SOLVED

Disabled teams account can still log in

%3CLINGO-SUB%20id%3D%22lingo-sub-1285134%22%20slang%3D%22en-US%22%3EDisabled%20teams%20account%20can%20still%20log%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285134%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20i%20am%20noticing%20a%20behaviour%20that%20i%20can%20reproduce%20right%20now%20that%20is%20very%20disturbing%20to%20my%20users%2Fmanagers.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20having%20to%20terminate%20people%20due%20to%20covid%2C%20but%20we%20want%20to%20offer%20the%20ability%20for%20them%20to%20come%20back%20one%20day%2C%20so%20the%20accounts%20are%20not%20being%20deleted%2C%20merely%20disabled.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20noticed%20that%20if%20a%20user%20is%20still%20logged%20into%20teams%2C%20even%20though%20their%20AD%20account%20is%20disabled%2C%20and%20office365%20says%20%22blocked%22%20they%20can%20still%20get%20in%20and%20attend%20team%20meetings!%20i%20can%20even%20send%20an%20email%20calendar%20invite%20to%20a%20meeting%20and%20the%20user%20can%20join%20that%20meeting.%20Tested%201%20hour%20after%20they%20were%20disabled%20in%20AD%20and%20blocked%20in%20office%20365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eobviously%20this%20is%20a%20huge%20problem!!!%20i%20have%20read%20other%20posts%20that%20an%20%22active%20sync%22%20connection%20may%20be%20left%20open%20for%20possibly%20days.%20Is%20this%20what%20is%20happening%3F%20it%20seems%20more%20specific%20to%20exchange%20though.%3C%2FP%3E%3CP%3Eref%3A%20%3CA%20href%3D%22https%3A%2F%2Fold.reddit.com%2Fr%2Fsysadmin%2Fcomments%2F8jlqmn%2Fterminated_employee_sent_email_an_hour_after%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fold.reddit.com%2Fr%2Fsysadmin%2Fcomments%2F8jlqmn%2Fterminated_employee_sent_email_an_hour_after%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20a%20setting%20somewhere%20or%20a%20way%20to%20force%20disabled%20users%20to%20logout%3F%20i%20even%20changed%20the%20users%20password%20and%20they%20can%20still%20open%20teams%20and%20it%20just%20auto%20logs%20them%20in.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1285134%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ELogin%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1285278%22%20slang%3D%22en-US%22%3ERe%3A%20Disabled%20teams%20account%20can%20still%20log%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285278%22%20slang%3D%22en-US%22%3E%3CP%3EDisabling%20a%20user%20doesn't%20immediately%20terminate%20access%2C%20this%20has%20been%20discussed%20in%20numerous%20threads%2Fblog%20posts%20which%20you%20can%20look%20up%20for%20additional%20details.%20TL%3BDR%20version%20is%20that%20users%20will%20have%20access%20until%20the%20tokens%20expire%2C%20and%20if%20you%20want%20to%20speed%20things%20up%20a%20bit%20you%20can%20revoke%20tokens%20via%20the%20O365%20admin%20portal%20or%20the%26nbsp%3B%3CSPAN%20style%3D%22color%3A%20%23000000%3B%20font-family%3A%20Monaco%2C%20Consolas%2C%20'Bitstream%20Vera%20Sans%20Mono'%2C%20'Courier%20New'%2C%20Courier%2C%20monospace%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant-ligatures%3A%20normal%3B%20font-variant-caps%3A%20normal%3B%20font-weight%3A%20400%3B%20letter-spacing%3A%20normal%3B%20orphans%3A%202%3B%20text-align%3A%20left%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20white-space%3A%20pre%3B%20widows%3A%202%3B%20word-spacing%3A%200px%3B%20-webkit-text-stroke-width%3A%200px%3B%20background-color%3A%20%23ffffff%3B%20text-decoration-style%3A%20initial%3B%20text-decoration-color%3A%20initial%3B%20display%3A%20inline%20!important%3B%20float%3A%20none%3B%22%3ERevoke-AzureADUserAllRefreshToken%3C%2FSPAN%3E%20cmdlet.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1285322%22%20slang%3D%22en-US%22%3ERe%3A%20Disabled%20teams%20account%20can%20still%20log%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285322%22%20slang%3D%22en-US%22%3E%3CP%3Elooks%20like%20i%20was%20able%20to%20block%20the%20attempt%20after%20some%20time%20now%20with%20the%20following%20command%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%3ERevoke-AzureADUserAllRefreshToken%20-ObjectId%20user%40domain.ca%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eref%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.petri.com%2Fblocking-access-office-365-user%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petri.com%2Fblocking-access-office-365-user%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eof%20course%20you%20have%20to%20connect%20to%20azure%20first%20with%20powershell.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%3EInstall-Module%20AzureAD%20-Force%3CBR%20%2F%3EImport-Module%20AzureAD%3CBR%20%2F%3EConnect-AzureAD%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1285333%22%20slang%3D%22en-US%22%3ERe%3A%20Disabled%20teams%20account%20can%20still%20log%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285333%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F315058%22%20target%3D%22_blank%22%3E%40windows2000%3C%2FA%3EA%20quick%20workaround%20for%20this%20solution%20could%20be%20turning%20off%20their%20Teams%20License%20so%20they%20are%20not%20able%20to%20use%20Microsoft%20team%20in%20desktop%2FMobile%2Fcould%20version%20since%20if%20they%20try%20to%20login%20they%20will%20get%20no%20license%20%2F%20active%20Team%20license.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20hope%20this%20will%20work%20and%20resolve%20your%20issue!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1285346%22%20slang%3D%22en-US%22%3ERe%3A%20Disabled%20teams%20account%20can%20still%20log%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285346%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3EIf%20it%20was%20in%20%22numerous%20threads%22%20i%20would%20have%20found%20it%20this%20morning%20easily%20by%20searching.%20There%20was%20nothing%20specific%20to%20teams.%20Even%20this%20command%20I%20found%20is%20for%20azure%20AD.%20I%20would%20think%20office%20365%20would%20behave%20better.%20A%20blocked%20user%20is%20a%20blocked%20user%20and%20therefor%20should%20force%20a%20disconnect%20at%20that%20time.%20Stupid%20that%20i%20have%20to%20run%20manual%20commands.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1476557%22%20slang%3D%22en-US%22%3ERe%3A%20Disabled%20teams%20account%20can%20still%20log%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1476557%22%20slang%3D%22en-US%22%3E%3CP%3EI%20tried%20that%20about%20three%20weeks%20ago%20and%20it%20worked%2C%20I%20tried%20it%20again%20yesterday%20and%20it%20didn't%20work.%20I%20think%20you%20need%20to%20revoke%20licences%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1476682%22%20slang%3D%22en-US%22%3ERe%3A%20Disabled%20teams%20account%20can%20still%20log%20in%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1476682%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20most%20secure%20way%20to%20manage%20this%20would%20be%20to%20change%20their%20passwords%20at%20the%20same%20time%20when%20blocking%20the%20accounts.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hey i am noticing a behaviour that i can reproduce right now that is very disturbing to my users/managers.

