Outlook - Second 365 account-different tenant- fails after both MFA activated

%3CLINGO-SUB%20id%3D%22lingo-sub-196308%22%20slang%3D%22en-US%22%3EOutlook%20-%20Second%20365%20account-different%20tenant-%20fails%20after%20both%20MFA%20activated%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196308%22%20slang%3D%22en-US%22%3E%3CP%3ESo%20I%20have%20admin%20accounts%20for%20two%20companies.%26nbsp%3B%20A%20main%20account%20which%20my%20machine%20is%20all%20setup%20with%20and%20our%20new%20parent%20company%20account.%26nbsp%3B%20After%20turning%20on%20MFA%20for%20both%20accounts%2C%20my%20Outlook%20stopped%20liking%20the%20second%20account%20-%20different%20tenant%2Fdomain.%26nbsp%3B%20Removing%20the%20second%20account%20and%20attempting%20to%20re-add%20fails.%26nbsp%3B%20It%20asks%20for%20a%20username%20and%20password%20in%20the%20old%20way%20and%20does%20not%20bring%20up%20the%20new%20way%20with%20the%20MFA%20etc.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOthers%20at%20the%20parent%20company%20are%20running%20MFA%20and%20everything%20else%20works(iphone%20mail%2C%20etc).%26nbsp%3B%20Was%20going%20to%20powershell%20into%20them%20to%20verify%20they%20indeed%20had%20that%20one%20thing%20you%20needed%20on%20and%20went%20down%20another%20rabbit%20hole%20I%20posted%20elsewhere%20about.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThoughts%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%2C%20if%20the%20answer%20is%20to%20nuke%20the%20outlook%20profile%2C%20are%20there%20other%20things%20I%20need%20to%20make%20sure%20I%20also%20nuke%20in%20say%2C%20credential%20manager%3F%26nbsp%3B%20Don't%20want%20to%20wait%20through%20a%20re-sync%20for%20no%20reason%20if%20I%20need%20to%20do%20other%20things.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-196308%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Emfa%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMulti-tenant%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOutlook%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-197011%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20-%20Second%20365%20account-different%20tenant-%20fails%20after%20both%20MFA%20activated%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-197011%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20asked%20them%20and%20haven't%20heard%20back%20about%20that.%26nbsp%3B%20Since%20I%20was%20unable%20to%20powershell%20into%20them(my%20other%20post%20in%20a%20different%20section%20of%20this%20community%20site)%2C%20I%20couldn't%20check%20myself.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20shut%20off%202-factor%20for%20my%20account%20with%20them%20in%20the%20meantime.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThey%20currently%20use%20Dirsync%20with%20their%20on-prem%20AD%20and%20have%20told%20me%20that%20they%20all%20had%20to%20use%20an%20app%20password%20for%20their%20Outlook%20with%202-factor%20on.%26nbsp%3B%20I%20guess%20that%20answers%20that%20so%20I%20will%20try%202-factor%20again%20and%20use%20an%20app%20password%20instead.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20suppose%20they%20will%20be%20able%20to%20use%20modern%20auth%20once%20they%20get%20AD%20Connect%20and%20MFA%20Server%20going%20with%20passthough%20authentication.%26nbsp%3B%20But%20Dirsync%20was%20just%20a%20more%20simple%20sync%20so%20I%20still%20don't%20know%20why%20modern%20auth%20wouldn't%20work%20for%20them%2C%20or%20why%20it%20works%20for%20roughly%20the%20first%20day%2C%20then%20fails%20completely%20-%20and%20iphone%20mail%20still%20works%20modern%20auth%20for%20that%20tenant.%26nbsp%3B%20Who%20knows.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196630%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20-%20Second%20365%20account-different%20tenant-%20fails%20after%20both%20MFA%20activated%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196630%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20Modern%20authentication%20(and%20MAPI%2FHTTP)%20enabled%20in%20that%20second%20account's%20tenant%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196332%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20-%20Second%20365%20account-different%20tenant-%20fails%20after%20both%20MFA%20activated%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196332%22%20slang%3D%22en-US%22%3E%3CP%3EWin%2010%201709%2C%20Outlook%202016%2F365%201804(Build%209226.2156)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20initally%20I%20activated%20MFA%20on%20my%20main%20account.%3C%2FP%3E%3CP%3EMy%20main%20account%20went%20completely%20fine%2C%20it%20prompted%20my%20shortly%20after%20doing%20turning%20on%20MFA%20with%20a%20login%20screen%20so%20logged%20in%2C%20then%20approved%20via%20MS%20Auth%20app%20for%20iphone.%3C%2FP%3E%3CP%3ENext%2C%20I%20activated%20MFA%20on%20the%20second%20account%20on%20the%20other%20domain%2Ftenant.%3C%2FP%3E%3CP%3EThis%20also%20went%20fine%2C%20and%20did%20the%20same%20as%20the%20previous%20account.%3C%2FP%3E%3CP%3EThat%20was%20yesterday.%3C%2FP%3E%3CP%3EToday%2C%20launch%20outlook%20and%20am%20presented%20with%20an%20older%20style%20username%2Fpassword%20box%20for%20the%20second%20account.%26nbsp%3B%20I%20put%20that%20in%20and%20it%20errors.%26nbsp%3B%20First%20account%20is%20still%20fine.%3C%2FP%3E%3CP%3EI%20remove%20the%20second%20account%2C%20thinking%20I%20would%20just%20have%20to%20re-add%20it.%26nbsp%3B%20(I%20had%20to%20do%20this%20for%20both%20on%20my%20iphone%20for%20some%20reason)%3C%2FP%3E%3CP%3EI%20go%20to%20re-add%2C%20File%26gt%3BAccount%20Settings%26gt%3BNew%3C%2FP%3E%3CP%3EPut%20the%20second%20account%20e-mail%20in%2C%20it%20then%20comes%20up%20with%20the%20older%20style%20box%20again%2C%20then%20fails%20with%20a%20%22Something%20went%20wrong%22%20%22Something%20went%20wrong%20and%20Outlook%20couldn't%20set%20up%20your%20account%22%20with%20no%20specific%20code%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20that%20KB%20article%20still%20apply%3F%26nbsp%3B%20It's%20none%20of%20the%206%20symptoms.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196320%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20-%20Second%20365%20account-different%20tenant-%20fails%20after%20both%20MFA%20activated%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196320%22%20slang%3D%22en-US%22%3E%3CP%3EVersion%20of%20Outlook%3F%20And%20of%20Windows%3F%20There%20is%20difference%20in%20behavior%20in%20how%20the%20W10%20components%20(WAM)%20handle%20authentication%20compared%20to%20Office%20(ADAL)%2C%20and%20you%20might%20be%20seeing%20just%20that.%20Try%20the%20workaround%20from%20this%20KB%20article%3A%3C%2FP%3E%0A%3CP%20lang%3D%22x-none%22%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-my%2Fhelp%2F4025962%2Fcan-t-sign-in-after-update-to-office-2016-build-16-0-7967-on-windows-1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CFONT%20color%3D%22%230066cc%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-my%2Fhelp%2F4025962%2Fcan-t-sign-in-after-update-to-office-2016-build-16-0-7967-on-windows-1%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2381167%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20-%20Second%20365%20account-different%20tenant-%20fails%20after%20both%20MFA%20activated%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2381167%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F149411%22%20target%3D%22_blank%22%3E%40Cecil%20C.%20Achord%3C%2FA%3E%26nbsp%3BDid%20you%20ever%20find%20a%20resolution%20to%20this%3F%26nbsp%3B%20I%20too%20am%20having%20a%20very%20similar%20problem%20once%20adding%20enabling%20MFA%20on%20another%20email%20address%20within%20Outlook%20from%20a%20different%20Tenant.%26nbsp%3B%20Once%20I%20set%20it%20up%20it%20initially%20looked%20to%20be%20working%20but%20I%20noticed%20a%20few%20hours%20later%20all%20of%20the%20users%20that%20shows%20their%20MFA%20as%20%22Enforced%22%20they%20could%20not%20access%20their%20email.%26nbsp%3B%20I%20would%20prompt%20them%20for%20their%20password%20but%20they'd%20never%20get%20logged%20in.%26nbsp%3B%20They%20did%20report%20that%20it%20was%20working%20fine%20on%20their%20cell%20phones%20though.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

