admin
74 TopicsOffice 365 Admin Role Needed for MFA
I would like to assign members of the help desk access to manage MFA for non-admin users. I already assigned the Authentication admin role and this partially works. Right now the help desk can go into AAD, switch to Authentication methods and do everything that is needed there. However, as a Global Admin from the Microsoft 365 admin center I can see Users > Active Users > Multi-Factor Authentication and I can manage Manage multifactor authentication from the User itself. These options are not available for the help desk. Is there another role that I can use to grant access to the legacy MFA management portal?Solved104KViews4likes22CommentsDo you have to buy Premium P2 for every licensed user to use Privileged Identity Management
Do you have to buy Active Directory Premium P2 for every licensed user in your tenant to use Privileged Identity Management or can you just purchase it for the admin accounts you want to manage? $8 a month for every user is steep if you just want to control admin access but not too bad if we just had it on our admin users.1.3KViews3likes1CommentConnect-SPOService : Could not authenticate to SharePoint Online
Hi All! I am unable to connect to SPO from SharePoint online management shell using my account. MFA is enabled. Connect-SPOService -url https://[URL].sharepoint.com I'm getting the following response: Connect-SPOService : Could not authenticate to SharePoint Online https://[URL].sharepoint.com/ using OAuth 2.0 At line:1 char:1 + Connect-SPOService -url https://[URL].sharepoint.com + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [Connect-SPOService], AuthenticationException + FullyQualifiedErrorId : Microsoft.Online.SharePoint.PowerShell.AuthenticationException,Microsoft.Online.SharePoi nt.PowerShell.ConnectSPOService Can anyone help with this? Thanks.20KViews1like3CommentsSole Global Admin locked out - lost MFA device, SSPR phone verification returns error
Hello, I am the sole Global Administrator of a Microsoft 365 Business Standard tenant and I am completely locked out of the account. What happened: - My phone with Microsoft Authenticator was physically destroyed. - I installed Authenticator on a new phone. My personal account restored from cloud backup, but the work account only appears as a "connected account" - it shows no TOTP code and receives no push notifications. Push requests still go to the old device. What I tried while my admin session was still alive: - Entra ID > per-user MFA > "Require selected users to provide contact methods again" - saved successfully. - User > Authentication methods > "Require re-register multifactor authentication" - returned "Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade." - The Authentication methods list for the user was EMPTY, and default sign-in method showed "No default". "Add authentication method" button was greyed out. - "Revoke sessions" - succeeded, but this also terminated my own admin session and signed me out of Outlook and OneDrive. - aka.ms/mfasetup cannot be reached because it requires a fresh MFA challenge. Self-service password reset (passwordreset.microsoftonline.com): - First verification via alternate email succeeds every time (I have full access to that mailbox). - Second verification fails: both "Text my mobile phone" and "Call my office phone" return "Sorry, we ran into a problem contacting you." I tried +370xxxxxxx, 370xxxxxxx and 8xxxxxxxx formats - same error every time. This looks like a service-side failure, not a formatting issue. - Sign-in Helper now also reports "Account blocked due to multiple incorrect password attempts." Error codes seen: 500121 and AADSTS50133. I have tried calling Microsoft support in several countries. The automated system either asks for an internal extension number or the AI assistant disconnects the call before reaching a human. There is no second Global Admin and no recovery codes. I can provide the tenant ID, user unique identifier, subscription order number and proof of access to the billing email address privately. Requesting escalation to the Data Protection team for admin account recovery. Any guidance on how to reach a human agent would be greatly appreciated. Thank you.282Views1like4CommentsStuck in an authenticator loop
