<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Identity &amp; Authentication topics</title>
    <link>https://techcommunity.microsoft.com/t5/identity-authentication/bd-p/IdentityAuth</link>
    <description>Identity &amp; Authentication topics</description>
    <pubDate>Sat, 25 Apr 2026 05:53:27 GMT</pubDate>
    <dc:creator>IdentityAuth</dc:creator>
    <dc:date>2026-04-25T05:53:27Z</dc:date>
    <item>
      <title>Broken Account Recovery (discontinued product)</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/broken-account-recovery-discontinued-product/m-p/4512765#M2563</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;We have the MSFT Office Family plan which has the now discontinued custom domain support that used to be an option as a "Premium" feature. Back in August we upgraded the phone of one of the account members on the family plan and lost connection to their MS Office account with the only device that was accessing to the account (the phone with access was reset as part of the upgrade/trade in process). I have tried the account recovery form and it simply doesn't work. I have tried to explain to MSFT support that the tool is broken but can't get anywhere. For the account in question we have an Outlook email client (with non working password) that has a cache of all of the email until loss of access occurred. So when I do the account recovery form, I have name, DOB, region, past passwords and data for all fields including sent email Id's and send subjects, But every time the MSFT recovery mechanism says "Unfortunately, we have determined that the information provided was not sufficient...". WTF.&lt;/P&gt;&lt;P&gt;Every time I contact MSFT support I get the same answer, an explanation of the point system used to reset the the account. Same steps to recover....based on this, the recovery should work...yet it doesn't. I have tried somewhere 50+ attempts now over the last 9 months. I even have a contact who is VP level at MSFT who sponsored a support ticket internally but that just ended up with the support person sending me a link to the account recovery form and closed the ticket without looking in the details of the ticket.&lt;/P&gt;&lt;P&gt;I can't modify / add a new account as MSFT has as a discontinued product no longer allow members to add/change id's. So I'm locked at the current user set. I have created another email address by saving the cached data to OLM file and importing via the Outlook client but that doesn't restore use of the @mydomain.com for that person. I even retained a lawyer who send a demand to MSFT legal...but the email address didn't go anywhere so at the point of needing to do this on headed paper/send via snail mail.&lt;/P&gt;&lt;P&gt;Does anyone have any idea how to get through to MSFT explain the recovery tool is broken? I assume there are so few accounts using custom domains pin family plans that they simply don't test this recovery path.&lt;/P&gt;&lt;P&gt;At this point without some internal guidance is a) lawyer and force a demand for password reset b) give up, ditch all of the users using the custom domain, configure an alias for all of the accounts and then change my MX record to a company doing email forwarding and then forward to the new/old legacy accounts (i.e. the ones with the &lt;A class="lia-external-url" href="mailto:email address removed for privacy reasons)" target="_blank"&gt;mailto:email address removed for privacy reasons)&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 04:18:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/broken-account-recovery-discontinued-product/m-p/4512765#M2563</guid>
      <dc:creator>anewham</dc:creator>
      <dc:date>2026-04-20T04:18:08Z</dc:date>
    </item>
    <item>
      <title>Authenticator</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/authenticator/m-p/4510865#M2561</link>
      <description>&lt;P&gt;I need your help.&lt;/P&gt;&lt;P&gt;I broke my Iphone and after replacing it I cannot log into my Microsoft admin account since the authentication app is not working.&lt;/P&gt;&lt;P&gt;I am the administrator of my own small business account.&amp;nbsp; I have gone through all the account recovery help but neither the send text to my number or call my number works.&lt;/P&gt;&lt;P&gt;All online support depends on having an the code from the Authenticator app&lt;/P&gt;&lt;P&gt;I am completely lost here ☹&lt;/P&gt;&lt;P&gt;hope someone can help&lt;/P&gt;&lt;P&gt;Dadi Johannesson&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 14:30:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/authenticator/m-p/4510865#M2561</guid>
      <dc:creator>DadJo</dc:creator>
      <dc:date>2026-04-13T14:30:38Z</dc:date>
    </item>
