Close Menu
Breaking News in Technology & Business – Tech Geekwire

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung Expands Health Ambitions with Acquisition of Xealth

    July 8, 2025

    No content to rewrite

    July 8, 2025

    Theo Health Signs Star Golfer to Test Sports Injury Technology

    July 8, 2025
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech GeekwireBreaking News in Technology & Business – Tech Geekwire
    • New
      • Amazon
      • Digital Health Technology
      • Microsoft
      • Startup
    • AI
    • Corporation
    • Crypto
    • Event
    Facebook X (Twitter) Instagram
    Breaking News in Technology & Business – Tech Geekwire
    Home ยป Microsoft Entra ID Update Triggers False Positive Account Lockouts
    Microsoft

    Microsoft Entra ID Update Triggers False Positive Account Lockouts

    techgeekwireBy techgeekwireApril 21, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    A recent Microsoft Entra ID update has caused widespread account lockouts across various organizations, with many administrators suspecting false positives triggered by the new leaked credentials detection feature, known as MACE Credential Revocation.

    The issue began after the update, with multiple system administrators reporting that accounts were being flagged as having compromised credentials despite having unique and unused passwords. One Reddit user noted that around half a dozen accounts were blocked after credentials were supposedly found on the dark web, but the affected users didn’t share common characteristics, suggesting it wasn’t a targeted attack.

    Microsoft later acknowledged the issue, stating that they had ‘inadvertently generat[ed] alerts in Entra ID Protection’ between 4AM UTC and 9AM UTC on April 20. According to Microsoft, the problem occurred when they internally logged a subset of short-lived user refresh tokens for a small percentage of users, contrary to their standard practice of logging only metadata about such tokens. The issue was immediately corrected, and the tokens were invalidated to protect customers.

    However, users received different explanations for the lockouts, with some being quoted ‘Error Code: 53003’ for conditional access policy, while others were told it was related to an outage in their region, despite no outage being reported. TechRadar Pro has requested clarification from Microsoft on the incident and the varying explanations provided to users.

    Impact and Response

    The lockouts caused significant disruption, with affected accounts being flagged as high risk despite having no other risk detections or risky sign-ins. Many organizations use Entra ID with multi-factor authentication (MFA) enabled, making the false positives particularly puzzling. Microsoft’s admission of inadvertently generating alerts helps explain the widespread issue, but the varying explanations given to users remain unclear.

    Conclusion

    The incident highlights the challenges organizations face when implementing new security features. While leaked credentials detection is crucial for security, false positives can cause significant operational disruption. Microsoft’s prompt acknowledgment and corrective action are positive steps, but further clarification will be needed to prevent similar incidents in the future.

    account lockouts Entra ID false positives Microsoft
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techgeekwire
    • Website

    Related Posts

    Samsung Expands Health Ambitions with Acquisition of Xealth

    July 8, 2025

    No content to rewrite

    July 8, 2025

    Theo Health Signs Star Golfer to Test Sports Injury Technology

    July 8, 2025

    Tech Sector Sees Fresh Wave of Layoffs in June as Companies Adapt to Changing Market

    July 8, 2025

    Congress Wrestles with ‘Big Beautiful Bill’ AI Moratorium Provision

    July 8, 2025

    Microsoft Signs Deal to Power Premier League’s AI Tools

    July 8, 2025
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Samsung Expands Health Ambitions with Acquisition of Xealth

    July 8, 2025

    No content to rewrite

    July 8, 2025

    Theo Health Signs Star Golfer to Test Sports Injury Technology

    July 8, 2025

    Tech Sector Sees Fresh Wave of Layoffs in June as Companies Adapt to Changing Market

    July 8, 2025
    Advertisement
    Demo
    About Us
    About Us

    A rich source of news about the latest technologies in the world. Compiled in the most detailed and accurate manner in the fastest way globally. Please follow us to receive the earliest notification

    We're accepting new partnerships right now.

    Email Us: info@example.com
    Contact: +1-320-0123-451

    Our Picks

    Samsung Expands Health Ambitions with Acquisition of Xealth

    July 8, 2025

    No content to rewrite

    July 8, 2025

    Theo Health Signs Star Golfer to Test Sports Injury Technology

    July 8, 2025
    Categories
    • AI (2,705)
    • Amazon (1,060)
    • Corporation (998)
    • Crypto (1,140)
    • Digital Health Technology (1,088)
    • Event (531)
    • Microsoft (1,235)
    • New (9,634)
    • Startup (1,177)
    © 2025 TechGeekWire. Designed by TechGeekWire.
    • Home

    Type above and press Enter to search. Press Esc to cancel.