%3CLINGO-SUB%20id%3D%22lingo-sub-1398351%22%20slang%3D%22en-US%22%3EPerform%20Index%20reset%20for%20Cloud%20SSA%20using%20Multi%20Factor%20Authentication%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1398351%22%20slang%3D%22en-US%22%3E%3CP%3EI%20was%20working%20on%20a%20case%20recently%2C%20where%20the%20users%20were%20trying%20to%20delete%20the%20Index%20from%20SharePoint%20Cloud%20SSA%20and%20when%20followed%20the%20article%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Farchive%2Fblogs%2Fspses%2Fcloud-search-service-application-removing-items-from-the-office-365-search-index%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Farchive%2Fblogs%2Fspses%2Fcloud-search-service-application-removing-items-from-the-office-365-search-index%3C%2FA%3E%26nbsp%3B%2C%20it%20had%20the%20script%20to%20perform%20the%20same.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHowever%2C%20the%20end%20user%20had%20their%20accounts%20configured%20with%20Multi%20Factor%20Authentication%20and%20the%20above%20didn't%20have%20the%20context.%3CBR%20%2F%3E%3CBR%20%2F%3EWent%20ahead%20and%20tweaked%20the%20script%20and%20wrote%20one%20to%20leverage%20the%20App%20Context%20and%20connect%20to%20the%20SPO%20Service.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlternatively%2C%20You%20can%20use%3C%2FP%3E%0A%3CP%3EPowerShell%20PnP%20authentication%20manager%20which%20allows%20for%20a%20web%20login%20to%20provide%20your%20SPO%20credentials%2C%20which%20will%20allow%20for%20MFA.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3E%26lt%3B%23%3CBR%20%2F%3E.SYNOPSIS%3CBR%20%2F%3EIssue%20a%20call%20to%20SharePoint%20Online%20to%20delete%20all%20metadata%20from%20on-premises%20content%20that%20was%3CBR%20%2F%3Eindexed%20through%20cloud%20hybrid%20search.%20This%20operation%20is%20asynchronous.%3CBR%20%2F%3E.PARAMETER%20PortalUrl%3CBR%20%2F%3ESharePoint%20Online%20portal%20URL%2C%20for%20example%20'%3CA%20href%3D%22https%3A%2F%2Fabhassai.sharepoint.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fabhassai.sharepoint.com%3C%2FA%3E'.%3CBR%20%2F%3E.PARAMETER%20Credential%3CBR%20%2F%3ELogon%20credential%20for%20tenant%20admin.%20Will%20prompt%20for%20credential%20if%20not%20specified.%3CBR%20%2F%3E%23%26gt%3B%3CBR%20%2F%3Eparam(%3CBR%20%2F%3E%5BParameter(Mandatory%3D%24true%2C%20HelpMessage%3D%22SharePoint%20Online%20portal%20URL%2C%20for%20example%20'%3CA%20href%3D%22https%3A%2F%2Fcontoso.sharepoint.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcontoso.sharepoint.com%3C%2FA%3E'.%22)%5D%3CBR%20%2F%3E%5BValidateNotNullOrEmpty()%5D%3CBR%20%2F%3E%5BString%5D%20%24PortalUrl%2C%3C%2FP%3E%0A%3CP%3E%5BParameter(Mandatory%3D%24false%2C%20HelpMessage%3D%22Logon%20credential%20for%20tenant%20admin.%20Will%20be%20prompted%20if%20not%20specified.