Microsoft Entra account lockouts attributable to consumer token logging mishap


Microsoft

Microsoft confirms that the weekend Entra account lockouts had been attributable to the invalidation of short-lived consumer refresh tokens that had been mistakenly logged into inner techniques.

On Saturday morning, quite a few organizations reported that they started receiving Microsoft Entra alerts that accounts had leaked credentials, inflicting the accounts to be locked out routinely.

Impacted prospects initially thought the account lockouts had been tied to the rollout of a brand new enterprise software known as “MACE Credential Revocation,” put in minutes earlier than the alerts had been issued.

Nevertheless, an admin for one of many impacted organizations shared an advisory despatched by Microsoft stating that the problem was attributable to the corporate mistakenly logging the impacted account’s consumer refresh tokens quite than simply their metadata.

After realizing they logged precise account tokens, they started invalidating them, which unintentionally generated the alerts and lockouts.

“On Friday 4/18/25, Microsoft recognized that it was internally logging a subset of short-lived consumer refresh tokens for a small share of customers, whereas our normal logging course of is to solely log metadata about such tokens,” reads an advisory from Microsoft posted on Reddit.

“The inner logging difficulty was instantly corrected, and the group carried out a process to invalidate these tokens to guard prospects.  As a part of the invalidation course of, we inadvertently generated alerts in Entra ID Safety indicating the consumer’s credentials could have been compromised.”

“These alerts had been despatched between 4/20/25 4AM UTC and 4/20/25 9AM UTC. We have now no indication of unauthorized entry to those tokens – and if we decide there have been any unauthorized entry, we’ll invoke our normal safety incident response and communication processes.”

Microsoft says impacted prospects can provide the “Confirm User Safe” suggestions in Microsoft Entra for the flagged consumer to revive entry to their accounts.

The corporate says they are going to publish a Submit Incident Overview (PIR) after the investigation is completed, which shall be shared with all impacted prospects.

BleepingComputer additionally contacted Microsoft on Saturday however has not but obtained a reply to our questions in regards to the incident.



Source link

Leave a Reply