authentication
373 Topics[URGENT] Sole Global Admin MFA Lockout - No escalation after 7 days (Ticket #2609050040000232)
Hello, I'm dealing with a critical "Sole Global Administrator MFA Lockout" scenario for one week now, and standard ticket support is taking 24h per reply with no effective escalation so far. Ps: I had to use my personnel account to login because my business account is unavailable!! PROBLEM SUMMARY: After switching phones, the only registered MFA method (Microsoft Authenticator) became orphaned. There's no MFA backup method and no working second admin account on the tenant. As a result, I'm locked out of: - Microsoft 365 Admin Center login - Microsoft Entra Admin Center login - Corporate email and Teams access WHAT I'VE ALREADY TRIED (unsuccessfully): - Deleting the broken MFA method (error: "delete operation failed") - Enabling and generating a Temporary Access Pass (blocked - admins cannot generate a TAP for themselves, and the second admin account is also affected by the same broken MFA issue) - Checking for account lockout status (not the case) - Error received during sign-in attempts: Error Code 500121 OPEN TICKET: Ticket #2609050040000232, open for 5 days now, only generic responses received so far. REQUEST: Could someone from the Microsoft team (moderator, MVP, or any direct contact) help escalate this to the Tenant Recovery / Data Protection team? I'm available to prove tenant ownership (domain control, subscription details, billing information). Any guidance on how to expedite this specific type of case would be greatly appreciated. Thank you.105Views0likes1CommentMicrosoft values a hacker's disposable email more than your email linked to Microsoft for 8 years
My Pc was compromised and my session tokens were stolen . I had security info connected with my email and phone number . I also had passkey setup on both my pc (after reset) and my phone . It took one click for the hacker to remove the security features . They setup their own security info and added a disposable email instead of mine . I was somehow able to log in to the account using my pc passkey , as it was already signed in . First I requested to change the hacker's email to my one , which was useless cause the wait time period was 30 days . But in doing so I locked myself out of recovering the account with the mail that notified me that my security info was changed . I went to account recovery which only allowed me to change the password not the email so its still connected to the hacker's email . My frustration is the hacker can 1 click change my forever linked email since accounts creation . But when i try to do so they prevents me to do that stating that "there was recent security information change and the account will not allow for additional change for 30 years" . I opened up "account recovery form" and filled it out , point to be noted there were no fields where I could enter my details of my problem they just ask some basic information . After sometime they send a mail stating provided information is not enough . How am i suppose to provide more information if there are no fields for additional information . I contacted Microsoft agent , they guided me to reply to the account recovery form mail which did not worked as I was not allowed to reply on such email . I contacted Microsoft agent again , this time they told me I will be getting an email with account recovery form and I should mention every details . Well it was the same recovery form I used earlier with limited fields . I still field out the form and after sometime I was mailed by mailto:email address removed for privacy reasons to provide additional details for my identify , I was again requested to submit an account recovery form on https://account.live.com/acsr?cs=1 which was the same link with limited fields to provide information . I proceeded but in the end I was told that I have reached the daily limit for submitting form for this account . Just to be sure I mailed mailto:email address removed for privacy reasons the requested details .41Views0likes0CommentsTrapped in an Authenticator Loop
Dear Community, please help! I am trapped in an Authenticator Loop. I've got a microsoft workplace account, but if I want to log in, I have to type in a code from the microsoft authenticator app. I downloaded the app, but in order to use it, I have to log into my account and in order to do so, I also have to type in a code from the authenticator app, which I don't get, because to get the code I would have to log into the authenticator app, what I would need a code for... No matter which link I click, I can't open anything before I enter the code, which I can't get. I am using teams on mac, either on a firefox browser or on the desktop app and the authenticator on an Iphone. Please don't just tell me "don't use teams on a mac", this wasn't my choice. Unfortunately, my emplyer's IT support also is chronically unavailable. So is here anyone who could help me? I've already gone through the usual deleting the app, using another browser etc. options. Best Lukas1.2KViews0likes5CommentsMicrosoft Teams and Authenticator lockdown