%22)%5D%3CBR%20%2F%3E%5BPSCredential%5D%20%24Credential%3CBR%20%2F%3E)%3C%2FP%3E%0A%3CP%3E%24AzureEnvironment%20%3D%20%22AzureCloud%22%3CBR%20%2F%3E%24IsGermanCloud%20%3D%20%24false%3CBR%20%2F%3E%24IsChinaCloud%20%3D%20%24false%3CBR%20%2F%3E%24IsITARvNext%20%3D%20%24false%3CBR%20%2F%3EIf%20(%24Portalurl.EndsWith(%22.de%22)%20-or%20%24Portalurl.EndsWith(%22.de%2F%22))%3CBR%20%2F%3E%7B%3CBR%20%2F%3E%24IsGermanCloud%20%3D%20%24true%3CBR%20%2F%3E%24AzureEnvironment%20%3D%20%22AzureGermanyCloud%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3EIf%20(%24Portalurl.EndsWith(%22.cn%22)%20-or%20%24Portalurl.EndsWith(%22.cn%2F%22))%3CBR%20%2F%3E%7B%3CBR%20%2F%3E%24IsChinaCloud%20%3D%20%24true%3CBR%20%2F%3E%24AzureEnvironment%20%3D%20%22AzureChinaCloud%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3EIf%20(%24Portalurl.EndsWith(%22.dps.mil%22)%20-or%20%24Portalurl.EndsWith(%22.dps.mil%2F%22)%20-or%20%24Portalurl.EndsWith(%22.sharepoint-mil.us%22)%20-or%20%24Portalurl.EndsWith(%22.sharepoint-mil.us%2F%22)%20-or%20%24Portalurl.EndsWith(%22.sharepoint.us%22)%20-or%20%24Portalurl.EndsWith(%22.sharepoint.us%2F%22))%3CBR%20%2F%3E%7B%3CBR%20%2F%3E%24IsITARvNext%20%3D%20%24true%3CBR%20%2F%3E%24AzureEnvironment%20%3D%20%22USGovernment%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3EIf%20(%24IsPortalForUSGovernment)%3CBR%20%2F%3E%7B%3CBR%20%2F%3E%24AzureEnvironment%20%3D%20%22USGovernment%22%3CBR%20%2F%3E%7D%3C%2FP%3E%0A%3CP%3E%24SP_VERSION%20%3D%20%2215%22%3CBR%20%2F%3E%24regKey%20%3D%20Get-ItemProperty%20-Path%20%22HKLM%3A%5CSOFTWARE%5CMicrosoft%5COffice%20Server%5C15.0%5CSearch%22%20-ErrorAction%20SilentlyContinue%3CBR%20%2F%3Eif%20(%24regKey%20-eq%20%24null)%20%7B%3CBR%20%2F%3E%24regKey%20%3D%20Get-ItemProperty%20-Path%20%22HKLM%3A%5CSOFTWARE%5CMicrosoft%5COffice%20Server%5C16.0%5CSearch%22%20-ErrorAction%20SilentlyContinue%3CBR%20%2F%3Eif%20(%24regKey%20-eq%20%24null)%20%7B%3CBR%20%2F%3Ethrow%20%22Unable%20to%20detect%20SharePoint%20Server%20installation.%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%24SP_VERSION%20%3D%20%2216%22%3CBR%20%2F%3E%7D%3C%2FP%3E%0A%3CP%3E%24code%20%3D%20%40%22%3CBR%20%2F%3Eusing%20System%3B%3CBR%20%2F%3Eusing%20System.Net%3B%3CBR%20%2F%3Eusing%20System.Security%3B%3CBR%20%2F%3Eusing%20Microsoft.SharePoint%3B%3CBR%20%2F%3Eusing%20Microsoft.SharePoint.Administration%3B%3CBR%20%2F%3Eusing%20Microsoft.SharePoint.Client%3B%3CBR%20%2F%3Eusing%20Microsoft.SharePoint.IdentityModel%3B%3CBR%20%2F%3Eusing%20Microsoft.SharePoint.IdentityModel.OAuth2%3B%3C%2FP%3E%0A%3CP%3Estatic%20public%20class%20ClientContextHelper%3CBR%20%2F%3E%7B%3CBR%20%2F%3Epublic%20static%20ClientContext%20GetAppClientContext(string%20siteUrl)%3CBR%20%2F%3E%7B%3CBR%20%2F%3ESPServiceContext%20serviceContext%20%3D%20SPServiceContext.GetContext(SPServiceApplicationProxyGroup.Default%2C%20SPSiteSubscriptionIdentifier.Default)%3B%3CBR%20%2F%3Eusing%20(SPServiceContextScope%20serviceContextScope%20%3D%20new%20SPServiceContextScope(serviceContext))%3CBR%20%2F%3E%7B%3CBR%20%2F%3EClientContext%20clientContext%20%3D%20new%20ClientContext(siteUrl)%3B%3CBR%20%2F%3EICredentials%20credentials%20%3D%20null%3B%3CBR%20%2F%3EclientContext.ExecutingWebRequest%20%2B%3D%20(sndr%2C%20request)%20%3D%26gt%3B%3CBR%20%2F%3E%7B%3CBR%20%2F%3Erequest.WebRequestExecutor.RequestHeaders.Add(HttpRequestHeader.Authorization%2C%20%22Bearer%22)%3B%3CBR%20%2F%3Erequest.WebRequestExecutor.WebRequest.PreAuthenticate%20%3D%20true%3B%3CBR%20%2F%3E%7D%3B%3C%2FP%3E%0A%3CP%3E%2F%2F%20Run%20elevated%20to%20get%20app%20credentials%3CBR%20%2F%3ESPSecurity.RunWithElevatedPrivileges(delegate()%3CBR%20%2F%3E%7B%3CBR%20%2F%3Ecredentials%20%3D%20SPOAuth2BearerCredentials.Create()%3B%3CBR%20%2F%3E%7D)%3B%3C%2FP%3E%0A%3CP%3EclientContext.Credentials%20%3D%20credentials%3B%3C%2FP%3E%0A%3CP%3Ereturn%20clientContext%3B%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%22%40%3C%2FP%3E%0A%3CP%3E%24assemblies%20%3D%20%40(%3CBR%20%2F%3E%22System.Core.dll%22%2C%3CBR%20%2F%3E%22System.Web.dll%22%2C%3CBR%20%2F%3E%22Microsoft.SharePoint%2C%20Version%3D%24SP_VERSION.0.0.0%2C%20Culture%3Dneutral%2C%20PublicKeyToken%3D71e9bce111e9429c%22%2C%3CBR%20%2F%3E%22Microsoft.SharePoint.Client%2C%20Version%3D%24SP_VERSION.0.0.0%2C%20Culture%3Dneutral%2C%20PublicKeyToken%3D71e9bce111e9429c%22%2C%3CBR%20%2F%3E%22Microsoft.SharePoint.Client.Runtime%2C%20Version%3D%24SP_VERSION.0.0.0%2C%20Culture%3Dneutral%2C%20PublicKeyToken%3D71e9bce111e9429c%22%3CBR%20%2F%3E)%3C%2FP%3E%0A%3CP%3EAdd-Type%20-AssemblyName%20(%22Microsoft.SharePoint.Client%2C%20Version%3D%24SP_VERSION.0.0.0%2C%20Culture%3Dneutral%2C%20PublicKeyToken%3D71e9bce111e9429c%22)%3CBR%20%2F%3EAdd-Type%20-AssemblyName%20(%22Microsoft.SharePoint.Client.Search%2C%20Version%3D%24SP_VERSION.0.0.0%2C%20Culture%3Dneutral%2C%20PublicKeyToken%3D71e9bce111e9429c%22)%3CBR%20%2F%3EAdd-Type%20-AssemblyName%20(%22Microsoft.SharePoint.Client.Runtime%2C%20Version%3D%24SP_VERSION.0.0.0%2C%20Culture%3Dneutral%2C%20PublicKeyToken%3D71e9bce111e9429c%22)%3CBR%20%2F%3EAdd-Type%20-TypeDefinition%20%24code%20-ReferencedAssemblies%20%24assemblies%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%26lt%3B%23%20if%20(%24Credential%20-eq%20%24null)%3CBR%20%2F%3E%7B%3CBR%20%2F%3E%24Credential%20%3D%20Get-Credential%20-Message%20%22SharePoint%20Online%20tenant%20admin%20credential%22%3CBR%20%2F%3E%7D%20%23%26gt%3B%3CBR%20%2F%3EConnect-MsolService%20-AzureEnvironment%20%24AzureEnvironment%3CBR%20%2F%3E%24cctx%20%3D%20%5BClientContextHelper%5D%3A%3AGetAppClientContext(%24PortalUrl)%3C%2FP%3E%0A%3CP%3E%24manager%20%3D%20New-Object%20Microsoft.SharePoint.Client.Search.ContentPush.PushTenantManager%20%24cctx%3CBR%20%2F%3E%24task%20%3D%20%24manager.DeleteAllCloudHybridSearchContent()%3CBR%20%2F%3E%24cctx.ExecuteQuery()%3C%2FP%3E%0A%3CP%3EWrite-Host%20%22Started%20delete%20task%20(id%3D%24(%24task.Value))%22%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1398351%22%20slang%3D%22en-US%22%3E%3CP%3EPerforming%20an%20Index%20Reset%20for%20your%20Cloud%20SSA%20%2C%20where%20accounts%20have%20been%20configured%20with%20Multi%20Factor%20Authentication.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1398351%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Emfa%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esharepoint%20hybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharepoint%20Search%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