    <item>
      <title>Config Question:  Microsoft 365, Microsoft Authenticator, Mac Mail Users</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/config-question-microsoft-365-microsoft-authenticator-mac-mail/m-p/4508100#M2553</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp; We are currently using Microsoft 365 which is "hosted" or "federated" through GoDaddy.&amp;nbsp; I want to pilot Microsoft Authenticator, so that we can have either MFA, SSO, or a combo of both.&amp;nbsp; I'm running into a possible issue when I enable MFA for myself, as an enduser.&amp;nbsp; We run TEAMS, and I only get asked to re-login into Teams to authenticate, which does work.&amp;nbsp; However, if Mac Mail running as a client on the endpoint machine, should I assume that MFA will not work, since it is always communicating to the "hosted/federated" backend?&amp;nbsp; That it never disconnects the connection?&amp;nbsp; &amp;nbsp;If there is something I should do differently with the config, I'd appreciate the guidance here.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 15:45:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/config-question-microsoft-365-microsoft-authenticator-mac-mail/m-p/4508100#M2553</guid>
      <dc:creator>SkolBandit</dc:creator>
      <dc:date>2026-04-02T15:45:45Z</dc:date>
    </item>
    <item>
      <title>SSO from PingOne to Entra app failing; Not matching on sub value and can't find by email</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/sso-from-pingone-to-entra-app-failing-not-matching-on-sub-value/m-p/4507345#M2551</link>
      <description>&lt;P&gt;I am trying to implement SSO from PingOne to my Azure app I have registered in Entra External ID. When I don't have the PingOne account pre-provisioned, the sign-in flow provisions the account but with a bad value for the "Issuer" (the tenant id is incorrectly appended to the end of the issuer URL). This leads to a AADSTS500208 error. If I use Graph API to pre-provision the user with the proper "Issuer" URL, I get a message on the Entra prompt that says "Account Already Exists. Click next to sign in". Clicking Next gives the following error message:&lt;BR /&gt;We couldn't find an account with this email address&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 15:11:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/sso-from-pingone-to-entra-app-failing-not-matching-on-sub-value/m-p/4507345#M2551</guid>
      <dc:creator>ewhiteside</dc:creator>
      <dc:date>2026-03-31T15:11:04Z</dc:date>
    </item>
    <item>
      <title>Login Catch-22: locked out of Work account due to MFA mismatch.</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/login-catch-22-locked-out-of-work-account-due-to-mfa-mismatch/m-p/4506753#M2549</link>
      <description>&lt;P&gt;"I am the owner of the domain mydomain.be, registered at one.com. I have a Microsoft 365 Business Premium subscription. I am locked out of my work/school tenant admin account (&lt;A href="mailto:email address removed for privacy reasons" target="_blank"&gt;email address removed for privacy reasons&lt;/A&gt;) due to an MFA issue — the Microsoft Authenticator is configured but not delivering push notifications, and the TOTP code length does not match what the login screen expects. I cannot access the admin center. I need to recover Global Admin access to my flavo.be tenant so I can manage users and licenses. I can prove domain ownership via DNS if required.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 08:01:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/login-catch-22-locked-out-of-work-account-due-to-mfa-mismatch/m-p/4506753#M2549</guid>
      <dc:creator>HansFLAVO</dc:creator>
      <dc:date>2026-03-30T08:01:03Z</dc:date>
    </item>
    <item>
      <title>Problem authenticator app</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/problem-authenticator-app/m-p/4505518#M2546</link>
      <description>&lt;P&gt;Hi, how do I delete an account other than my personal account from the Authenticator app? It was added by mistake and is still there, and there isn't even a "delete account" button on microsoft.com.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2026 12:10:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/problem-authenticator-app/m-p/4505518#M2546</guid>
      <dc:creator>Sgarrupino</dc:creator>
      <dc:date>2026-03-25T12:10:37Z</dc:date>
    </item>
    <item>
      <title>Hotmail to Outlook Migration Broke My Account</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/hotmail-to-outlook-migration-broke-my-account/m-p/4503892#M2543</link>
