Home

Outlook MFA issues, asks for "need password" and get blank screen

%3CLINGO-SUB%20id%3D%22lingo-sub-680421%22%20slang%3D%22en-US%22%3EOutlook%20MFA%20issues%2C%20asks%20for%20%22need%20password%22%20and%20get%20blank%20screen%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-680421%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPremier%20support%20is%20failing%20to%20make%20an%20progress%2C%20I%20have%20had%20a%20ticket%20open%20for%20a%20month%20now%20with%20no%20luck%20(Getting%20escalated%20to%20Tier%203%20this%20morning).%26nbsp%3B%20Here%20is%20the%20scenario%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20Conditional%20Access%20rule%20that%20says%20if%20someone%20accesses%20Office%20365%20(All%20Office)%20from%20a%20Non-trusted%20Location%20require%20MFA.%26nbsp%3B%20For%20most%20people%20it%20works%20fine%26nbsp%3B%20but%20we%20have%20about%2010%25%20of%20the%20people%20who%20run%20into%20a%20really%20weird%20problem%20in%20outlook%20only%2C%20all%20other%20apps%20(Skype%2C%20Word%2C%20etc.)%20work%20fine.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUser%20opens%20outlook%20(2016%20current%20monthly)%20and%20it%20shows%20the%20%22need%20password%22%20screen%20at%20the%20bottom%20and%20no%20email%20is%20sent%2Freceived%2C%20when%20we%20click%20on%20it%20we%20see%20a%20white%20box%20comes%20up%20and%20goes%20away%2C%20it%20does%20not%20give%20them%20the%20option.%26nbsp%3B%20So%20kind%20of%20stuck%20there!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20you%20go%20to%20File-%26gt%3BAccounts%20and%20do%20a%20Sign-out%20and%20then%20try%20to%20sign-back%20in%20it%20comes%20up%20with%20the%20email%20window%20but%20as%20soon%20as%20you%20submit%20the%20email%20the%20window%20goes%20away%20and%20they%20stay%20signed%20out.%26nbsp%3B%20Here%20is%20where%20it%20gets%20interesting%2C%20lets%20say%20you%20put%20someones%20email%20in%20there%20that%20works%20(but%20is%20also%20part%20of%20the%20same%20MFA%20rules)%2C%20it%20takes%20that%20and%20then%20brings%20up%20the%20MFA%20prompt%20for%20original%20user.%26nbsp%3B%20Once%20that%20user%20then%20presses%20approve%20(MS%20authentication%20app%2C%20push%20notifications)%20then%20it%20signs%20that%20user%20in%20and%20email%20starts%20flowing%20again.%26nbsp%3B%20It%20seems%20to%20work%20for%20a%20couple%20of%20weeks%20and%20then%20stops%20again%20with%20the%20same%20prompt.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20put%20in%20all%20the%20normal%20reg%20keys%20to%20enforce%20modern%20auth%3C%2FP%3E%3CP%3E(EnableAdal%20-1%2C%20Alwaysusemsoauthforautodiscovery%20%3D%201%2C%20disableADALaptopWAmOverrride%20-%201%2CDisable%20AADWAM)%26nbsp%3B%20but%20I%20think%20it%20may%20be%20something%20on%20the%20username%20side%20since%20putting%20in%20another%20username%20works.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-680421%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Emfa%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Emodern%20auth%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOutlook%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-680483%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20MFA%20issues%2C%20asks%20for%20%22need%20password%22%20and%20get%20blank%20screen%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-680483%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F142545%22%20target%3D%22_blank%22%3E%40Daniel%20Schmidt%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20what%20you%20explained%20here%20%2C%20it%20seems%20to%20work%20for%20some%20users.%20My%20recommendation%20would%20be%20to%20focus%20on%20the%20client%20end%20and%20anything%20to%20do%20with%20the%20client%20end%20related%20issues.%3CBR%20%2F%3ECompare%20(cross%20check)%20both%20working%20and%20non%20working%20machines.%3CBR%20%2F%3EWhich%20operation%20system%20they%20use%3F%20Which%20build%3F%20X64%20OR%20X86%20Architecture%3F%3CBR%20%2F%3EExact%20version%20of%20Outlook%3F%20Which%20build%3F%3CBR%20%2F%3EAre%20all%20users%20under%20the%20same%20domain%3F%20Same%20GPO%20applied%20to%20all%3F%3CBR%20%2F%3EHave%20you%20checked%20the%20credential%20manager%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20happy%20here%20to%20support%20and%20help%26nbsp%3B%20you%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThank%20you%3CBR%20%2F%3EDav%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-680518%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20MFA%20issues%2C%20asks%20for%20%22need%20password%22%20and%20get%20blank%20screen%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-680518%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F340070%22%20target%3D%22_blank%22%3E%40Dav1988%3C%2FA%3E%26nbsp%3BThank%20you!%26nbsp%3B%20Yes%20all%20build%20via%20SCCM%2C%20same%20image%2C%20same%20department%2FOU%20so%20all%20same%20policies.%26nbsp%3B%20Tried%20to%20clear%20credential%20manager%2C%20even%20hapening%20brand%20new%20builds%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-680615%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20MFA%20issues%2C%20asks%20for%20%22need%20password%22%20and%20get%20blank%20screen%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-680615%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F142545%22%20target%3D%22_blank%22%3E%40Daniel%20Schmidt%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20you%20tried%20%22Microsoft%20Support%20and%20Recovery%20Assistant%22%20on%20a%20non%20working%20machine%20on%20an%20external%20network%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDisable%20MFA%20for%20the%20non%20working%20user.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3Eopened%20Outlook%20---%26gt%3B%20Clicked%20File%20----%26gt%3B%20Office%20Account%20---%26gt%3Bsign%20out%20of%20all%20accounts.%3C%2FP%3E%3CP%3EEnable%20MFA%20for%20the%20user%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3CP%3EDav%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1000400%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20MFA%20issues%2C%20asks%20for%20%22need%20password%22%20and%20get%20blank%20screen%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1000400%22%20slang%3D%22en-US%22%3EWere%20you%20able%20to%20resolve%20your%20issue%3F%20I%20have%20same%20situation%20happening%20today%20for%20the%20first%20time.%3C%2FLINGO-BODY%3E
Daniel Schmidt
Contributor