I was working on a case recently, where the users were trying to delete the Index from SharePoint Cloud SSA and when followed the article https://docs.microsoft.com/en-gb/archive/blogs/spses/cloud-search-service-application-removing-items... , it had the script to perform the same.

 

However, the end user had their accounts configured with Multi Factor Authentication and the above didn't have the context.

Went ahead and tweaked the script and wrote one to leverage the App Context and connect to the SPO Service.

 

Alternatively, You can use

PowerShell PnP authentication manager which allows for a web login to provide your SPO credentials, which will allow for MFA.

<#
.SYNOPSIS
Issue a call to SharePoint Online to delete all metadata from on-premises content that was
indexed through cloud hybrid search. This operation is asynchronous.
.PARAMETER PortalUrl
SharePoint Online portal URL, for example 'https://abhassai.sharepoint.com'.
.PARAMETER Credential
Logon credential for tenant admin. Will prompt for credential if not specified.
#>
param(
[Parameter(Mandatory=$true, HelpMessage="SharePoint Online portal URL, for example 'https://contoso.sharepoint.com'.")]
[ValidateNotNullOrEmpty()]
[String] $PortalUrl,

[Parameter(Mandatory=$false, HelpMessage="Logon credential for tenant admin. Will be prompted if not specified.")]
[PSCredential] $Credential
)

$AzureEnvironment = "AzureCloud"
$IsGermanCloud = $false
$IsChinaCloud = $false
$IsITARvNext = $false
If ($Portalurl.EndsWith(".de") -or $Portalurl.EndsWith(".de/"))
{
$IsGermanCloud = $true
$AzureEnvironment = "AzureGermanyCloud"
}
If ($Portalurl.EndsWith(".cn") -or $Portalurl.EndsWith(".cn/"))
{
$IsChinaCloud = $true
$AzureEnvironment = "AzureChinaCloud"
}
If ($Portalurl.EndsWith(".dps.mil") -or $Portalurl.EndsWith(".dps.mil/") -or $Portalurl.EndsWith(".sharepoint-mil.us") -or $Portalurl.EndsWith(".sharepoint-mil.us/") -or $Portalurl.EndsWith(".sharepoint.us") -or $Portalurl.EndsWith(".sharepoint.us/"))
{
$IsITARvNext = $true
$AzureEnvironment = "USGovernment"
}
If ($IsPortalForUSGovernment)
{
$AzureEnvironment = "USGovernment"
}

$SP_VERSION = "15"
$regKey = Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Office Server\15.0\Search" -ErrorAction SilentlyContinue
if ($regKey -eq $null) {
$regKey = Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Office Server\16.0\Search" -ErrorAction SilentlyContinue
if ($regKey -eq $null) {
throw "Unable to detect SharePoint Server installation."
}
$SP_VERSION = "16"
}

$code = @"
using System;
using System.Net;
using System.Security;
using Microsoft.SharePoint;
using Microsoft.SharePoint.Administration;
using Microsoft.SharePoint.Client;
using Microsoft.SharePoint.IdentityModel;
using Microsoft.SharePoint.IdentityModel.OAuth2;

static public class ClientContextHelper
{
public static ClientContext GetAppClientContext(string siteUrl)
{
SPServiceContext serviceContext = SPServiceContext.GetContext(SPServiceApplicationProxyGroup.Default, SPSiteSubscriptionIdentifier.Default);
using (SPServiceContextScope serviceContextScope = new SPServiceContextScope(serviceContext))
{
ClientContext clientContext = new ClientContext(siteUrl);
ICredentials credentials = null;
clientContext.ExecutingWebRequest += (sndr, request) =>
{
request.WebRequestExecutor.RequestHeaders.Add(HttpRequestHeader.Authorization, "Bearer");
request.WebRequestExecutor.WebRequest.PreAuthenticate = true;
};

// Run elevated to get app credentials
SPSecurity.RunWithElevatedPrivileges(delegate()
{
credentials = SPOAuth2BearerCredentials.Create();
});

clientContext.Credentials = credentials;

return clientContext;
}
}
}
"@

$assemblies = @(
"System.Core.dll",
"System.Web.dll",
"Microsoft.SharePoint, Version=$SP_VERSION.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c",
"Microsoft.SharePoint.Client, Version=$SP_VERSION.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c",
"Microsoft.SharePoint.Client.Runtime, Version=$SP_VERSION.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c"
)

Add-Type -AssemblyName ("Microsoft.SharePoint.Client, Version=$SP_VERSION.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c")
Add-Type -AssemblyName ("Microsoft.SharePoint.Client.Search, Version=$SP_VERSION.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c")
Add-Type -AssemblyName ("Microsoft.SharePoint.Client.Runtime, Version=$SP_VERSION.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c")
Add-Type -TypeDefinition $code -ReferencedAssemblies $assemblies


<# if ($Credential -eq $null)
{
$Credential = Get-Credential -Message "SharePoint Online tenant admin credential"
} #>
Connect-MsolService -AzureEnvironment $AzureEnvironment
$cctx = [ClientContextHelper]::GetAppClientContext($PortalUrl)

$manager = New-Object Microsoft.SharePoint.Client.Search.ContentPush.PushTenantManager $cctx
$task = $manager.DeleteAllCloudHybridSearchContent()
$cctx.ExecuteQuery()

Write-Host "Started delete task (id=$($task.Value))"