Passwords
5 TopicsLost mfa global admin can not login, no break glass account
No partner or another global admin or break glass account. Yes I know thats a mistake but just need mfa reset for the global admin account. Hi. I have been calling ms support for multiple days, on hold for hours at a time. I know the story about getting hold of the data protection team and there hold times. I can't login to my tenant to open a case since I lost my mfa, changed phones and the restore is not working. Already tried sspr and thats not working either, my backup email is not getting the pin. Anyone as MS that can help open a case vs being on hold for days at a time. txs M54Views0likes1CommentCan't change PasswordExpirationPolicy of all users with Update-MgUser
Hello, Ive got into a problem where we disabled Password expiration in the GUI but some account keep having it enabled when you look with Powershell. Microsoft provides a guide where they explain hot to set all users policy to never expire, sadly it doesn't work, I've tried it in several Tenants already. Here is the link to the guide: https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/set-password-to-never-expire?view=o365-worldwide The command: Get-MGuser -All | Update-MgUser -PasswordPolicies DisablePasswordExpiration The error when the command is used: Update-MgUser_UpdateViaIdentityExpanded: The pipeline has been stopped. Exception: InputObject has null value for InputObject.UserId I know that you should set a UserID as a scope for it to work, but this isn't possible as far as I know on update-mguser. Please help me find a solution to update everyone's PasswordExpirationPolicy to never expire. I was thinking about creating a script that goes through every userid and performs the action, but my knowledge isn't as advanced to create it.Solved596Views0likes1CommentHow to change user passwords in bulk - without force to change
Hello everyone, I'm in the process of updating the passwords for multiple users, and I'd like to set specific passwords of my choice. Additionally, I want to ensure that these accounts won't prompt users to change their passwords upon their first login. I'd greatly appreciate your assistance, as the scripts I previously used are no longer effective.Solved17KViews0likes3CommentsFIDO2 enabled user receive "Protect your account"
We are having issues in two different scenarios with Azure MFA for users who use FIDO2 exclusively. It seems, any settings somehow still require Microsoft Authenticator. First scenario: Registering FIDO2 after the 14 days grace period When a user is created in Azure (either directly or on-prem sync, no difference here), the user has a 14 days grace period. During this period, configuring FIDO2 works flawlessly using a Temporary Access Pass (TAP). After the 14 days, the user logs in using the provided TAP to https://aka.ms/mysecurityinfo, starts the "Add sign in method", follows the steps for the FIDO2 key, once the key is confirmed and the user is redirected back to mysecurityinfo, Azure prompts for a "Additional information is required" and requires the user to register the Microsoft Authenticator app first. The only logs we see is that the user interrupted the MFA setup. We tried several browsers, normal or incognito mode, different users, nothing prevented this, except for configuring MS Authenticator first, then configuring FIDO2 afterwards. We deleted the MS Authenticator app for these users as it was only a workaround. Now these users seem to face the second scenario below. Second scenario: FIDO2 sign in prompts for a "Protect your account" - skippable for 14 days Users are able to sign in using the FIDO2, and immediately after, they are prompted a "Protect your account" window, which asks them to configure MS Authenticator again. They have the option to skip this for 14 times (not days). If we check the user's sign in logs, it shows Failure for the user satisfying the Conditional Access requiring MFA, which is rather unexpected because the user does in fact manage to sign in using the FIDO2 security key, and is able to access the resources when skipping the "Protect your account" request. We thought it may be App specific, but finally the users face this issue with different apps (Workday, Concur, MS Teams...) After asking Google, many articles point out this is related to Security Defaults. This is not our case, as we are using Conditional Access and they are not compatible. The Conditional Access (CA) is enforcing an MFA of a custom Authentication Strength which includes the FIDO2 as one of the accepted options. The per-user MFA settings are configured to be Disabled for the affected users, as it is already enforced by the CA. The only setting that we have not modified yet is the Multifactor authentication registration policy which is set to Enabled - we cannot customise this as we have only P1 license (and we cannot find information if disabling this would later prevent us from enabling it afterwards due to missing license). As mentioned at the beginning, it seems there is somewhere a setting that expects everybody to use MS Authenticator for MFA regardless of what we configure, except if we disable MFA altogether (not gonna happen). Are there any other settings we should check or review or we can test? Thanks in advance.1.3KViews0likes2CommentsMultifactor page doenst show users and i cant disable or manage any options. App passwords broken to
We are using Office365 for Business and i've enabled mfa for our employees yesterday. It worked fine for the first hour, but after a while some of the MFA pages in my admin panel or the users account stopped working. We can set-up 2factor, but we cant create any new 'App passwords'. https://account.activedirectory.windowsazure.com/AppPasswords.aspx On this page we get a hard error inside the browser: Correlation-id: WEU#ea857e13-a859-4935-be0b-4a0c4e5f17a8 Errorcode: 0 When we try to disable mfa, the users arent listing on the following page: https://account.activedirectory.windowsazure.com/UserManagement/MultifactorVerification.aspx The users arent listing and we cant modify any settings. The problem we are having is that we cant generate App Passwords, which we need for Outlook and we cant disable mfa because of the users not listing in the admin center where we should be able to change mfa settings per user. Is there something going on with this part of Azure or am i doing something wrong?Solved3.4KViews0likes8Comments