Hello everyone,

 

Premier support is failing to make an progress, I have had a ticket open for a month now with no luck (Getting escalated to Tier 3 this morning).  Here is the scenario

 

We have Conditional Access rule that says if someone accesses Office 365 (All Office) from a Non-trusted Location require MFA.  For most people it works fine  but we have about 10% of the people who run into a really weird problem in outlook only, all other apps (Skype, Word, etc.) work fine.

 

User opens outlook (2016 current monthly) and it shows the "need password" screen at the bottom and no email is sent/received, when we click on it we see a white box comes up and goes away, it does not give them the option.  So kind of stuck there!

 

When you go to File->Accounts and do a Sign-out and then try to sign-back in it comes up with the email window but as soon as you submit the email the window goes away and they stay signed out.  Here is where it gets interesting, lets say you put someones email in there that works (but is also part of the same MFA rules), it takes that and then brings up the MFA prompt for original user.  Once that user then presses approve (MS authentication app, push notifications) then it signs that user in and email starts flowing again.  It seems to work for a couple of weeks and then stops again with the same prompt.

 

We put in all the normal reg keys to enforce modern auth

(EnableAdal -1, Alwaysusemsoauthforautodiscovery = 1, disableADALaptopWAmOverrride - 1,Disable AADWAM)  but I think it may be something on the username side since putting in another username works.

4 Replies

Hi@Daniel Schmidt 

 

From what you explained here , it seems to work for some users. My recommendation would be to focus on the client end and anything to do with the client end related issues.
Compare (cross check) both working and non working machines.
Which operation system they use? Which build? X64 OR X86 Architecture?
Exact version of Outlook? Which build?
Are all users under the same domain? Same GPO applied to all?
Have you checked the credential manager?

 

We are happy here to support and help  you :)


Thank you
Dav,

 

 

 

 

 

Highlighted

@Deleted Thank you!  Yes all build via SCCM, same image, same department/OU so all same policies.  Tried to clear credential manager, even hapening brand new builds

Hi@Daniel Schmidt 

 

Have you tried "Microsoft Support and Recovery Assistant" on a non working machine on an external network?

 

Disable MFA for the non working user.

opened Outlook ---> Clicked File ----> Office Account --->sign out of all accounts.

Enable MFA for the user

 

Thank you

Dav,

 

 

Were you able to resolve your issue? I have same situation happening today for the first time.
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies