<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Identity &amp; Authentication topics</title>
    <link>https://techcommunity.microsoft.com/t5/identity-authentication/bd-p/IdentityAuth</link>
    <description>Identity &amp; Authentication topics</description>
    <pubDate>Sat, 13 Jun 2026 17:05:46 GMT</pubDate>
    <dc:creator>IdentityAuth</dc:creator>
    <dc:date>2026-06-13T17:05:46Z</dc:date>
    <item>
      <title>How do I get support so I don't loose my account?</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-get-support-so-i-don-t-loose-my-account/m-p/4524019#M2579</link>
      <description>&lt;P&gt;I have a business 365 account but changed address and so my credit card payments stopped.&amp;nbsp; However, I can't log in to my account because I also have an authentication problem (my authentication app on iPhone is still working but the entry for this account has gone and there is a new one called "Microsoft Entra ID" but when I go to get the authentication code this "Entra ID" authenticator does not produce it).&lt;/P&gt;&lt;P&gt;To get help from Microsoft it always asks for authentication.&amp;nbsp; I would like to keep this account and start paying again but I can't find a way to get help to fix the authentication problem because raising a ticket or talking to an agent requires authentication.&lt;/P&gt;&lt;P&gt;I got my final warning email today saying&lt;/P&gt;&lt;H1&gt;Warning—your online services will be deprovisioned and your data deleted in seven days&lt;/H1&gt;&lt;P&gt;There must be some way to get a call from Microsoft so I don't loose my account and all my data?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 12:37:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-get-support-so-i-don-t-loose-my-account/m-p/4524019#M2579</guid>
      <dc:creator>workless</dc:creator>
      <dc:date>2026-05-29T12:37:31Z</dc:date>
    </item>
    <item>
      <title>Microsoft Authenticator führt Wiederherstellung nicht aus</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-authenticator-f%C3%BChrt-wiederherstellung-nicht-aus/m-p/4523300#M2577</link>
      <description>&lt;P&gt;Ich möchte die App auf meinem neuen Handy weiter nutzen und habe dafür auf dem alten Gerät eine Sicherung erstellt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wenn ich nun die App auf dem neuen Handy einrichten möchte, bekomme ich eine Fehlermeldung, daß es angeblich keine Sicherung gibt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ich benötige die App dringend für die MFA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kann jemand helfen?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 13:13:06 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-authenticator-f%C3%BChrt-wiederherstellung-nicht-aus/m-p/4523300#M2577</guid>
      <dc:creator>Marko13059</dc:creator>
      <dc:date>2026-05-27T13:13:06Z</dc:date>
    </item>
    <item>
      <title>How do I find the account linked to an Office Home &amp; Student 2013 key?</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-find-the-account-linked-to-an-office-home-student-2013/m-p/4522747#M2575</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Microsoft's after-sales service redirected me here because they no longer provide updates for this type of product, nor even security support.&lt;/P&gt;&lt;P&gt;I have two Microsoft accounts. However, when I try to reconnect my key to one of them, it tells me the key is already linked to another Microsoft account. But which one?! How can I find that account or regain ownership of my Office key ?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2026 15:35:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-find-the-account-linked-to-an-office-home-student-2013/m-p/4522747#M2575</guid>
      <dc:creator>Kévin</dc:creator>
      <dc:date>2026-05-25T15:35:35Z</dc:date>
    </item>
    <item>
      <title>Web-signin 3rd party IDP not working</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/web-signin-3rd-party-idp-not-working/m-p/4518433#M2572</link>
      <description>&lt;P&gt;We have a working Entra ID SAML federation to a third-party IdP that uses FIDO2/WebAuthn (IdP as Relying Party) for browser sign-in, and we are trying to use the same federation through Windows Web sign-in on an Entra-joined Windows 11 device — but the IdP page loads blank in the WebView and Microsoft-Windows-WebAuthN/Operational records zero events, while the same security key works fine for FIDO2 sign-in with login.microsoft.com as RP on the same device.&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;- Is WebAuthn brokering to third-party Relying Parties inside the Web sign-in WebView supported?&lt;/P&gt;&lt;P&gt;- If not, is it on the roadmap?&lt;/P&gt;&lt;P&gt;- What is the supported architectural path for delivering passwordless Windows sign-in using a federated IdP's own FIDO2/WebAuthn credentials, given Graph API passkey provisioning is Beta-only?&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 11:55:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/web-signin-3rd-party-idp-not-working/m-p/4518433#M2572</guid>