      <description>&lt;P&gt;A year or two ago, I updated my Microsoft account to try and migrate from &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="2797186" data-lia-user-login="hotmail" class="lia-mention lia-mention-user"&gt;hotmail&lt;/a&gt;.com to @outlook.com. Since then, my Microsoft account is broken. I log in with my @outlook.com email, but account.microsoft.com displays my &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="2797186" data-lia-user-login="hotmail" class="lia-mention lia-mention-user"&gt;hotmail&lt;/a&gt;.com email everywhere. Mobile apps will not stay logged in properly and kick me out after a day. On my account info page my @outlook.com email isn't even listed and &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="2797186" data-lia-user-login="hotmail" class="lia-mention lia-mention-user"&gt;hotmail&lt;/a&gt;.com is listed as primary, but only logging in with @outlook works.&lt;BR /&gt;&lt;BR /&gt;I'm pretty sure when I originally tried to migrate my account some exception wasn't handled properly part way through the process and my account is in some sort of database limbo. Is there anyone at Microsoft here that can help with this?&lt;BR /&gt;&lt;BR /&gt;Also, sorry if this isn't the right place to post this, but a call with Microsoft support pointed me here and there doesn't seem to be a "Microsoft Account Support" hub or space on this platform. If anyone knows of a better location feel free to suggest that as well.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2026 17:30:54 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/hotmail-to-outlook-migration-broke-my-account/m-p/4503892#M2543</guid>
      <dc:creator>crackerjam6</dc:creator>
      <dc:date>2026-03-19T17:30:54Z</dc:date>
    </item>
    <item>
      <title>SMS code is not sent due to blocking</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/sms-code-is-not-sent-due-to-blocking/m-p/4501492#M2541</link>
      <description>&lt;P&gt;Hi! Sorry, I was using a translator to write this thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;About two weeks ago, I lost access to my Microsoft account. I haven't forgotten my password, and I haven't logged in from a new device—the system simply decided something was wrong and decided to send me an SMS code to verify my identity.&lt;/P&gt;&lt;P&gt;I currently live in Russia and have a Russian SIM card. My government has blocked receiving SMS codes from foreign companies (WhatsApp, Telegram, Microsoft, etc.). I enter the last four digits of my phone number and click "Send Code," but then it says "This feature is currently unsupported." I've submitted recovery forms numerous times, but the account is very old and some of the information has simply been lost!&lt;/P&gt;&lt;P&gt;I was barely able to contact a live person from Xbox support, and they opened a service request for recovery. The operator handling my issue completely ignores my messages. The only response he gave was that the form I sent him by email couldn't confirm my identity. He didn't even notice that I just needed a security code for the email address I used to REGISTER the account, as I couldn't receive an SMS code due to the political situation in my country.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today, I contacted a real Microsoft employee again, and he told me to write here because engineers often respond to messages and they can send me the code by email.&lt;/P&gt;&lt;P&gt;Please help me. This account has no material value other than a copy of Minecraft. This account is precious as a memory and something that helped me through an important period in my life.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for reading this thread.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 09:01:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/sms-code-is-not-sent-due-to-blocking/m-p/4501492#M2541</guid>
      <dc:creator>Philipp_Ges</dc:creator>
      <dc:date>2026-03-12T09:01:24Z</dc:date>
    </item>
    <item>
      <title>Can't access Microsoft Authenticator for business accounts</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/can-t-access-microsoft-authenticator-for-business-accounts/m-p/4497954#M2535</link>
