security
954 TopicsM365 only admin locked out MFA error 53003
I am learning this the hard way....so here it goes. Currently I am locked out of as the only admin on the tenant with error 53003. I was updating some Microsoft MFA default policy settings in Entra and mistakenly deleted the admin user from the exclusions list, and got locked out. Thankfully I have another tenant, not as big the one locked out. Initiated several support tickets for which everyone calls, and despite of subline mentioning the issue says that they have to assign this ticket to Entra. Then the ticket gets updated and noone has been assigned every since. I have initiated severity A support tickets from Azure portal but no one has called in last 24 hours to help. We area business with Business Premium licenses with over 20 users, and now completely locked out. I have looked almost everywhere online. There is no phone number that takes you to a support agent - PLEASE HELP........453Views0likes3CommentsCan't sign in to microsoft account
I'm locked out of my microsoft account simply because I don't have access to the Authenticator App. I recently performed a factory reset on my phone with the Authenticator App on and now I can't sign in to my account. I have tried the self help forums and I got a response email saying: "It looks like you just used the Microsoft account recovery form (account.live.com) to request a password reset for e**************email address removed for privacy reasons. Because you've turned on two-step verification for your account, we ignore these requests but wanted to let you know. If you're having trouble signing in, go to (account.live.com/ResetPassword) and reset your password using security info such as your phone, alternate email address, or authenticator app." It won't let me use my phone number when I select it as a sign in option. I have tried the recovery forms to no avail.8Views0likes0CommentsMicrosoft values a hacker's disposable email more than your email linked to Microsoft for 8 years
My Pc was compromised and my session tokens were stolen . I had security info connected with my email and phone number . I also had passkey setup on both my pc (after reset) and my phone . It took one click for the hacker to remove the security features . They setup their own security info and added a disposable email instead of mine . I was somehow able to log in to the account using my pc passkey , as it was already signed in . First I requested to change the hacker's email to my one , which was useless cause the wait time period was 30 days . But in doing so I locked myself out of recovering the account with the mail that notified me that my security info was changed . I went to account recovery which only allowed me to change the password not the email so its still connected to the hacker's email . My frustration is the hacker can 1 click change my forever linked email since accounts creation . But when i try to do so they prevents me to do that stating that "there was recent security information change and the account will not allow for additional change for 30 years" . I opened up "account recovery form" and filled it out , point to be noted there were no fields where I could enter my details of my problem they just ask some basic information . After sometime they send a mail stating provided information is not enough . How am i suppose to provide more information if there are no fields for additional information . I contacted Microsoft agent , they guided me to reply to the account recovery form mail which did not worked as I was not allowed to reply on such email . I contacted Microsoft agent again , this time they told me I will be getting an email with account recovery form and I should mention every details . Well it was the same recovery form I used earlier with limited fields . I still field out the form and after sometime I was mailed by mailto:email address removed for privacy reasons to provide additional details for my identify , I was again requested to submit an account recovery form on https://account.live.com/acsr?cs=1 which was the same link with limited fields to provide information . I proceeded but in the end I was told that I have reached the daily limit for submitting form for this account . Just to be sure I mailed mailto:email address removed for privacy reasons the requested details .32Views0likes0CommentsRevoking Access Tokens for Risky Service Principals
A Technical Community post discusses the topic of using the Entra ID continuous access evaluation (CAE) feature to revoke access for service principals when apps become risky or potentially compromised. The Microsoft Graph Command Line Tools app is a good example of a service principal in common use, so we examine the access tokens issued for interactive Graph sessions to discover if they are CAE-enabled. Just for fun! https://office365itpros.com/2026/09/03/cae-service-principals/58Views0likes0CommentsHow much of your Microsoft 365 environment can you actually see at once?