I have a 365 Business account. Haven't logged in for a while due to reasons, i was just starting up as a sole trader. Anyway decided now is the time to resurrect it and get up and running, except Authenticator doesn't work because I changed my phone, and my back up email is out of date, and no longer exists. I have tried the support web chat which wants to send a code to authenticator or my back up email. Just called the help line that referred me to the web chat which doesn't work, I couldn't get past the bot. So I am stuck. Any recovery options does not recognise my log in details, i think this is because its been a while since I logged in (I still pay but ....) but I can't resurrect it because I don't have a way of getting a code due to authenticator/back up email as cited above. I am really at a loss as to what to do. I don't want to abandon it and start again as there are documents in my one drive that I need. Can anyone help please. (I think all that needs to happen is an update to my back up email and then I can get going). I am the sole administrator on my business account.201Views1like3CommentsCan't Login to Authenticator App
I am unable to login to my Microsoft 365 Business account, because I'm unable to login to my Authenticator App. I am also the only administrator on my business account, so no one in my organization can help me. Microsoft online support and phone support just keep sending me in circles. The only way I see to create a support ticket is to login, but my issue is that I can't login. Help, please!243Views1like3CommentsBest setup for multiple machines
I have a live account for my email address as I have a surface and originally registered for an account to use for machine backups, browsing syncing etc. I also use onenote and wanted it syncing to a 365 onedrive account so I signed up for office 365 business basics so that I could sync onedrive and all of the associated attachments, audio records etc to it. I would love to use use the paid business account but I cant sign into the surface with the business account, only home accounts as I dont have pro. The next issue is that I use another laptop, android tablet and phone also signing into the business 365 account. These all used to sync fine but now, all other devices disconnect as the one you have signed into it connects. Not a major issue, you sign into the device you want to use, sync and then continue However i jump from device to device that often that it starts to grate on me that i cant just grab a device and sync. Is there any way I can register each device so that they are trusted and then more than one device can stay connected.190Views1like1CommentAzure AD Connect Admin Audit log
Hi, Does anyone know if there is an Admin audit log for AADConnect? i'm looking for something that logs when an admin has, for example, made a change to the sync, such as adding or removing an OU from the sync scope, manually triggering an initial or delta sync, opening the admin tools or opening the connectors in edit mode? i am seeing a lot of clients systems whereby AAD Connect spends a lot of its time complaining about the need for an initial sync, I suspect a lot of these cases are where an admin has opened the sync and OK'd, or even cancelled out, but it seems to have marked the connector as changed. it seems odd that there is no evident admin audit log for something as critical, and security sensitive, as AAD Connect, if there isnt. if it relies on logging to event viewer only, then is there any guidance or documentation (i haven't managed to find any) to identify which event IDs would correlate to the above activities, trawling the logs so far i havent found anything identifying when a connector has been changed or, frankly, when an admin has opened or used the tools (MIISClient or Azure AD Connect app/tool) Thanks in advance for your input. Pete90KViews1like22CommentsHoldings and Subsidiaries - How to manage?
Hello and greetings from Portugal, I'm looking for some advice about how should I manage a client's request. They're changing they're structure in the following way. They're creating an holding and some subsidiaries. How should a manage this, in a way that, although they are different companies, they have a "top company" and they should be able to find themselves in Teams, for example. Thanks in advance! Best regards, Diogo Sousa1.3KViews1like5CommentsGlobal Admin Locked Out - STILL no call back from "Data Protection Team"
Posting this here in the hope that someone will be able to help me. I'm the global admin of a small O365 tenancy and am locked out of the admin portal owing to my mobile phone (and subsequent Microsoft authenticator app) being damaged beyond repair meaning I cannot complete the MFA process to log in. Whilst I appreciate I should have had either a) a secondary method enabled such as a phone call or b) "break-glass" account with a complex password and no MFA, I need support with this issue ASAP. I have called the Microsoft support line no less than FIVE(!) times to be told that someone from the "Data Protection Team" will be calling me back within X hours yet it has now been over 2 weeks and I have still had no call. This is an M365 Business license and thus not the level of support I would expect. Please can someone advise on how to escalate this case (happy to provide case details via PM)2.9KViews1like6Comments