contributor141Views0likes2CommentsAAD multiple accounts from same realm is not supported by clients.
I've signed out of Excel for iPadOS 2.101.25100311. I've closed (not forced shutdown) and reopened the app. I'm trying to sign in with a different Microsoft account. However, it shows the error: "Another account from your organization is already signed in on this device". How can I completely sign out of that other account? The troubleshooting details are below. Correlation Id: 5520852a-4877-ec4c-97be-f3de2c079058 Timestamp: 2026-06-21T22:49:29.000Z DPTI: FAF41146-8AF4-425C-95EE-1654DD13C47C Message: AAD multiple accounts from same realm is not supported by clients. Tag: 5pzx9SolvedrootsmusicJun 21, 2026Brass Contributor219Views0likes1CommentHow do I get support so I don't loose my account?
I have a business 365 account but changed address and so my credit card payments stopped. However, I can't log in to my account because I also have an authentication problem (my authentication app on iPhone is still working but the entry for this account has gone and there is a new one called "Microsoft Entra ID" but when I go to get the authentication code this "Entra ID" authenticator does not produce it). To get help from Microsoft it always asks for authentication. I would like to keep this account and start paying again but I can't find a way to get help to fix the authentication problem because raising a ticket or talking to an agent requires authentication. I got my final warning email today saying Warning—your online services will be deprovisioned and your data deleted in seven days There must be some way to get a call from Microsoft so I don't loose my account and all my data?Solved154Views0likes6CommentsExcel authentication token reuse for access to Log Analytics
I have noticed that Excel is not able to reuse the authentication token when accessing Log Analytics workspaces if an expired token was renewed for a single sheet in a workbook. Scenario: 1 workbook with 1+ worksheets Each worksheet is a different query to LA (KQL query displayed in Excel for ease and consolidation) Access to LA is protected by the usual access controls (Conditional Access; Security Reader role + Session control) After a period of time, session and token expire and require renewal User receives a prompt stating the token has expired and needs to be renew User clicks on "Sign-in" and successfully completes the prompts (u/n+pwd+MFA) Expected result: The new token will be reused for subsequent connections to LA within the same workbook Actual result: User is prompted to re-authenticate for each and every connection in the workbook resulting in as many auth requests as there are connections Workaround: After successfully completing the first auth request, close Excel and re-open it and run "Refresh all" This successfully completes refresh of all data without any additional re-auth requests Is this behaviour by design or due to a configuration? Is there a way to address this so that the first token is re-used by all other connections without having to close and reopen the workbook?SolvedzivrivkisJan 30, 2026Brass Contributor173Views0likes2CommentsDeactivating Option to change Profile Picture at myaccount.microsoft.com
As the title says. I would like to deactivate the option for users to change their profile picture at myaccount.microsoft.com. The profile picture at our company is synchronized to AD and via Entra Connect to Entra ID. Is there an option as an admin to deactivate that option without deactivating the entire portal? Kind Regards Christopher SiebertzSolvedCSIFeb 21, 2025Tin Contributor2.3KViews1like4CommentsFederation Issues - No protocol handlers?