      <dc:creator>GeorgJ</dc:creator>
      <dc:date>2026-05-11T11:55:40Z</dc:date>
    </item>
    <item>
      <title>How to target Azure VPN (Microsoft-Registered) app with Conditional Access Policies?</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/how-to-target-azure-vpn-microsoft-registered-app-with/m-p/4516691#M2568</link>
      <description>&lt;P&gt;I have an Azure Point-to-Site VPN Gateway configured using the &lt;STRONG&gt;Microsoft-registered Azure VPN Client App ID&lt;/STRONG&gt; (Audience value: c632b3df-fb67-4d84-bdcf-b95ad541b5c8). Everything is working correctly for our users. The issue I am having is that anyone with an Entra account can connect to the VPN and I want to restrict this with a blocking Conditional access policy. I do not want to create a custom app registration, because then I will have to change the 'audience' value on the app gateway and all user's will need to modify their VPN clients.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is I need to target the Microsoft-registered Azure VPN app in a&amp;nbsp;&lt;STRONG&gt;Conditional Access policy&lt;/STRONG&gt; but it does not appear in my Enterprise Applications list or in the CA app picker when searching.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My questions:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Why does the Microsoft-registered app not automatically create a service principal in my tenant the way other Microsoft apps do?&lt;/LI&gt;&lt;LI&gt;Is there a supported way to make it appear in the CA app picker without creating a custom app registration or changing the gateway Audience value?&lt;/LI&gt;&lt;LI&gt;Has anyone successfully targeted c632b3df-fb67-4d84-bdcf-b95ad541b5c8 in a CA policy while keeping it as the gateway Audience value?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks for the assistance here&lt;/P&gt;</description>
      <pubDate>Sun, 03 May 2026 19:48:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/how-to-target-azure-vpn-microsoft-registered-app-with/m-p/4516691#M2568</guid>
      <dc:creator>mmarchand</dc:creator>
      <dc:date>2026-05-03T19:48:53Z</dc:date>
    </item>
    <item>
      <title>Broken Account Recovery (discontinued product)</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/broken-account-recovery-discontinued-product/m-p/4512765#M2563</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;We have the MSFT Office Family plan which has the now discontinued custom domain support that used to be an option as a "Premium" feature. Back in August we upgraded the phone of one of the account members on the family plan and lost connection to their MS Office account with the only device that was accessing to the account (the phone with access was reset as part of the upgrade/trade in process). I have tried the account recovery form and it simply doesn't work. I have tried to explain to MSFT support that the tool is broken but can't get anywhere. For the account in question we have an Outlook email client (with non working password) that has a cache of all of the email until loss of access occurred. So when I do the account recovery form, I have name, DOB, region, past passwords and data for all fields including sent email Id's and send subjects, But every time the MSFT recovery mechanism says "Unfortunately, we have determined that the information provided was not sufficient...". WTF.&lt;/P&gt;&lt;P&gt;Every time I contact MSFT support I get the same answer, an explanation of the point system used to reset the the account. Same steps to recover....based on this, the recovery should work...yet it doesn't. I have tried somewhere 50+ attempts now over the last 9 months. I even have a contact who is VP level at MSFT who sponsored a support ticket internally but that just ended up with the support person sending me a link to the account recovery form and closed the ticket without looking in the details of the ticket.&lt;/P&gt;&lt;P&gt;I can't modify / add a new account as MSFT has as a discontinued product no longer allow members to add/change id's. So I'm locked at the current user set. I have created another email address by saving the cached data to OLM file and importing via the Outlook client but that doesn't restore use of the @mydomain.com for that person. I even retained a lawyer who send a demand to MSFT legal...but the email address didn't go anywhere so at the point of needing to do this on headed paper/send via snail mail.&lt;/P&gt;&lt;P&gt;Does anyone have any idea how to get through to MSFT explain the recovery tool is broken? I assume there are so few accounts using custom domains pin family plans that they simply don't test this recovery path.&lt;/P&gt;&lt;P&gt;At this point without some internal guidance is a) lawyer and force a demand for password reset b) give up, ditch all of the users using the custom domain, configure an alias for all of the accounts and then change my MX record to a company doing email forwarding and then forward to the new/old legacy accounts (i.e. the ones with the &lt;A class="lia-external-url" href="mailto:email address removed for privacy reasons)" target="_blank"&gt;mailto:email address removed for privacy reasons)&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 04:18:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/broken-account-recovery-discontinued-product/m-p/4512765#M2563</guid>