I’m having a very frustrating issue with Microsoft Teams. I am able to log in to teams using my normal personal email and account ONLY ON THE WEB BROWSER. From the web browser, I am not able to access the business channel that I am in. When attempting to log in on the downloaded mobile Teams App, I am sent directly to Microsoft Authenticator, which after waiting several hours, waiting even a full day, is still displaying a message about repeated verification attempt and to wait and try again later. I have accessed Microsoft support chat and they had no help for me. I need the authenticator lockdown to refresh and it will not.226Views0likes1CommentAuthenticator não funciona
Tenho um e-mail corporativo (sou o adm único, nao tem ti) que faço login na conta do powerbi, contudo, meu celular com o authenticator foi perdido e já nao tenho mais acesso, por este motivo, nao consigo mais logar na conta pq ele sempre direciona para o authenticador que nao tenho mais acesso e não abre a possibilidade de receber o codigo por outro meio, (sms ou email). ja tentei vários recursos (chat, telefone do suporte) para recuperar a conta e nao consigo. Todas as opções direcionam para o autenticador. solicito a microsoft que dê uma solução, resetando o autenticador anterior para que eu possa acessar a conta e incluir métodos alternativos de desbloqueio, ou sugira outra solução.170Views0likes1CommentNot able to do an account recovory when 2FA is enabled and Passkeey is half set up
I am not able to log into my personal account. I have tried account recovery, but I have 2FA set up so I go a message saying this is ignored. I have rest the password using 2FA but when I try to login the message is that I can not use password to login. I beleive my partern loged me out of the account and tried to log in to her account but instead started Passkey set up. I have needed to login with my company account even to raise this post. Any help would be great.154Views0likes1CommentM365, Entra ID, Google Password Manager Passkeys
I went into my tenant, opened the Entra ID Admin, and enabled passkeys (fido2) authentication. I want to use Google Password manager since it will work across al my devices/platforms (Windows, Mac, Android, iOS). I went into the security settings for Microsoft 365 account to add an authentication method. I am happy to say that "passkey" is listed as an option, so I created a new passkey in Google Chrome/Password Manager and named it after my userid in the tenant. To test it, I logged out and attempted to log in using the passkey. The option came up, but Microsoft complained it was not a valid key. I tried again stating that I would my phone for the key and scanned the QR code but my phone said there is no passkey I would need to create one. How do I solve this? BTW: I did add Google's AAGUID in the Entra admin and allowed it but that did not solve the issue.Solved296Views0likes2CommentsHow do I get support so I don't loose my account?
I have a business 365 account but changed address and so my credit card payments stopped. However, I can't log in to my account because I also have an authentication problem (my authentication app on iPhone is still working but the entry for this account has gone and there is a new one called "Microsoft Entra ID" but when I go to get the authentication code this "Entra ID" authenticator does not produce it). To get help from Microsoft it always asks for authentication. I would like to keep this account and start paying again but I can't find a way to get help to fix the authentication problem because raising a ticket or talking to an agent requires authentication. I got my final warning email today saying Warning—your online services will be deprovisioned and your data deleted in seven days There must be some way to get a call from Microsoft so I don't loose my account and all my data?Solved287Views0likes6CommentsHow to target Azure VPN (Microsoft-Registered) app with Conditional Access Policies?
I have an Azure Point-to-Site VPN Gateway configured using the Microsoft-registered Azure VPN Client App ID (Audience value: c632b3df-fb67-4d84-bdcf-b95ad541b5c8). Everything is working correctly for our users. The issue I am having is that anyone with an Entra account can connect to the VPN and I want to restrict this with a blocking Conditional access policy. I do not want to create a custom app registration, because then I will have to change the 'audience' value on the app gateway and all user's will need to modify their VPN clients. The problem is I need to target the Microsoft-registered Azure VPN app in a Conditional Access policy but it does not appear in my Enterprise Applications list or in the CA app picker when searching. My questions: Why does the Microsoft-registered app not automatically create a service principal in my tenant the way other Microsoft apps do? Is there a supported way to make it appear in the CA app picker without creating a custom app registration or changing the gateway Audience value? Has anyone successfully targeted c632b3df-fb67-4d84-bdcf-b95ad541b5c8 in a CA policy while keeping it as the gateway Audience value? Thanks for the assistance here223Views0likes2Comments