User unable to login to Office 365 email either through portal or Outlook

%3CLINGO-SUB%20id%3D%22lingo-sub-1085687%22%20slang%3D%22en-US%22%3EUser%20unable%20to%20login%20to%20Office%20365%20email%20either%20through%20portal%20or%20Outlook%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1085687%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22content%20wysiwyg-content%22%3EUser%20(User1%40domain.com.au)%20started%20getting%20prompt%20for%20password%20on%20Outlook%20so%20our%20service%20desk%20reset%20password%20for%20the%20user.%3CBR%20%2F%3EAfter%20that%20if%20the%20user%20goes%20to%20office%20365%20portal%20to%20login%20then%20user%20gets%20a%20prompt%20that%20they%20are%20being%20redirected%20to%20organisation's%20login%20and%20get%20prompted%20for%20the%20username%20and%20password%20in%20the%20pop-up%20prompt.%3CBR%20%2F%3EAfter%20entering%20the%20details%20the%20portal%20just%20returns%20back%20to%20the%20O365%20login%20prompt%20again.%3CBR%20%2F%3E%3CBR%20%2F%3EUser%20password%20has%20been%20reset%20again%20since%20then%20and%20still%20the%20same%20happens.%3CBR%20%2F%3EDelta%20sync%20was%20forced%20on%20the%20Azure%20AD%20Connect.%20Logs%20on%20O365%20side%20suggest%20the%20sync%20happened%20successfully%20for%20this%20user.%3CBR%20%2F%3E%3CBR%20%2F%3EAzure%20AD%20connect%20is%20configured%20to%20use%20Federated%20authentication%20through%20ADFS%20server%20farm.%3CBR%20%2F%3EBefore%20we%20reset%20the%20password%20for%20the%20second%20time%20we%20could%20see%20event%20ID%20342%20on%20the%20ADFS%20server%20stating%20the%20following%3A-%3CBR%20%2F%3E%3CEM%3ESystem.IdentityModel.Tokens.SecurityTokenValidationException%3A%20User1%40domain.com.au%20---%26gt%3B%20System.ComponentModel.Win32Exception%3A%20The%20user%20name%20or%20password%20is%20incorrect.%3C%2FEM%3E%3CBR%20%2F%3E%3CBR%20%2F%3EBut%20after%20resetting%20the%20password%20we%20don't%20even%20see%20that%20error%20on%20ADFS%20server.%3CBR%20%2F%3EUser%20can%20log%20onto%20even%20the%20Citrix%20portal%20without%20any%20problem%20so%20the%20password%20is%20correct.%3CBR%20%2F%3ELogin%20has%20been%20tried%20on%20multiple%20computers%20as%20well%20to%20rule%20out%20browser%20issues.%3CBR%20%2F%3E%3CBR%20%2F%3EWhat%20could%20be%20the%20issue%3F%3CBR%20%2F%3EAnd%20what%20steps%20can%20we%20take%20to%20troubleshoot%20further.%3C%2FDIV%3E%3CDIV%20class%3D%22rating%20disabled%22%3E%3CDIV%20class%3D%22member-rating%22%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1085687%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Contributor
User (User1@domain.com.au) started getting prompt for password on Outlook so our service desk reset password for the user.
After that if the user goes to office 365 portal to login then user gets a prompt that they are being redirected to organisation's login and get prompted for the username and password in the pop-up prompt.
After entering the details the portal just returns back to the O365 login prompt again.

User password has been reset again since then and still the same happens.
Delta sync was forced on the Azure AD Connect. Logs on O365 side suggest the sync happened successfully for this user.

Azure AD connect is configured to use Federated authentication through ADFS server farm.
Before we reset the password for the second time we could see event ID 342 on the ADFS server stating the following:-
System.IdentityModel.Tokens.SecurityTokenValidationException: User1@domain.com.au ---> System.ComponentModel.Win32Exception: The user name or password is incorrect.

But after resetting the password we don't even see that error on ADFS server.
User can log onto even the Citrix portal without any problem so the password is correct.
Login has been tried on multiple computers as well to rule out browser issues.

What could be the issue?
And what steps can we take to troubleshoot further.
 
0 Replies