      <dc:creator>anewham</dc:creator>
      <dc:date>2026-04-20T04:18:08Z</dc:date>
    </item>
    <item>
      <title>Authenticator</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/authenticator/m-p/4510865#M2561</link>
      <description>&lt;P&gt;I need your help.&lt;/P&gt;&lt;P&gt;I broke my Iphone and after replacing it I cannot log into my Microsoft admin account since the authentication app is not working.&lt;/P&gt;&lt;P&gt;I am the administrator of my own small business account.&amp;nbsp; I have gone through all the account recovery help but neither the send text to my number or call my number works.&lt;/P&gt;&lt;P&gt;All online support depends on having an the code from the Authenticator app&lt;/P&gt;&lt;P&gt;I am completely lost here ☹&lt;/P&gt;&lt;P&gt;hope someone can help&lt;/P&gt;&lt;P&gt;Dadi Johannesson&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 14:30:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/authenticator/m-p/4510865#M2561</guid>
      <dc:creator>DadJo</dc:creator>
      <dc:date>2026-04-13T14:30:38Z</dc:date>
    </item>
    <item>
      <title>Config Question:  Microsoft 365, Microsoft Authenticator, Mac Mail Users</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/config-question-microsoft-365-microsoft-authenticator-mac-mail/m-p/4508100#M2553</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp; We are currently using Microsoft 365 which is "hosted" or "federated" through GoDaddy.&amp;nbsp; I want to pilot Microsoft Authenticator, so that we can have either MFA, SSO, or a combo of both.&amp;nbsp; I'm running into a possible issue when I enable MFA for myself, as an enduser.&amp;nbsp; We run TEAMS, and I only get asked to re-login into Teams to authenticate, which does work.&amp;nbsp; However, if Mac Mail running as a client on the endpoint machine, should I assume that MFA will not work, since it is always communicating to the "hosted/federated" backend?&amp;nbsp; That it never disconnects the connection?&amp;nbsp; &amp;nbsp;If there is something I should do differently with the config, I'd appreciate the guidance here.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 15:45:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/config-question-microsoft-365-microsoft-authenticator-mac-mail/m-p/4508100#M2553</guid>
      <dc:creator>SkolBandit</dc:creator>
      <dc:date>2026-04-02T15:45:45Z</dc:date>
    </item>
    <item>
      <title>SSO from PingOne to Entra app failing; Not matching on sub value and can't find by email</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/sso-from-pingone-to-entra-app-failing-not-matching-on-sub-value/m-p/4507345#M2551</link>
      <description>&lt;P&gt;I am trying to implement SSO from PingOne to my Azure app I have registered in Entra External ID. When I don't have the PingOne account pre-provisioned, the sign-in flow provisions the account but with a bad value for the "Issuer" (the tenant id is incorrectly appended to the end of the issuer URL). This leads to a AADSTS500208 error. If I use Graph API to pre-provision the user with the proper "Issuer" URL, I get a message on the Entra prompt that says "Account Already Exists. Click next to sign in". Clicking Next gives the following error message:&lt;BR /&gt;We couldn't find an account with this email address&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 15:11:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/sso-from-pingone-to-entra-app-failing-not-matching-on-sub-value/m-p/4507345#M2551</guid>
      <dc:creator>ewhiteside</dc:creator>
      <dc:date>2026-03-31T15:11:04Z</dc:date>
    </item>
    <item>
      <title>Login Catch-22: locked out of Work account due to MFA mismatch.</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/login-catch-22-locked-out-of-work-account-due-to-mfa-mismatch/m-p/4506753#M2549</link>