      <description>&lt;P&gt;Hello.&amp;nbsp; I am the tech support for a small church, where I am the admin for our MS 365 accounts, which are set up as "business accounts".&amp;nbsp; I have been using Microsoft Authenticator for MFA for years.&amp;nbsp; Recently I switched to a new phone and installed Microsoft Authenticator.&amp;nbsp; All of my personal Authenticator accounts transferred over just fine, but all of the church's business accounts say "Scan the QR Code provided by your organization to finish recovering this account".&amp;nbsp; The thing is, I &lt;EM&gt;&lt;STRONG&gt;am &lt;/STRONG&gt;&lt;/EM&gt;the "organization" and I don't know how to generate any QR code to recover the accounts. It was suggested that I could do something about this by logging into my Microsoft 365 administrator account, but when I try to log into my admin account, the only MFA option is "enter the code from Microsoft Authenticator".&amp;nbsp; It's not offering a text or alternate email, only Microsoft Authenticator, which is what I'm locked out of.&amp;nbsp; So I'm stuck in a loop.&lt;/P&gt;&lt;P&gt;I opened a ticket with Microsoft Support nine days ago.&amp;nbsp; I have received one phone call since then.&amp;nbsp; The support person insisted that they needed to talk to the account's "alternate administrator", which I set up as my pastor, who is pretty computer savvy but not a deep IT person.&amp;nbsp; They tried to call him one time, but he was not available to answer right then.&amp;nbsp; There has been no communication since then.&amp;nbsp; I'm hoping someone in this group can help me figure this out.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 19:46:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/can-t-access-microsoft-authenticator-for-business-accounts/m-p/4497954#M2535</guid>
      <dc:creator>KFBC_Tech</dc:creator>
      <dc:date>2026-02-27T19:46:58Z</dc:date>
    </item>
    <item>
      <title>Microsoft Feedback Portal account is not working</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-feedback-portal-account-is-not-working/m-p/4491519#M2530</link>
      <description>&lt;P&gt;I changed my Microsoft password a year ago, and it updated everywhere other than the Feedback Portal. As a result, I get an error when I try to login, or do anything on the page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft account support's suggestion was to login to the Feedback Portal which is insane given I'm having issues accessing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I get this issue resolved? I've got three separate support tickets now and they keep asking me to wait 24 hours to get the issue resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone from the Feedback Portal team please contact me to resolve this?"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what Microsoft Support have said:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"understand your frustration, and yes—this is an account‑related issue because the Feedback Portal is still tied to your old alias, which causes login conflicts and forces you out. Your Microsoft account itself signs in correctly, but the Feedback Portal is pulling outdated identity data that you cannot update on your own. Since you cannot access the Portal to submit feedback, directing you back there is not a workable solution. What you need is for Support to escalate this to the internal Identity/Feedback Platform engineering team so they can manually correct the outdated alias mapping on the backend. In this situation, the Feedback Portal and Tech Community teams are the ones who manage and maintain that specific platform. Because the issue appears on the Feedback Portal side—even though your Microsoft account is working normally—only their dedicated team can make the necessary corrections on their end. That’s why we are guiding you to connect with them through the links provided:&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/" target="_blank"&gt;https://techcommunity.microsoft.com/&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="https://feedbackportal.microsoft.com/feedback" target="_blank"&gt;https://feedbackportal.microsoft.com/feedback&lt;/A&gt;. They will be able to review the portal‑specific account data and assist you further. I understand why this is frustrating. Since you’re unable to stay signed in to the Feedback Portal, I completely see why posting there isn’t possible for you. However, I do need to be transparent: I’m not able to escalate this issue directly to the Feedback Portal team, as they don’t provide internal escalation channels for us and only accept requests through their own platform.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 11:21:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-feedback-portal-account-is-not-working/m-p/4491519#M2530</guid>
      <dc:creator>bobbyeagle</dc:creator>
      <dc:date>2026-02-02T11:21:22Z</dc:date>
    </item>
    <item>
      <title>Excel authentication token reuse for access to Log Analytics</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/excel-authentication-token-reuse-for-access-to-log-analytics/m-p/4490828#M2528</link>
