Home

Enabling Azure MFA causes user account to lockout in AD

%3CLINGO-SUB%20id%3D%22lingo-sub-72778%22%20slang%3D%22en-US%22%3EEnabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-72778%22%20slang%3D%22en-US%22%3E%3CP%3ECurrently%20we%20are%20in%20a%20hybrid%20environment%20where%20we%20utilize%20ADConnect%20to%20sync%20passwords%20up%20to%20our%20Azure%20AD%20tenant.%20%26nbsp%3BAll%20user%20mailboxes%20are%20on%20Office%20365%20with%20an%20Exchange%202010%20SP3%20environment%20on%20prem.%20%26nbsp%3BWe%20also%20have%20Skype%20for%20Business%20on%20prem%20as%20well.%20%26nbsp%3BPlease%20don't%20ask%20why%20we%20are%20setup%20this%20way.%20%26nbsp%3B%20Management%20and%20their%20infinite%20wisdom.%20%26nbsp%3BThe%20users%20we%20are%20testing%20with%20have%20Office%202016%20and%20I've%20enabled%20modern%20authentication%20for%20Exchange%20Online%20and%20verified%20they%20are%20connecting%20that%20way.%20%26nbsp%3BWell%20anytime%20I%20enable%20a%20user%20for%20MFA%20after%20about%20an%20hour%20or%20so%20they%20start%20getting%20prompted%20in%20Outlook%20and%20Skype%20for%20their%20credentials.%20%26nbsp%3BEntering%20them%20do%20not%20work%20nor%20does%20the%20app%20password.%20%26nbsp%3BWhat%20it%20turns%20out%20to%20be%20is%20their%20accounts%20are%20locked%20out%20in%20our%20on%20prem%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe've%20tried%20clearing%20out%20all%20credentials%20and%20that%20works%20sometimes.%20%26nbsp%3BMy%20question%20is%20has%20anyone%20run%20into%20a%20scenario%20such%20as%20this%20where%20the%20users%20account%20locks%20out%20a%20while%20after%20MFA%20is%20enabled%3F%20%26nbsp%3BIf%20so%20did%20you%20find%20a%20resolution%3F%20%26nbsp%3BWe%20can't%20move%20forward%20with%20this%20until%20this%20won't%20happen%20everytime%20we%20enable%20someone.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advanced.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-72778%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-217943%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-217943%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20the%20same%20thing%20going%20on%20with%20Modern%20Authentication.%20I%20believe%20it%20has%20to%20do%20with%20our%20autodiscover%20records%20(SCP%20and%20DNS)%20pointing%20at%20our%20on-prem%202010%20Exchange%20server%20(which%20doesn't%20support%20modern%20auth).%20I'm%20going%20to%20be%20changing%20it%20to%20point%20at%20Office%20365%20autodiscover%20this%20week.%20Hopefully%20it%20fixes%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-212165%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-212165%22%20slang%3D%22en-US%22%3E%3CP%3Esame%20issue%20here.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-206681%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-206681%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20found%20a%20solution.%26nbsp%3B%20Not%20use%20Azure%20MFA%20that%20MS%20has%20to%20offer%20since%20it%20is%20so%20buggy%20and%20lacking%20support%20and%20use%20a%203rd%20party%20solution.%26nbsp%3B%20We%20switched%20to%20Duo%20and%20it%20is%20light%20years%20ahead%20of%20MS%20in%20terms%20of%20functionality%2C%20administration%2C%20reporting%20and%20most%20importantly%20support.%26nbsp%3B%20I%20know%20that's%20an%20expense%20companies%20may%20not%20be%20looking%20for%2C%20but%20we%20were%20tired%20of%20fighting%20all%20the%20issues%20that%20came%20with%20Azure%20MFA%20and%20lack%20of%20support.%26nbsp%3B%20The%20conditional%20access%20policies%20they%20are%20pushing%20people%20towards%20aren't%20mature%20enough%20yet.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-204302%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-204302%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20having%20the%20same%20issue.%3C%2FP%3E%3CP%3EWas%20there%20solution%20on%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196851%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196851%22%20slang%3D%22en-US%22%3EWe%20are%20having%20this%20issue%20also.%20We've%20determined%20that%20it's%20only%20the%20Skype%202016%20client%20having%20the%20issue.%20It%20seems%20to%20be%20related%20to%20the%20initial%20connection%20to%20Skype.%20When%20you%20start%20up%20the%20computer%2C%20restart%20the%20computer%2C%20undock%20and%20redock%20the%20computer%20or%20if%20you%20open%20Skype%20at%20any%20point%20during%20the%20day.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20found%20an%20article%20on%20a%20similar%20issue%20that%20mentioned%20that%20the%20Skype%20client%20tries%20to%20authenticate%20to%20Exchange.%20I%20don't%20know%20what%20credentials%20is%20uses%20to%20connect%2C%20but%20neither%20the%20user's%20network%20password%20or%20the%20App%20Password%20work%20when%20the%20authentication%20boxes%20begin%20after%20opening%20Skype.%3CBR%20%2F%3E%3CBR%20%2F%3EWe're%20still%20looking%20for%20a%20resolution%20to%20this%20issue.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-192585%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-192585%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20seeing%20the%20same%20issue.%20We%20have%20tried%20using%20both%20app%20passwords%20and%20the%20modern%20authentication.%20We%20get%20a%20continual%20password%20request%20loop%20from%20outlook%20that%20eventually%20locks%20the%20user%20account%20out.%26nbsp%3B%20We%20have%20ensured%20that%20exchange%20online%20is%20configured%20to%20allow%20modern%20auth.%20Did%20anyone%20come%20up%20with%20a%20solution.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-73541%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-73541%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20use%20app%20passwords%2C%20that%20are%20generated%20when%20you%20enable%20MFA.%20These%20passwords%20should%20be%20use%20for%20all%20non-web%20apps.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-73053%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-73053%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Nuno%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsers%20usually%20have%20a%20mobile%20device%2C%20but%20we%20go%20through%20and%20enroll%20them%20via%20MS%20Intune%20Company%20Portal%20before%20hand.%20%26nbsp%3BOnce%20the%20user%20has%20MFA%20enabled%20we%20then%20go%20through%20the%20process%20of%20setting%20up%20their%20App%20Password%20which%20is%20then%20entered%20into%20the%20credentials%20section%20of%20the%20mail%20app%20they%20are%20using.%20%26nbsp%3BIt%20usually%20accepts%20this%20part%20and%20contiues%20to%20sync.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20wondering%20if%20this%20part%20is%20done%20too%20soon%20before%20everything%20has%20time%20to%20replicate%20causing%20the%20lockout.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-72841%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Azure%20MFA%20causes%20user%20account%20to%20lockout%20in%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-72841%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Derek%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20the%20user%20have%20any%20other%20devices%20connected%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20seen%20in%20the%20past%2C%20that%20some%20devices%20do%20the%20lockout%2C%20that%20could%20be%20your%20cause.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Derek Hymel
Occasional Contributor