      <description>&lt;P&gt;"I am the owner of the domain mydomain.be, registered at one.com. I have a Microsoft 365 Business Premium subscription. I am locked out of my work/school tenant admin account (&lt;A href="mailto:email address removed for privacy reasons" target="_blank"&gt;email address removed for privacy reasons&lt;/A&gt;) due to an MFA issue — the Microsoft Authenticator is configured but not delivering push notifications, and the TOTP code length does not match what the login screen expects. I cannot access the admin center. I need to recover Global Admin access to my flavo.be tenant so I can manage users and licenses. I can prove domain ownership via DNS if required.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 08:01:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/login-catch-22-locked-out-of-work-account-due-to-mfa-mismatch/m-p/4506753#M2549</guid>
      <dc:creator>HansFLAVO</dc:creator>
      <dc:date>2026-03-30T08:01:03Z</dc:date>
    </item>
    <item>
      <title>Problem authenticator app</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/problem-authenticator-app/m-p/4505518#M2546</link>
      <description>&lt;P&gt;Hi, how do I delete an account other than my personal account from the Authenticator app? It was added by mistake and is still there, and there isn't even a "delete account" button on microsoft.com.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2026 12:10:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/problem-authenticator-app/m-p/4505518#M2546</guid>
      <dc:creator>Sgarrupino</dc:creator>
      <dc:date>2026-03-25T12:10:37Z</dc:date>
    </item>
    <item>
      <title>Hotmail to Outlook Migration Broke My Account</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/hotmail-to-outlook-migration-broke-my-account/m-p/4503892#M2543</link>
      <description>&lt;P&gt;A year or two ago, I updated my Microsoft account to try and migrate from &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="2797186" data-lia-user-login="hotmail" class="lia-mention lia-mention-user"&gt;hotmail&lt;/a&gt;.com to @outlook.com. Since then, my Microsoft account is broken. I log in with my @outlook.com email, but account.microsoft.com displays my &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="2797186" data-lia-user-login="hotmail" class="lia-mention lia-mention-user"&gt;hotmail&lt;/a&gt;.com email everywhere. Mobile apps will not stay logged in properly and kick me out after a day. On my account info page my @outlook.com email isn't even listed and &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="2797186" data-lia-user-login="hotmail" class="lia-mention lia-mention-user"&gt;hotmail&lt;/a&gt;.com is listed as primary, but only logging in with @outlook works.&lt;BR /&gt;&lt;BR /&gt;I'm pretty sure when I originally tried to migrate my account some exception wasn't handled properly part way through the process and my account is in some sort of database limbo. Is there anyone at Microsoft here that can help with this?&lt;BR /&gt;&lt;BR /&gt;Also, sorry if this isn't the right place to post this, but a call with Microsoft support pointed me here and there doesn't seem to be a "Microsoft Account Support" hub or space on this platform. If anyone knows of a better location feel free to suggest that as well.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 17:30:54 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/hotmail-to-outlook-migration-broke-my-account/m-p/4503892#M2543</guid>
      <dc:creator>crackerjam6</dc:creator>
      <dc:date>2026-03-19T17:30:54Z</dc:date>
    </item>
    <item>
      <title>SMS code is not sent due to blocking</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/sms-code-is-not-sent-due-to-blocking/m-p/4501492#M2541</link>
      <description>&lt;P&gt;Hi! Sorry, I was using a translator to write this thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;About two weeks ago, I lost access to my Microsoft account. I haven't forgotten my password, and I haven't logged in from a new device—the system simply decided something was wrong and decided to send me an SMS code to verify my identity.&lt;/P&gt;&lt;P&gt;I currently live in Russia and have a Russian SIM card. My government has blocked receiving SMS codes from foreign companies (WhatsApp, Telegram, Microsoft, etc.). I enter the last four digits of my phone number and click "Send Code," but then it says "This feature is currently unsupported." I've submitted recovery forms numerous times, but the account is very old and some of the information has simply been lost!&lt;/P&gt;&lt;P&gt;I was barely able to contact a live person from Xbox support, and they opened a service request for recovery. The operator handling my issue completely ignores my messages. The only response he gave was that the form I sent him by email couldn't confirm my identity. He didn't even notice that I just needed a security code for the email address I used to REGISTER the account, as I couldn't receive an SMS code due to the political situation in my country.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today, I contacted a real Microsoft employee again, and he told me to write here because engineers often respond to messages and they can send me the code by email.&lt;/P&gt;&lt;P&gt;Please help me. This account has no material value other than a copy of Minecraft. This account is precious as a memory and something that helped me through an important period in my life.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for reading this thread.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 09:01:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/sms-code-is-not-sent-due-to-blocking/m-p/4501492#M2541</guid>