      <description>&lt;P&gt;I have noticed that Excel is not able to reuse the authentication token when accessing Log Analytics workspaces if an expired token was renewed for a single sheet in a workbook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1 workbook with 1+ worksheets&lt;/LI&gt;&lt;LI&gt;Each worksheet is a different query to LA (KQL query displayed in Excel for ease and consolidation)&lt;/LI&gt;&lt;LI&gt;Access to LA is protected by the usual access controls (Conditional Access; Security Reader role + Session control)&lt;/LI&gt;&lt;LI&gt;After a period of time, session and token expire and require renewal&lt;/LI&gt;&lt;LI&gt;User receives a prompt stating the token has expired and needs to be renew&lt;/LI&gt;&lt;LI&gt;User clicks on "Sign-in" and successfully completes the prompts (u/n+pwd+MFA)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Expected result:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The new token will be reused for subsequent connections to LA within the same workbook&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Actual result:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User is prompted to re-authenticate for each and every connection in the workbook resulting in as many auth requests as there are connections&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;After successfully completing the first auth request, close Excel and re-open it and run "Refresh all"&lt;/LI&gt;&lt;LI&gt;This successfully completes refresh of all data without any additional re-auth requests&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this behaviour by design or due to a configuration? Is there a way to address this so that the first token is re-used by all other connections without having to close and reopen the workbook?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 14:05:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/excel-authentication-token-reuse-for-access-to-log-analytics/m-p/4490828#M2528</guid>
      <dc:creator>zivrivkis</dc:creator>
      <dc:date>2026-01-30T14:05:12Z</dc:date>
    </item>
    <item>
      <title>How Do I Target the Azure VPN Client in a Conditional Access Policy?</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-target-the-azure-vpn-client-in-a-conditional-access/m-p/4487209#M2523</link>
      <description>&lt;P&gt;I am using the Azure VPN Client to connect users to an Azure VPN Gateway using their Entra ID credentials to authenticate.&amp;nbsp; I want to target this application with a CA policy that requires MFA every time it connects.&amp;nbsp; The problem is that I don't see the applications in my Enterprise Apps and all of my searching says that it won't appear because it was "pre-certified" by Microsoft.&amp;nbsp; In the Gateway setup I used the Audience GUID of&lt;/P&gt;&lt;P&gt;c632b3df-fb67-4d84-bdcf-b95ad541b5c8.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this is working as expected.&amp;nbsp; The only solution that I have found for targeting the Azure VPN Client app is to create a Service Principal using that Audience GUID.&amp;nbsp; This seems like a bit of a hack, so I am posting here to see if there are any other methods that I am missing to target this app when it doesn't appear in my Enterprise Apps list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 17:12:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/how-do-i-target-the-azure-vpn-client-in-a-conditional-access/m-p/4487209#M2523</guid>
      <dc:creator>cmiarshvac</dc:creator>
      <dc:date>2026-01-19T17:12:44Z</dc:date>
    </item>
    <item>
      <title>Hybrid Identity Admin Questions</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/hybrid-identity-admin-questions/m-p/4486908#M2520</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, we are migrating our Entra Connect Sync server to it's own dedicated server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regards to the Hybrid Identity admin role, do we:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Include MFA on this account&lt;/LI&gt;&lt;LI&gt;Configure as Eligible or Permanent in PIM&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Info appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stuart&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jan 2026 23:27:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/hybrid-identity-admin-questions/m-p/4486908#M2520</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-01-18T23:27:03Z</dc:date>
    </item>
    <item>
