microsoft 365 apps
39 TopicsModern Auth Looping with Outlook 2016 when Outside Corporate Network
Hello! First time poster, here. In the past ~1-2 months, our travelling users have been running into an authentication loop in Outlook 2016. They will suddenly be asked to enter their password in Outlook (the larger, white, browser-based modern authentication window, not the small Outlook client username/password authentication window). Entering their password will close the window, then the window will immediately pop back up. The Outlook client cannot be used until they come back inside our network and reboot their PC. I was able to immediately reproduce the issue on my work laptop (64-bit Windows 10 1803 running Office 2016 32-bit version 1809) by deleting my Outlook profile, deleting all saved Office-related credentials in the Credential Manager, and connecting my laptop to my smartphone hotspot (to simulate being outside the network). Starting Outlook 2016, I'll create a new profile, connect with my AD account, enter my password in the Outlook 2016 authentication box; my email will actually start loading in Outlook, then the larger, white authentication window will pop up. I enter my password, it will disappear, then pop up again, and on, and on... We have worked with MS Support on this issue for a total of ~7 hours in multiple remote sessions, and here are the troubleshooting steps they took, which all failed: -Using an app password when the MFA browser window asks for the user’s password (“invalid password”) -Adding “HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\DisableADALatopWAMOverride” to the registry, with a DWORD value of 1 -Using “Fiddler” to collect logs while the issue occurred (the technician seemed like they had no idea how to use the program, since the certificates installed by the program effectively blocked Outlook 2016 from communicating with the Microsoft servers) -Turning on Outlook logging, and reproducing the issue. The logs were not affected in any way while the looping was taking place, leading us to believe that the issue is taking place outside of the Outlook application. -MS O365 Support then brushed it off as Incident EX152471, which was announced as resolved yesterday evening, but the problem still persists in our environment. The ONLY workaround that we found, is adding "DisableAADWAM" to HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\, and giving it a DWORD value of 1. But disabling Web Access Management is not a solution! Can anyone shed any light on our issue? Thank you, --Ryan67KViews1like11CommentsHow to reset the Authenticator app
Hello Microsoft Community. I'm consumer license and use a personal email account. I want to access on the account.microsoft.com. I have a problem on Microsoft account that has a Microsoft Authenticator app that I never used or set up before. As I believe that this issue will be assisted and commented by research engineers, social engineers, moderator, administrator and developers. I'm hoping for the response of this concern. Thank you, Michael.41KViews0likes1CommentWindows AD account password expired but user can still send/receive email and use Teams
Hi. I recently discovered that some users with expired AD passwords are still working as if nothing has changed, which caught me by surprise. All the users affected do not use the VPN on a regular basis, or sign into Office 365. They all use desktop office for their email (Outlook) and chats (Teams). We are all still working from home. It appears as if a user is only challenged to update their expired password once they physically authenticate against the domain controller(s). But what if they never do? This means a user with an expired password will continue to send/receive emails and send chats in Teams regardless of when their password expired, unless they perform some form of "logon". I ran a PowerShell script to elucidate more and found that we have dozens of users in this boat. Some users have passwords that expired YEARS ago! Is this by design? In that the password expiration attribute is pointless until said account actively connects or authenticates to the domain? Why is the "expiration" attribute not part of the user SID? I'm baffled. We have on premise domain controllers which syncs out to Office 365 via ADSync and this is syncing fine with no errors, including password sync. Any help appreciated.Solved32KViews0likes2CommentsOutlook Modern Auth not working
I am still being affected by this and I have a mix of users with the reg key and without https://techcommunity.microsoft.com/t5/identity-authentication/modern-auth-looping-with-outlook-2016-when-outside-corporate/m-p/280804 We are a 300 person Firm all working remote and the last thing I need is for Outlook to act all screwy. Has anyone fixed this? is this a bug? Has Microsoft stated what the actual fix for this is? WIndows Build 1903 18362.657: Outlook for O365 16.0.11929.20586 Just to recap I have user with and without the reg key in the post above and were still having the issue. Has anyone solved this?28KViews0likes6CommentsFIDO2 Office 365 and Windows Hello For Business Sign-in?
I saw that this was in preview a year ago. https://techcommunity.microsoft.com/t5/Azure-Active-Directory-Identity/bg-p/Identity Is logging into Windows 10 Hybrid joined systems using FIDO security keys now working? What about signing into Office 365 desktop apps, mobile apps and web apps with FIDO security keys?11KViews1like2CommentsHow to exclude O365 desktop apps from MFA when using Conditional Access?
Hi all. I'm have a little trouble excluding the O365 desktop apps from my Conditional Access policy. I have set up a policy to force MFA when accessing MS admin sites such as Azure, Exchange etc, I want this in place to protect them of course. But since I created the policy (with only myself as a test user) I am now getting the likes of Excel failing to log in, and requiring MFA to complete a log in. The policy is "Include all cloud apps". My Conditional Access policy has exclusions for "Office 365" and "Microsoft Cloud App Security" (the last was a stab in the dark). I figured that would allow the apps to bypass this policy, but I'm still having to pass MFA to allow Excel to sign in. I'm not worried if MFA remains on OWA or any other web based access as they aren't used much and I'm happy for them to be MFA'd anyway. Can anyone tell me if there is a way to exclude the desktop apps from MFA but still retain cloud protection? Thanks, Rich.Solved6.9KViews0likes2CommentsHow to share confidential files
Hi, not sure if this is the right channel please refer me to the rigth one if not. We would like to share a report (stored in our SharePoint Online) with specific people at one of our clients (who also are in O365 by the way). I wanted to do this by restricting access on the file itself using the built in feature for this and then add those email adresses needed to allow specific people to read the file. However, I ran into multiple issues. 1. When restricting access. No one else in my org. could retain full control access to the file (I want anyone in my org to be able to add recipients, make changes, print etc). Adding users to the list of people who can edit the file is not sufficient. 2. When people at our client clicks on the link they get a prompt saying "Sorry, Word cannot open this document in a browser because it is protected by IRM..." with no link or option to open in desktop instead. 3. when they try to open it from within e.g. Word they still cannot access even if their email-address is in the list of allowed readers. 4. It works if we send a copy of the file - but that is likely less secure and creates unneccessary redundance and diverging versions of the file. What is the "proper" way of doing this?5.2KViews0likes8CommentsHow can I restrict other team members to view and edit certain sheets within an excel?
We have an excel document to collect team members commission information. Every team member maintains own data in different worksheet in this file. But as it's sensitive data, everyone should only be able to access his/her own data or their own team's data, not other people or teams. Can anyone suggest a way to realize it?4.4KViews0likes2CommentsEnabling modern authentication : Impacts
Hi All, In our organization , we are planning to roll out modern authentication for Exchange,SharePoint and Skype for Business which is currently disabled. If we enable it at tenant level, will there be any impact at end user level? We only have Outlook 2016 and above in our tenant. Regards, Saikrishna M4KViews0likes1Comment