      <dc:creator>Philipp_Ges</dc:creator>
      <dc:date>2026-03-12T09:01:24Z</dc:date>
    </item>
    <item>
      <title>Can't access Microsoft Authenticator for business accounts</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/can-t-access-microsoft-authenticator-for-business-accounts/m-p/4497954#M2535</link>
      <description>&lt;P&gt;Hello.&amp;nbsp; I am the tech support for a small church, where I am the admin for our MS 365 accounts, which are set up as "business accounts".&amp;nbsp; I have been using Microsoft Authenticator for MFA for years.&amp;nbsp; Recently I switched to a new phone and installed Microsoft Authenticator.&amp;nbsp; All of my personal Authenticator accounts transferred over just fine, but all of the church's business accounts say "Scan the QR Code provided by your organization to finish recovering this account".&amp;nbsp; The thing is, I &lt;EM&gt;&lt;STRONG&gt;am &lt;/STRONG&gt;&lt;/EM&gt;the "organization" and I don't know how to generate any QR code to recover the accounts. It was suggested that I could do something about this by logging into my Microsoft 365 administrator account, but when I try to log into my admin account, the only MFA option is "enter the code from Microsoft Authenticator".&amp;nbsp; It's not offering a text or alternate email, only Microsoft Authenticator, which is what I'm locked out of.&amp;nbsp; So I'm stuck in a loop.&lt;/P&gt;&lt;P&gt;I opened a ticket with Microsoft Support nine days ago.&amp;nbsp; I have received one phone call since then.&amp;nbsp; The support person insisted that they needed to talk to the account's "alternate administrator", which I set up as my pastor, who is pretty computer savvy but not a deep IT person.&amp;nbsp; They tried to call him one time, but he was not available to answer right then.&amp;nbsp; There has been no communication since then.&amp;nbsp; I'm hoping someone in this group can help me figure this out.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 19:46:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/can-t-access-microsoft-authenticator-for-business-accounts/m-p/4497954#M2535</guid>
      <dc:creator>KFBC_Tech</dc:creator>
      <dc:date>2026-02-27T19:46:58Z</dc:date>
    </item>
    <item>
      <title>Microsoft Feedback Portal account is not working</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-feedback-portal-account-is-not-working/m-p/4491519#M2530</link>
      <description>&lt;P&gt;I changed my Microsoft password a year ago, and it updated everywhere other than the Feedback Portal. As a result, I get an error when I try to login, or do anything on the page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft account support's suggestion was to login to the Feedback Portal which is insane given I'm having issues accessing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I get this issue resolved? I've got three separate support tickets now and they keep asking me to wait 24 hours to get the issue resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone from the Feedback Portal team please contact me to resolve this?"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what Microsoft Support have said:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"understand your frustration, and yes—this is an account‑related issue because the Feedback Portal is still tied to your old alias, which causes login conflicts and forces you out. Your Microsoft account itself signs in correctly, but the Feedback Portal is pulling outdated identity data that you cannot update on your own. Since you cannot access the Portal to submit feedback, directing you back there is not a workable solution. What you need is for Support to escalate this to the internal Identity/Feedback Platform engineering team so they can manually correct the outdated alias mapping on the backend. In this situation, the Feedback Portal and Tech Community teams are the ones who manage and maintain that specific platform. Because the issue appears on the Feedback Portal side—even though your Microsoft account is working normally—only their dedicated team can make the necessary corrections on their end. That’s why we are guiding you to connect with them through the links provided:&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/" target="_blank"&gt;https://techcommunity.microsoft.com/&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="https://feedbackportal.microsoft.com/feedback" target="_blank"&gt;https://feedbackportal.microsoft.com/feedback&lt;/A&gt;. They will be able to review the portal‑specific account data and assist you further. I understand why this is frustrating. Since you’re unable to stay signed in to the Feedback Portal, I completely see why posting there isn’t possible for you. However, I do need to be transparent: I’m not able to escalate this issue directly to the Feedback Portal team, as they don’t provide internal escalation channels for us and only accept requests through their own platform.