Hi All, It's been a number of years since I've federated a domain with Entra, i'm flipping this back in a home environment to complete some testing. Would appreciate some troubleshooting thoughts. What from memory was a quick task, I've spent waaaaay to long on this today. I've rebuilt the environment a number of times with the same outcome. Install ADFS (Enabled the sign-in page). Install WAP. Generate Let's Encrypt certificate and provide to the servers. Port Forward 443 to the WAP server. Use Entra Connect to Federate the domain (AD FS Config looks good and generated as Microsoft Office 365 Identity Platform) WAP is configured via AAD Connect (Blank but seems alright talking back to ADFS) I can hit https://adfs.domain.com/adfs/ls/idpinitiatedsignon.aspx and authenticate with UPN internally/externally. I can hit https://adfs.domain.com/FederationMetadata/2007-06/FederationMetadata.xml internally/externally. I also setup IAMShowcase to test (https://sptest.iamshowcase.com/) and published the app via the WAP, worked fine for SP and IDP initiated flows. Interestingly enough, I am chucked the following error from the ADFS redirection with M365 authentication: Error details: MSIS7065: There are no registered protocol handlers on path /adfs/ls/ to process the incoming request. This raises an error on the ADFS server ID#364, I've rebuilt a few times and havent been able to find much in troubleshooting. Would love to hear if someone else has seen something similar, i'm at a bit of a loss here. Encountered error during federation passive request. Additional Data Protocol Name: Relying Party: Exception details: Microsoft.IdentityServer.Web.IdPInitiatedSignonPageDisabledException: MSIS7012: An error occurred while processing the request. Contact your administrator for details. at Microsoft.IdentityServer.Web.Protocols.Saml.IdpInitiatedSignOnRequestSerializer.ReadMessage(WrappedHttpListenerRequest httpRequest) at Microsoft.IdentityServer.Web.Protocols.Saml.HttpSamlMessageFactory.CreateMessage(WrappedHttpListenerRequest httpRequest) at Microsoft.IdentityServer.Web.Protocols.Saml.SamlContextFactory.CreateProtocolContextFromRequest(WrappedHttpListenerRequest request, ProtocolContext& protocolContext) at Microsoft.IdentityServer.Web.Protocols.Saml.SamlProtocolHandler.CreateProtocolContext(WrappedHttpListenerRequest request) at Microsoft.IdentityServer.Web.PassiveProtocolListener.GetProtocolHandler(WrappedHttpListenerRequest request, ProtocolContext& protocolContext, PassiveProtocolHandler& protocolHandler) at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context) Get-MgFederatedDomainFederationConfiguration -Identity http://domain.com/ ActiveSignInUri : https://adfs.domain/adfs/services/trust/2005/usernamemixed IssuerUri : http://domain/adfs/services/trust/ MetadataExchangeUri : https://adfs.domain/adfs/services/trust/mex PassiveSignInUri : https://adfs.domain/adfs/ls/ PreferredAuthenticationProtocol : wsFed SignOutUri : https://adfs.domain/adfs/ls/SolvedMiikeNov 28, 2024Brass Contributor4.6KViews1like15CommentsWebsite Rendering Issue on Microsoft Edge - Seeking Assistance
Hello everyone, I've been encountering an unexpected problem with my website's rendering specifically on Microsoft Edge browser. The website displays perfectly fine on other browsers like Chrome, Firefox, and Safari, but when viewed on Microsoft Edge, certain elements seem to be misaligned or appear distorted. I've ensured that the website's code is compliant with web standards and has been validated. Despite this, the issue persists exclusively on Edge. I've also tested it across multiple devices running different versions of Edge, and the problem seems consistent. The https://capprocutapk.com/ is built using HTML5, CSS3, and JavaScript/jQuery for interactivity. I've used responsive design practices to ensure compatibility across various screen sizes. Has anyone encountered a similar problem before or have suggestions on how to address this issue specific to Microsoft Edge? Any insights, advice, or potential solutions would be greatly appreciated. Plz tell me how to fix as I am not a technical person. Thank you in advance for your help!Solvedmitchellsamu3Oct 27, 2024Copper Contributor2.4KViews0likes4CommentsFeature request - note field for AAGUID
Dear Microsoft Team, I am writing to request a feature enhancement for MS Entra. Specifically, it would be highly beneficial to have a note field associated with each enabled AAGUID. Currently, it is challenging to identify the device corresponding to each AAGUID. Adding this feature would greatly improve the usability and management of devices within MS Entra. Thank you for considering this request. I look forward to your response. Best regards, MartinSolvedMartin_KoeOct 21, 2024Copper Contributor310Views0likes2CommentsUser getting refresh token expired due to inactivity in Outlook desktop AADSTS70008
I have a user who continues to receive this AADSTS70008 error in Outlook Desktop. This computer has been in service for several years and Outlook desktop has been running fine. User can successfully authenticate in MS Teams and Outlook on the Web. MFA is enabled. I have attempted a restart but Outlook produces the same error. I have seen older posts suggesting that the registry key for the office activation be removed to fix this issue. Any thoughts on a more straightforward fix than registry hacks? DSTS70008Solved3.3KViews0likes2Comments
Tags
- Authentication370 Topics
- office 365222 Topics
- security173 Topics
- Identity77 Topics
- multi-factor authentication72 Topics
- admin71 Topics
- Authenticator app58 Topics
- Azure AD54 Topics
- exchange44 Topics
- microsoft 36543 Topics