security
159 TopicsLocked out because of bugged 2FA
Hello, I have one irritating problem. I did a reset of my microsoft authenticator app since it stopped working, i did not save the Authenticators security code, i got 2FA activated on my account. Now i have been trying to log in on my microsoft account for one month without succes. The 3 options i have for 2FA is Code to external my gmail - This works 2 times a day, then locked for 24h Code by text to my cellphone - This does not work when trying to log in, i get the error "Try another verification method, this method does not work at the moment". I know it works, its just in the combination with 2FA it wont work. Microsoft Authenticator - I cannot log into this one since the textmessage does not work on 2FA-login. I have been in a loop for the last month, i cant log into my ordinary e-mail, xbox and so on. Im still logged in on my computer and cellphone at the moment but im afraid it will time out very soon. Microsoft support says that they cannot do anything about it, it is only a server doing all the security. I cant remove 2FA on the account im still logged into, i need 2FA for that. Help!109Views0likes4CommentsTAP Question
Hi All I hope you are well. Anyway, I'm looking for some clarification over Temporary Access Passes (TAP) as our testing seems to reveal some different results from those listed in the MS documentation. Here's the scenario's. My understanding: Require MFA policy deployed via Conditional Access New user F3 user starts Issue TAP to user where they can then setup MFA themselves via My Security Info etc Testing results: Require MFA policy deployed via Conditional Access New user F3 user starts User can setup MFA themselves via MS Auth app on a mobile device or via My Security Info in a browser MS TAP Info page: "The most common use for a TAP is for a user to register authentication details during the first sign-in or device setup, without the need to complete extra security prompts." Ref: Configure a Temporary Access Pass in Microsoft Entra ID to register passwordless authentication methods - Microsoft Entra ID | Microsoft Learn Have I missed understood something here and if a new user can indeed still setup MFA is there any real need for a TAP for first time user? Info appreciated. SK58Views0likes1CommentNgcSet stays NO despite working WHFB setup - RPC 0x800706ba error
Hi everyone, I need help with a Windows Hello for Business certificate trust deployment that's almost working but stuck on the final step. **What's Working:** - Manual certificate enrollment works perfectly: `certreq -enroll -user -config "MyCA.domain.local\MyCA-CA" "MyWHFBTemplate"` - TPM 2.0 is ready, enabled, and functional - All Group Policies applied correctly (computer and user) - CA server healthy, templates published **What's NOT Working:** - `dsregcmd /status` shows `NgcSet : NO` (should be YES) - `NgcSvc` (Microsoft Passport) service is stopped on client - Getting error: "RPC server is unavailable (0x800706ba)" during automatic certificate enrollment - PIN setup fails because NGC containers won't create **The Strange Part:** Manual certificate enrollment works perfectly, but automatic enrollment fails with RPC errors. Both should use the same communication path to the CA. **Environment:** - On-premises certificate trust deployment (no Azure AD) - Domain-joined Windows 11 clients - Windows Server 2019/2022 infrastructure **Questions:** 1. Should NgcSvc start automatically when WHFB policies are applied? 2. Why would manual cert enrollment work but automatic fail with RPC errors? 3. Is there a difference in how system context vs user context accesses the CA? Has anyone seen this specific combination before? Any ideas what could cause this behavior? Thanks for any help!78Views0likes3CommentsMFA for one email account with several users
Client runs four shifts with support staff who work from home. Each group of four team members has a single 365 mailbox, and usage passes from one team member to another as the shifts change. For each group, client wants to implement 2FA with Authenticator on the phones of each team member, i.e. four phones authenticating one email account. But this used to be barred for business (‘work and school’) accounts. DAK what is the current position (and is this documented anywhere?), and if it is still barred what is the best way forward?Solved100KViews0likes4CommentsAllow any UTF8 characters in Microsoft account passwords
Hello, I tried to use characters like «¼∃≒∀» in passwords and the form always reject them while local windows accounts and on premise domain controllers accept them. I opened a support ticket to report this as a bug and was told it works this way by design (case 28980531). Was also directed here if I had any suggestions so here I am: please allow any and each UTF8 characters in your online service in the password field. Not being able to is a regression from using on premise domain controller that gladly accept even emojis in passwords. Thank you.4.9KViews0likes3CommentsToken replay question
I had a case of a user being phished and their token being used in a replay attack. The replay appeared in the sign in logs from a different IP address to the "true" users IP. I then saw activity on the account originating from the original IP until we killed the session a few hours later. I had someone suggest that in a token replay the M365 audit\activity logs and Entra ID signing logs will show the original persons IP, not the attackers. Can anyone confirm this?92Views0likes2CommentsAzure MFA "Activation Failed" error with Microsoft Authenticator App
We've opened a premier ticket, but has anyone in the community seen this error before? We've got a few users that can't set up the Microsoft Authenticator app, and nothing we do is working. This is rolling out to all of our users overnight tonight, and none of our global testing has run into anything like this.132KViews0likes17CommentsImpossible to login my business account
Hi everyone, here is what happened to my account: last year I created a One Drive business account, for that I had to create a Microsoft email: mailto:email address removed for privacy reasons I activated 2FA with my phone number A In December, I sold my phone and forgot the 2FA as I was still able to access my OneDrive (Remember me option) Now when the 2FA prompt happened, I realised I didn't have the 2FA but also forgot my OneDrive password as I never use this specific email Meanwhile I aksed Microsoft support from my personal email, to disconnect my 2FA from my business account, which they apparently did but then told me, when I realised I still could not log in, I should raise the request from the business account, except I can't access it Now I am stuck as I can't access this account online. I can't recover my password (https://account.live.com/password/reset), message "We don't recognise this one" update 2FA, as I need the password call them as Microsoft contact number never finds an available agent, spent 4 hours waiting last week... Would you have an idea to help me? I simply need to access my documents...Solved2.4KViews0likes5CommentsUser with hundreds of Interactive Sign-In log entries that are "Interrupted"
I have one user in our organization that has hundreds of Interactive Sign-in logs in EntraID that are marked as "Interrupted". I don't even know where to start with the user. Does anyone have a recommendation for isolating the cause of these logs? Recent entries are 95% related to Office Online Core SSO application.911Views0likes5Comments