So I have admin accounts for two companies.  A main account which my machine is all setup with and our new parent company account.  After turning on MFA for both accounts, my Outlook stopped liking the second account - different tenant/domain.  Removing the second account and attempting to re-add fails.  It asks for a username and password in the old way and does not bring up the new way with the MFA etc.

 

Others at the parent company are running MFA and everything else works(iphone mail, etc).  Was going to powershell into them to verify they indeed had that one thing you needed on and went down another rabbit hole I posted elsewhere about.

 

Thoughts?

 

Also, if the answer is to nuke the outlook profile, are there other things I need to make sure I also nuke in say, credential manager?  Don't want to wait through a re-sync for no reason if I need to do other things.

5 Replies

Version of Outlook? And of Windows? There is difference in behavior in how the W10 components (WAM) handle authentication compared to Office (ADAL), and you might be seeing just that. Try the workaround from this KB article:

https://support.microsoft.com/en-my/help/4025962/can-t-sign-in-after-update-to-office-2016-build-16-...

Win 10 1709, Outlook 2016/365 1804(Build 9226.2156)

 

So, initally I activated MFA on my main account.

My main account went completely fine, it prompted my shortly after doing turning on MFA with a login screen so logged in, then approved via MS Auth app for iphone.

Next, I activated MFA on the second account on the other domain/tenant.

This also went fine, and did the same as the previous account.

That was yesterday.

Today, launch outlook and am presented with an older style username/password box for the second account.  I put that in and it errors.  First account is still fine.

I remove the second account, thinking I would just have to re-add it.  (I had to do this for both on my iphone for some reason)

I go to re-add, File>Account Settings>New

Put the second account e-mail in, it then comes up with the older style box again, then fails with a "Something went wrong" "Something went wrong and Outlook couldn't set up your account" with no specific code

 

Would that KB article still apply?  It's none of the 6 symptoms.

Is Modern authentication (and MAPI/HTTP) enabled in that second account's tenant?

I have asked them and haven't heard back about that.  Since I was unable to powershell into them(my other post in a different section of this community site), I couldn't check myself.

 

I have shut off 2-factor for my account with them in the meantime.

 

They currently use Dirsync with their on-prem AD and have told me that they all had to use an app password for their Outlook with 2-factor on.  I guess that answers that so I will try 2-factor again and use an app password instead.

 

I suppose they will be able to use modern auth once they get AD Connect and MFA Server going with passthough authentication.  But Dirsync was just a more simple sync so I still don't know why modern auth wouldn't work for them, or why it works for roughly the first day, then fails completely - and iphone mail still works modern auth for that tenant.  Who knows.

@Cecil C. Achord Did you ever find a resolution to this?  I too am having a very similar problem once adding enabling MFA on another email address within Outlook from a different Tenant.  Once I set it up it initially looked to be working but I noticed a few hours later all of the users that shows their MFA as "Enforced" they could not access their email.  I would prompt them for their password but they'd never get logged in.  They did report that it was working fine on their cell phones though.