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 11:21:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-feedback-portal-account-is-not-working/m-p/4491519#M2530</guid>
      <dc:creator>bobbyeagle</dc:creator>
      <dc:date>2026-02-02T11:21:22Z</dc:date>
    </item>
    <item>
      <title>Excel authentication token reuse for access to Log Analytics</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/excel-authentication-token-reuse-for-access-to-log-analytics/m-p/4490828#M2528</link>
      <description>&lt;P&gt;I have noticed that Excel is not able to reuse the authentication token when accessing Log Analytics workspaces if an expired token was renewed for a single sheet in a workbook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1 workbook with 1+ worksheets&lt;/LI&gt;&lt;LI&gt;Each worksheet is a different query to LA (KQL query displayed in Excel for ease and consolidation)&lt;/LI&gt;&lt;LI&gt;Access to LA is protected by the usual access controls (Conditional Access; Security Reader role + Session control)&lt;/LI&gt;&lt;LI&gt;After a period of time, session and token expire and require renewal&lt;/LI&gt;&lt;LI&gt;User receives a prompt stating the token has expired and needs to be renew&lt;/LI&gt;&lt;LI&gt;User clicks on "Sign-in" and successfully completes the prompts (u/n+pwd+MFA)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Expected result:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The new token will be reused for subsequent connections to LA within the same workbook&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Actual result:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User is prompted to re-authenticate for each and every connection in the workbook resulting in as many auth requests as there are connections&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;After successfully completing the first auth request, close Excel and re-open it and run "Refresh all"&lt;/LI&gt;&lt;LI&gt;This successfully completes refresh of all data without any additional re-auth requests&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this behaviour by design or due to a configuration? Is there a way to address this so that the first token is re-used by all other connections without having to close and reopen the workbook?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 14:05:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/excel-authentication-token-reuse-for-access-to-log-analytics/m-p/4490828#M2528</guid>
      <dc:creator>zivrivkis</dc:creator>
      <dc:date>2026-01-30T14:05:12Z</dc:date>
    </item>
    <item>
      <title>How Do I Target the Azure VPN Client in a Conditional Access Policy?</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-target-the-azure-vpn-client-in-a-conditional-access/m-p/4487209#M2523</link>
      <description>&lt;P&gt;I am using the Azure VPN Client to connect users to an Azure VPN Gateway using their Entra ID credentials to authenticate.&amp;nbsp; I want to target this application with a CA policy that requires MFA every time it connects.&amp;nbsp; The problem is that I don't see the applications in my Enterprise Apps and all of my searching says that it won't appear because it was "pre-certified" by Microsoft.&amp;nbsp; In the Gateway setup I used the Audience GUID of&lt;/P&gt;&lt;P&gt;c632b3df-fb67-4d84-bdcf-b95ad541b5c8.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this is working as expected.&amp;nbsp; The only solution that I have found for targeting the Azure VPN Client app is to create a Service Principal using that Audience GUID.&amp;nbsp; This seems like a bit of a hack, so I am posting here to see if there are any other methods that I am missing to target this app when it doesn't appear in my Enterprise Apps list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 17:12:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-target-the-azure-vpn-client-in-a-conditional-access/m-p/4487209#M2523</guid>
      <dc:creator>cmiarshvac</dc:creator>
      <dc:date>2026-01-19T17:12:44Z</dc:date>
    </item>
    <item>