      <title>Hacked Live account</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/hacked-live-account/m-p/4482160#M2516</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;On of our customers accounts was hacked.&lt;BR /&gt;&lt;BR /&gt;This is a Live account linked to his own emailadres (not hotmail) from his Internet Provider.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;A few weeks ago someone gained access to this account.&lt;/P&gt;&lt;P&gt;They changed the recovery email address and the phone number.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer has a paid Office 36 family account, which is paid for with his MasterCard and he can provide the invoice from the last years..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried the account recovery Form multiple times, opened a case with CDOC Case Management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We simply got the reply that they could not do anything but to suspend the account.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I Think this is crazy, is there no solution to this ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2025 09:50:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/hacked-live-account/m-p/4482160#M2516</guid>
      <dc:creator>Wim Bartels</dc:creator>
      <dc:date>2025-12-31T09:50:40Z</dc:date>
    </item>
    <item>
      <title>Android Teams login fails during ADFS federation with SSL error</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/android-teams-login-fails-during-adfs-federation-with-ssl-error/m-p/4481249#M2511</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Android mobile users cannot sign in to Microsoft Teams&lt;/P&gt;&lt;P&gt;The login fails during the ADFS federation step due to an SSL error&lt;/P&gt;&lt;P&gt;Environment&lt;/P&gt;&lt;P&gt;Android OS versions 10 to 14&lt;/P&gt;&lt;P&gt;Microsoft Teams mobile app&lt;/P&gt;&lt;P&gt;Entra ID federated with on premises ADFS&lt;/P&gt;&lt;P&gt;ADFS service URL is masked&lt;/P&gt;&lt;P&gt;Public certificate issued by Sectigo&lt;/P&gt;&lt;P&gt;Issue description&lt;/P&gt;&lt;P&gt;After entering the account in Teams the sign in process redirects to ADFS&lt;/P&gt;&lt;P&gt;The page does not load correctly and shows infinite loading or a blank screen&lt;/P&gt;&lt;P&gt;The same account works normally on PC browser PC Teams and Outlook Web&lt;/P&gt;&lt;P&gt;The issue occurs only on Android mobile apps that use WebView&lt;/P&gt;&lt;P&gt;Android log summary&lt;/P&gt;&lt;P&gt;OAuth2 WebView client received SSL error&lt;/P&gt;&lt;P&gt;Primary error SSL untrusted&lt;/P&gt;&lt;P&gt;Wildcard certificate for masked domain&lt;/P&gt;&lt;P&gt;Certificate issued by Sectigo Public Server Authentication CA&lt;/P&gt;&lt;P&gt;Troubleshooting performed&lt;/P&gt;&lt;P&gt;Device date and time verified&lt;/P&gt;&lt;P&gt;Teams app cache cleared and app reinstalled&lt;/P&gt;&lt;P&gt;Issue reproduced on multiple Android versions and devices&lt;/P&gt;&lt;P&gt;PC authentication works with the same certificate&lt;/P&gt;&lt;P&gt;Questions&lt;/P&gt;&lt;P&gt;Can Android WebView or Microsoft mobile authentication fail with SSL untrusted when the ADFS server does not provide a complete certificate chain&lt;/P&gt;&lt;P&gt;Is full chain certificate configuration required on ADFS IIS for mobile authentication&lt;/P&gt;&lt;P&gt;Can SSL inspection or proxy interception cause this issue only on Android apps while PC browsers work normally&lt;/P&gt;&lt;P&gt;Are there official Microsoft recommendations for certificate configuration when using ADFS federation with Android mobile apps&lt;/P&gt;&lt;P&gt;Additional information&lt;/P&gt;&lt;P&gt;The same behavior occurs in other Microsoft mobile apps&lt;/P&gt;&lt;P&gt;The suspected causes are incomplete certificate chain or network SSL inspection&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 26 Dec 2025 09:12:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/android-teams-login-fails-during-adfs-federation-with-ssl-error/m-p/4481249#M2511</guid>
      <dc:creator>kek</dc:creator>
      <dc:date>2025-12-26T09:12:45Z</dc:date>
    </item>
    <item>
      <title>In "Per-user multifactor authentication" I disabled MFA for one user; All got disabled</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/in-quot-per-user-multifactor-authentication-quot-i-disabled-mfa/m-p/4480338#M2505</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm the 365 admin for our org.&amp;nbsp; Today I had a user that got a new phone and became stuck in a MS Authenticator app loop.&amp;nbsp; (The app required MFA to login to the app, but they can't login to the app because they aren't logged into the app.&amp;nbsp; This happened once before, and is a ridiculous Kafkaesque situation; but I digress.)&lt;/P&gt;&lt;P&gt;To solve it, I went to disable MFA on their account, allowing them to login to the app.&amp;nbsp; Then MFA could be re-enabled.&amp;nbsp; Problem solved.&lt;/P&gt;&lt;P&gt;And indeed that did work.&lt;/P&gt;&lt;P&gt;However, on the admin side (per the screenshot) I checked off their user account (the user starting with the letter "B") and hit the "Disable MFA" link.