Currently we are in a hybrid environment where we utilize ADConnect to sync passwords up to our Azure AD tenant.  All user mailboxes are on Office 365 with an Exchange 2010 SP3 environment on prem.  We also have Skype for Business on prem as well.  Please don't ask why we are setup this way.   Management and their infinite wisdom.  The users we are testing with have Office 2016 and I've enabled modern authentication for Exchange Online and verified they are connecting that way.  Well anytime I enable a user for MFA after about an hour or so they start getting prompted in Outlook and Skype for their credentials.  Entering them do not work nor does the app password.  What it turns out to be is their accounts are locked out in our on prem AD.

 

We've tried clearing out all credentials and that works sometimes.  My question is has anyone run into a scenario such as this where the users account locks out a while after MFA is enabled?  If so did you find a resolution?  We can't move forward with this until this won't happen everytime we enable someone.

 

Thanks in advanced.

9 Replies

Hi Derek,

 

Do the user have any other devices connected ?

 

I have seen in the past, that some devices do the lockout, that could be your cause.

Highlighted

Hi Nuno,

 

Users usually have a mobile device, but we go through and enroll them via MS Intune Company Portal before hand.  Once the user has MFA enabled we then go through the process of setting up their App Password which is then entered into the credentials section of the mail app they are using.  It usually accepts this part and contiues to sync.

 

I am wondering if this part is done too soon before everything has time to replicate causing the lockout.

 

Thanks

Just use app passwords, that are generated when you enable MFA. These passwords should be use for all non-web apps.

We are seeing the same issue. We have tried using both app passwords and the modern authentication. We get a continual password request loop from outlook that eventually locks the user account out.  We have ensured that exchange online is configured to allow modern auth. Did anyone come up with a solution.

We are having this issue also. We've determined that it's only the Skype 2016 client having the issue. It seems to be related to the initial connection to Skype. When you start up the computer, restart the computer, undock and redock the computer or if you open Skype at any point during the day.

I found an article on a similar issue that mentioned that the Skype client tries to authenticate to Exchange. I don't know what credentials is uses to connect, but neither the user's network password or the App Password work when the authentication boxes begin after opening Skype.

We're still looking for a resolution to this issue.

We are having the same issue.

Was there solution on this.

We found a solution.  Not use Azure MFA that MS has to offer since it is so buggy and lacking support and use a 3rd party solution.  We switched to Duo and it is light years ahead of MS in terms of functionality, administration, reporting and most importantly support.  I know that's an expense companies may not be looking for, but we were tired of fighting all the issues that came with Azure MFA and lack of support.  The conditional access policies they are pushing people towards aren't mature enough yet.

We have the same thing going on with Modern Authentication. I believe it has to do with our autodiscover records (SCP and DNS) pointing at our on-prem 2010 Exchange server (which doesn't support modern auth). I'm going to be changing it to point at Office 365 autodiscover this week. Hopefully it fixes it.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies