multi-factor authentication
86 TopicsTrapped in an Authenticator Loop
Dear Community, please help! I am trapped in an Authenticator Loop. I've got a microsoft workplace account, but if I want to log in, I have to type in a code from the microsoft authenticator app. I downloaded the app, but in order to use it, I have to log into my account and in order to do so, I also have to type in a code from the authenticator app, which I don't get, because to get the code I would have to log into the authenticator app, what I would need a code for... No matter which link I click, I can't open anything before I enter the code, which I can't get. I am using teams on mac, either on a firefox browser or on the desktop app and the authenticator on an Iphone. Please don't just tell me "don't use teams on a mac", this wasn't my choice. Unfortunately, my emplyer's IT support also is chronically unavailable. So is here anyone who could help me? I've already gone through the usual deleting the app, using another browser etc. options. Best Lukas1.7KViews0likes6CommentsConditional Access enforces MFA but Service Account still ask to secure account
Hi, I've setup Conditional Access policies to enforce MFA. But it excludes a group for service accounts. Whenever we login to a Service Account, they all ask to secure your account. Hit next > It says no MFA options are available > Skip. Both our own MFA conditional access policy and MS per-user conditional access policy excludes this group. The Legacy per-user authentication policy has all accounts disabled there in favour of the conditional access policy. We must be missing something here. Some of these are shared inboxes, others regular user accounts. Many of these services requires login through the typical Microsoft sign in screen to authorize access. Some does not support OpenID. So how do I 100% exclude service accounts from MFA? And how do I get rid of this popup to secure these accounts when it says no MFA options are available? TIA1KViews0likes2CommentsCan't access Microsoft Authenticator for business accounts
Hello. I am the tech support for a small church, where I am the admin for our MS 365 accounts, which are set up as "business accounts". I have been using Microsoft Authenticator for MFA for years. Recently I switched to a new phone and installed Microsoft Authenticator. All of my personal Authenticator accounts transferred over just fine, but all of the church's business accounts say "Scan the QR Code provided by your organization to finish recovering this account". The thing is, I am the "organization" and I don't know how to generate any QR code to recover the accounts. It was suggested that I could do something about this by logging into my Microsoft 365 administrator account, but when I try to log into my admin account, the only MFA option is "enter the code from Microsoft Authenticator". It's not offering a text or alternate email, only Microsoft Authenticator, which is what I'm locked out of. So I'm stuck in a loop. I opened a ticket with Microsoft Support nine days ago. I have received one phone call since then. The support person insisted that they needed to talk to the account's "alternate administrator", which I set up as my pastor, who is pretty computer savvy but not a deep IT person. They tried to call him one time, but he was not available to answer right then. There has been no communication since then. I'm hoping someone in this group can help me figure this out.730Views2likes4CommentsSole Global Admin locked out - lost MFA device, SSPR phone verification returns error
Hello, I am the sole Global Administrator of a Microsoft 365 Business Standard tenant and I am completely locked out of the account. What happened: - My phone with Microsoft Authenticator was physically destroyed. - I installed Authenticator on a new phone. My personal account restored from cloud backup, but the work account only appears as a "connected account" - it shows no TOTP code and receives no push notifications. Push requests still go to the old device. What I tried while my admin session was still alive: - Entra ID > per-user MFA > "Require selected users to provide contact methods again" - saved successfully. - User > Authentication methods > "Require re-register multifactor authentication" - returned "Delete operation failed. Try this command again or delete them one by one in the user authentication methods blade." - The Authentication methods list for the user was EMPTY, and default sign-in method showed "No default". "Add authentication method" button was greyed out. - "Revoke sessions" - succeeded, but this also terminated my own admin session and signed me out of Outlook and OneDrive. - aka.ms/mfasetup cannot be reached because it requires a fresh MFA challenge. Self-service password reset (passwordreset.microsoftonline.com): - First verification via alternate email succeeds every time (I have full access to that mailbox). - Second verification fails: both "Text my mobile phone" and "Call my office phone" return "Sorry, we ran into a problem contacting you." I tried +370xxxxxxx, 370xxxxxxx and 8xxxxxxxx formats - same error every time. This looks like a service-side failure, not a formatting issue. - Sign-in Helper now also reports "Account blocked due to multiple incorrect password attempts." Error codes seen: 500121 and AADSTS50133. I have tried calling Microsoft support in several countries. The automated system either asks for an internal extension number or the AI assistant disconnects the call before reaching a human. There is no second Global Admin and no recovery codes. I can provide the tenant ID, user unique identifier, subscription order number and proof of access to the billing email address privately. Requesting escalation to the Data Protection team for admin account recovery. Any guidance on how to reach a human agent would be greatly appreciated. Thank you.465Views1like4CommentsDisabling authentication methods in Entra having no effect
Fairly new to MS365 here and we're trying to restrict which MFA methods our users can use. We want our users to be able to either use the Authenticator app or a FIDO2 key depending on their role, in addition to a TAP to do the initial login. We're testing disabling various methods via the Authentication methods page in Entra. As a representative test we set TAP to disabled and it gave an error when I attempted to issue a TAP for a user via the user's Authentication methods page in Intune. However we don't get consistent results with other auth methods: Authenticator, Security key (FIDO2) and SMS. I put a specific group in the 'Enable and target' > 'Exclude' section for all 3 and was still able to configure Authenticator and a phone for SMS. When viewing the methods configured for the user, only the security key was listed under 'unusable methods'; hence the policies for Authenticator and SMS appear to have no effect. Similar tests with just one auth method yield the same result. Is there something we're doing or understanding wrongly about how these policies work?1.3KViews1like3CommentsStuck in an authenticator loop
I have a 365 Business account. Haven't logged in for a while due to reasons, i was just starting up as a sole trader. Anyway decided now is the time to resurrect it and get up and running, except Authenticator doesn't work because I changed my phone, and my back up email is out of date, and no longer exists. I have tried the support web chat which wants to send a code to authenticator or my back up email. Just called the help line that referred me to the web chat which doesn't work, I couldn't get past the bot. So I am stuck. Any recovery options does not recognise my log in details, i think this is because its been a while since I logged in (I still pay but ....) but I can't resurrect it because I don't have a way of getting a code due to authenticator/back up email as cited above. I am really at a loss as to what to do. I don't want to abandon it and start again as there are documents in my one drive that I need. Can anyone help please. (I think all that needs to happen is an update to my back up email and then I can get going). I am the sole administrator on my business account.348Views1like3CommentsMicrosoft Teams and Authenticator lockdown
I’m having a very frustrating issue with Microsoft Teams. I am able to log in to teams using my normal personal email and account ONLY ON THE WEB BROWSER. From the web browser, I am not able to access the business channel that I am in. When attempting to log in on the downloaded mobile Teams App, I am sent directly to Microsoft Authenticator, which after waiting several hours, waiting even a full day, is still displaying a message about repeated verification attempt and to wait and try again later. I have accessed Microsoft support chat and they had no help for me. I need the authenticator lockdown to refresh and it will not.308Views0likes1CommentMicrosoft Authenticator & Microsoft Work Accounts
I am moving my data and apps from my previous Android phone to a new Android phone. I have run into a problem with the Microsoft Authenticator app. I have several Microsoft work accounts which Microsoft Authenticator on the new phone says I need a QR code to recover the account. However, when I go to the Security page for the Microsoft work accounts, click on "Add Sign-In Methods", there is no option for an authenticator app. I should point out that I do have Microsoft Authenticator for these accounts installed and working on some tablets and iPads. How do I fix this so I can use my new Android phone? Thank you.Solved487Views0likes5CommentsNot able to do an account recovory when 2FA is enabled and Passkeey is half set up
I am not able to log into my personal account. I have tried account recovery, but I have 2FA set up so I go a message saying this is ignored. I have rest the password using 2FA but when I try to login the message is that I can not use password to login. I beleive my partern loged me out of the account and tried to log in to her account but instead started Passkey set up. I have needed to login with my company account even to raise this post. Any help would be great.206Views0likes1CommentM365, Entra ID, Google Password Manager Passkeys
I went into my tenant, opened the Entra ID Admin, and enabled passkeys (fido2) authentication. I want to use Google Password manager since it will work across al my devices/platforms (Windows, Mac, Android, iOS). I went into the security settings for Microsoft 365 account to add an authentication method. I am happy to say that "passkey" is listed as an option, so I created a new passkey in Google Chrome/Password Manager and named it after my userid in the tenant. To test it, I logged out and attempted to log in using the passkey. The option came up, but Microsoft complained it was not a valid key. I tried again stating that I would my phone for the key and scanned the QR code but my phone said there is no passkey I would need to create one. How do I solve this? BTW: I did add Google's AAGUID in the Entra admin and allowed it but that did not solve the issue.Solved396Views0likes2Comments