&amp;nbsp; A confirmation appeared asking me if I wanted to disable MFA &lt;STRONG&gt;for all selected users&lt;/STRONG&gt;.&amp;nbsp; Because I'm the careful sort, I could still see that&amp;nbsp;&lt;STRONG&gt;only that one user was checked off&lt;/STRONG&gt; as the popover div didn't cover that much of the screen.&lt;/P&gt;&lt;P&gt;Hence I confirmed that I wanted to disable MFA for&amp;nbsp;&lt;STRONG&gt;the selected users&amp;nbsp;&lt;/STRONG&gt;(i.e. that one user).&lt;/P&gt;&lt;P&gt;I then refreshed the page, and &lt;STRONG&gt;all users are now shown as having MFA disabled.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm 100% sure only that one user was selected, not everyone in my org.&amp;nbsp; That would've been foolish.&lt;/P&gt;&lt;P&gt;Trying to figure out what's wrong with this portion of the admin site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2025 16:24:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/in-quot-per-user-multifactor-authentication-quot-i-disabled-mfa/m-p/4480338#M2505</guid>
      <dc:creator>ScottoMR</dc:creator>
      <dc:date>2025-12-22T16:24:59Z</dc:date>
    </item>
    <item>
      <title>Graph http 449 throttled</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/graph-http-449-throttled/m-p/4480333#M2504</link>
      <description>&lt;P&gt;We are experiencing a lot of Microsoft Graph trolling errors from some of our applications that are hosted in Azure Web App Services and other third party such as Front App to name one. I am trying to find an approach or strategy to figure out and narrow down what may be causing so many of these events. Whether I can narrow down by application or process, I am not sure yet. We enforce MFA on all our users, but of course, on Azure Enterprise Applications, we don't, which are used extensively in our ecosystem of apps. Any help is much appreciated here.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2025 16:06:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/graph-http-449-throttled/m-p/4480333#M2504</guid>
      <dc:creator>RazTheOne</dc:creator>
      <dc:date>2025-12-22T16:06:47Z</dc:date>
    </item>
    <item>
      <title>Case 2512040040001886 - Cannot Access Account</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/case-2512040040001886-cannot-access-account/m-p/4479676#M2502</link>
      <description>&lt;P&gt;Since the 4th of December we have been patiently waiting on MS Tech support to assist on resolving our Case with no success endless calls and endless promises with no luck. How do you proceed in using Microsoft for a Business if they don't deliver on the support. My business is taking the brunt of it. I suppose another call holding for hours and another Support person promise a solution. No other methods to log complaints as you cannot log into your Account Portal.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 18:49:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/case-2512040040001886-cannot-access-account/m-p/4479676#M2502</guid>
      <dc:creator>StephenDuPlessis</dc:creator>
      <dc:date>2025-12-19T18:49:12Z</dc:date>
    </item>
    <item>
      <title>Someone changed my email but i still have access to my account</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/someone-changed-my-email-but-i-still-have-access-to-my-account/m-p/4479173#M2501</link>
      <description>&lt;P&gt;My microsoft account got hacked but the hacker didn't change my password, now i'm stuck with this weird email account from russia and dont know what&amp;nbsp; to do... I tried the Recovery form but i tried too many times and now doesn't let me try anymore. What can i do? I'm scared for my account&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 11:30:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/someone-changed-my-email-but-i-still-have-access-to-my-account/m-p/4479173#M2501</guid>
      <dc:creator>Juan3</dc:creator>
      <dc:date>2025-12-18T11:30:03Z</dc:date>
    </item>
    <item>
      <title>microsoft authenticator</title>
      <link>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-authenticator/m-p/4477240#M2498</link>
      <description>&lt;P&gt;hello I would like to ask for help because in the application since I reset the password it no longer lets me log in telling me that my user name and password are incorrect, I no longer know how to access, can someone help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 13:44:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/identity-authentication/microsoft-authenticator/m-p/4477240#M2498</guid>
      <dc:creator>flamadmax77</dc:creator>
      <dc:date>2025-12-11T13:44:09Z</dc:date>
    </item>
  </channel>
</rss>