      <title>Hybrid Identity Admin Questions</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/hybrid-identity-admin-questions/m-p/4486908#M2520</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, we are migrating our Entra Connect Sync server to it's own dedicated server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regards to the Hybrid Identity admin role, do we:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Include MFA on this account&lt;/LI&gt;&lt;LI&gt;Configure as Eligible or Permanent in PIM&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Info appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stuart&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jan 2026 23:27:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/hybrid-identity-admin-questions/m-p/4486908#M2520</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-01-18T23:27:03Z</dc:date>
    </item>
    <item>
      <title>Hacked Live account</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/hacked-live-account/m-p/4482160#M2516</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;On of our customers accounts was hacked.&lt;BR /&gt;&lt;BR /&gt;This is a Live account linked to his own emailadres (not hotmail) from his Internet Provider.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;A few weeks ago someone gained access to this account.&lt;/P&gt;&lt;P&gt;They changed the recovery email address and the phone number.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer has a paid Office 36 family account, which is paid for with his MasterCard and he can provide the invoice from the last years..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried the account recovery Form multiple times, opened a case with CDOC Case Management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We simply got the reply that they could not do anything but to suspend the account.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I Think this is crazy, is there no solution to this ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2025 09:50:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/hacked-live-account/m-p/4482160#M2516</guid>
      <dc:creator>Wim Bartels</dc:creator>
      <dc:date>2025-12-31T09:50:40Z</dc:date>
    </item>
    <item>
      <title>Android Teams login fails during ADFS federation with SSL error</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/android-teams-login-fails-during-adfs-federation-with-ssl-error/m-p/4481249#M2511</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Android mobile users cannot sign in to Microsoft Teams&lt;/P&gt;&lt;P&gt;The login fails during the ADFS federation step due to an SSL error&lt;/P&gt;&lt;P&gt;Environment&lt;/P&gt;&lt;P&gt;Android OS versions 10 to 14&lt;/P&gt;&lt;P&gt;Microsoft Teams mobile app&lt;/P&gt;&lt;P&gt;Entra ID federated with on premises ADFS&lt;/P&gt;&lt;P&gt;ADFS service URL is masked&lt;/P&gt;&lt;P&gt;Public certificate issued by Sectigo&lt;/P&gt;&lt;P&gt;Issue description&lt;/P&gt;&lt;P&gt;After entering the account in Teams the sign in process redirects to ADFS&lt;/P&gt;&lt;P&gt;The page does not load correctly and shows infinite loading or a blank screen&lt;/P&gt;&lt;P&gt;The same account works normally on PC browser PC Teams and Outlook Web&lt;/P&gt;&lt;P&gt;The issue occurs only on Android mobile apps that use WebView&lt;/P&gt;&lt;P&gt;Android log summary&lt;/P&gt;&lt;P&gt;OAuth2 WebView client received SSL error&lt;/P&gt;&lt;P&gt;Primary error SSL untrusted&lt;/P&gt;&lt;P&gt;Wildcard certificate for masked domain&lt;/P&gt;&lt;P&gt;Certificate issued by Sectigo Public Server Authentication CA&lt;/P&gt;&lt;P&gt;Troubleshooting performed&lt;/P&gt;&lt;P&gt;Device date and time verified&lt;/P&gt;&lt;P&gt;Teams app cache cleared and app reinstalled&lt;/P&gt;&lt;P&gt;Issue reproduced on multiple Android versions and devices&lt;/P&gt;&lt;P&gt;PC authentication works with the same certificate&lt;/P&gt;&lt;P&gt;Questions&lt;/P&gt;&lt;P&gt;Can Android WebView or Microsoft mobile authentication fail with SSL untrusted when the ADFS server does not provide a complete certificate chain&lt;/P&gt;&lt;P&gt;Is full chain certificate configuration required on ADFS IIS for mobile authentication&lt;/P&gt;&lt;P&gt;Can SSL inspection or proxy interception cause this issue only on Android apps while PC browsers work normally&lt;/P&gt;&lt;P&gt;Are there official Microsoft recommendations for certificate configuration when using ADFS federation with Android mobile apps&lt;/P&gt;&lt;P&gt;Additional information&lt;/P&gt;&lt;P&gt;The same behavior occurs in other Microsoft mobile apps&lt;/P&gt;&lt;P&gt;The suspected causes are incomplete certificate chain or network SSL inspection&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 26 Dec 2025 09:12:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/android-teams-login-fails-during-adfs-federation-with-ssl-error/m-p/4481249#M2511</guid>
      <dc:creator>kek</dc:creator>
      <dc:date>2025-12-26T09:12:45Z</dc:date>
    </item>
  </channel>
</rss>