 

We are having to terminate people due to covid, but we want to offer the ability for them to come back one day, so the accounts are not being deleted, merely disabled.

 

I have noticed that if a user is still logged into teams, even though their AD account is disabled, and office365 says "blocked" they can still get in and attend team meetings! i can even send an email calendar invite to a meeting and the user can join that meeting. Tested 1 hour after they were disabled in AD and blocked in office 365.

 

obviously this is a huge problem!!! i have read other posts that an "active sync" connection may be left open for possibly days. Is this what is happening? it seems more specific to exchange though.

ref: https://old.reddit.com/r/sysadmin/comments/8jlqmn/terminated_employee_sent_email_an_hour_after/

 

Is there a setting somewhere or a way to force disabled users to logout? i even changed the users password and they can still open teams and it just auto logs them in.

 

 

6 Replies
Highlighted

Disabling a user doesn't immediately terminate access, this has been discussed in numerous threads/blog posts which you can look up for additional details. TL;DR version is that users will have access until the tokens expire, and if you want to speed things up a bit you can revoke tokens via the O365 admin portal or the Revoke-AzureADUserAllRefreshToken cmdlet.

Highlighted
Best Response confirmed by windows2000 (Occasional Contributor)
Solution

looks like i was able to block the attempt after some time now with the following command:

 

Revoke-AzureADUserAllRefreshToken -ObjectId user@domain.ca

 

ref: https://www.petri.com/blocking-access-office-365-user

 

of course you have to connect to azure first with powershell.

 

Install-Module AzureAD -Force
Import-Module AzureAD
Connect-AzureAD

 

Highlighted

@windows2000A quick workaround for this solution could be turning off their Teams License so they are not able to use Microsoft team in desktop/Mobile/could version since if they try to login they will get no license / active Team license.

 

I hope this will work and resolve your issue!

Highlighted

@Vasil MichevIf it was in "numerous threads" i would have found it this morning easily by searching. There was nothing specific to teams. Even this command I found is for azure AD. I would think office 365 would behave better. A blocked user is a blocked user and therefor should force a disconnect at that time. Stupid that i have to run manual commands.

Highlighted

I tried that about three weeks ago and it worked, I tried it again yesterday and it didn't work. I think you need to revoke licences

Highlighted

The most secure way to manage this would be to change their passwords at the same time when blocking the accounts.