Not how many users you have. Not how many sites, teams, apps or flows you have. How much of it can you actually see connected together? I've been working across Microsoft 365 environments for a while, and I kept running into the same thing. There is no shortage of information. If anything, there is probably too much of it. Users, groups, permissions, SharePoint, Teams, Power Apps, Power Automate, Power BI, Dataverse, OneDrive, Exchange, Intune, licensing, configuration... It's all there. But when you're actually trying to understand how everything fits together, it can be a different story. You open one blade. Find something. Open another. Cross-check it. Go back. Open something else. Before long, you're jumping between different parts of the tenant trying to build the bigger picture in your head. And if you're working with larger environments, that gets difficult pretty quickly. The information isn't necessarily missing. The relationships between the information are what can be difficult to see. That got me thinking about a slightly different question: Instead of "where do I find this information?" "Show me what's connected to this." That's where VisibleState started. Start anywhere. Follow the connections. Imagine starting with a single user. Instead of seeing that user simply as a record with a list of properties, imagine being able to explore the relationships around them: User → Groups → SharePoint → Teams → Power Apps → Power Automate → Power BI → Dataverse → OneDrive → Exchange → Intune Then the questions become different: What does this user have access to? Is that access direct or coming through a group? What resources are connected to them? What depends on something they're associated with? Which licenses are involved? Are there relationships that look unusual? If something changes, what else might be affected? Those questions aren't necessarily about finding another piece of information. They're about putting information that already exists into context. A report can tell you that something exists. A connected view helps you understand what it is connected to. Illustrative example below — not a real customer environment. I'm not suggesting Microsoft 365 doesn't already give us this information Quite the opposite. Microsoft 365 already gives administrators an incredible amount of information and tooling. The thing I've been thinking about is what happens when you want to look across those boundaries. Sometimes I don't want another export. I don't want another list. I don't necessarily want another dashboard. I want to start with something I'm looking at and ask: "What's connected to this?" And then keep following the trail. That's the idea I'm exploring with VisibleState. The interesting part is what happens when you change the viewpoint The same relationships can be useful for completely different reasons. For example: Administrators may want to understand access, permissions and dependencies. Security and governance teams may want to find unusual relationships or exceptions. Compliance teams may need to understand who can access something and why. People managing multiple environments may want a consistent way to understand what's there without rebuilding the picture manually every time. Leadership may not need to see the graph at all. They may simply want to know what's important, what's exposed and what could be affected. It's still the same underlying environment. You're just looking at it from a different angle. And that's where I think things get interesting. Where I'm at with it VisibleState started as something I was building to make my own work easier. I was spending a lot of time investigating environments, tracing access and putting information together for reports. The individual tasks weren't necessarily difficult. It was the jumping between different places and reconstructing the bigger picture that took the time. So I started building something that would let me approach the environment through the relationships instead. It's grown quite a bit from where it started, and I'm continuing to build it. I'm not posting this as a product launch, and I'm not looking for people to sign up. I'm genuinely interested in whether the problem I'm seeing is familiar to other people working with Microsoft 365. So I'm curious... If you could start with any object in your Microsoft 365 environment and immediately see what it's connected to, where would you start? Would it be: Users and access Groups and permissions SharePoint and Teams Power Apps, Power Automate, Power BI and Dataverse Licensing and resources Governance and unusual relationships Something completely different Maybe you've already got a good way of doing this. Maybe you still find yourself jumping between different services and piecing things together manually. Or maybe I'm looking at the problem from the wrong direction. What's the one relationship in your Microsoft 365 environment that you wish you could see instantly?127Views0likes0CommentsHow to properly redact a PDF?
I need to share a PDF that contains names, email addresses, and other confidential details that must be removed first. Simply placing black boxes over the text does not seem secure, since the original content may still be searchable, selectable, or recoverable, so I need a way to permanently redact a PDF. Because the document contains sensitive information, I would prefer not to upload it to an online tool. I’m looking for either a built-in option or professional third-party desktop software that can permanently redact both text and images while processing the file locally. It would also be useful to remove hidden information from a PDF before sharing, including comments, document metadata, and any other embedded details. What is the safest way to handle this, and how can I verify that a PDF is properly redacted before I send it?202Views0likes3CommentsWhy is Microsoft being a bully in regard to security defaults?
Hi, I received this email today: The security defaults setting for your domain.com tenant will be turned on by May 11, 2023 You’re receiving this email because you’re a global administrator for domain.com. To help protect your organization, we’re always working to improve the security of Microsoft cloud services. As part of this, we’re enabling the security defaults setting in your tenant that includes multifactor authentication, which can block more than 99.9 percent of identity attacks that attempt to compromise your accounts. When you log in to your account between April 27, 2023, and May 11, 2023, you’ll see a message prompting you to proactively enable security defaults. If you haven’t logged in or enabled this setting when that timeframe ends, we’ll enable it for you automatically. This is my subscription, I pay for it and Microsoft has no right to tell me what to do!!!! Angry I already disabled my security defaults in Azure admin centre a long time ago and do not want security defaults on because there may be situations where my mobile is unavailable, there is no signal or the battery is flat. Microsoft can suggest this, but cannot force their clients to enable this if they don't want to. There are many of my clients that don't want to authenticate a second time because it would cause a nightmare with their employees. Forcing someone is dictatorship. In a democratic society people get to choose what they want to do. I read that I can use conditional access policies but Microsoft is going to hit you with an additional Azure AD Premium subscription on top of what you are already paying. Many of my clients are small businesses who try to keep their costs down. Currently inflation is rampant and many small businesses are going bust. Thanks Microsoft for increasing our cost of living and running a business. This is my 2 cents worth on this subject.2.6KViews1like4CommentsSecurity Admin Center Tenant Allow/Block List Not Able to Block IPv4?
While using the Security Admin Center Tenant Allow/Block List we have been able to block specific email addresses and IPv6 IP addresses but are unable to block IPv4 IP addresses. We have tried both using the console and the CLI but have turned up unsuccessful both times when it comes to IPv4. A large majority of the phishing attempts that we encounter come from IPv4 addresses but we have been unable to block any of these. Will there ever be functionality for IPv4 within the Tenant Allow/Block list or is the only option to use conditional access policies? Also why is this enterprise tool only functional with IPv6 and without documentation stating that it does not work for IPv4?2.1KViews4likes6CommentsFile Sharing between licensed account holders
From a starting point of this year, we have been finding that any to most file shares that happened between licensed MS account users are being flagged and quarantined by the anti-malware policy. This should be, we are looking to resolve this issue. Has anyone else experienced this issue and what was your resolve. At the moment we have to monitor the quarantines and manually go in to release the share notifications.349Views0likes4Comments