Sunday, April 20, 2025
HomeTechnologyWidespread Microsoft Entra lockouts tied to new safety characteristic rollout

Widespread Microsoft Entra lockouts tied to new safety characteristic rollout

Widespread Microsoft Entra lockouts tied to new safety characteristic rollout

Home windows directors from quite a few organizations report widespread account lockouts triggered by false positives within the rollout of a brand new Microsoft Entra ID’s “leaked credentials” detection app known as MACE.

These alerts and lockouts started final evening, with some admins believing they had been false positives because the accounts have distinctive passwords that aren’t used on every other websites or functions.

Microsoft Entra ID, previously Azure Energetic Listing, is a cloud-based id and entry administration service that helps organizations handle consumer identities and safe entry to sources.

In a Reddit thread posted early this morning, Home windows admins reported receiving a number of alerts from Entra indicating that a few of their consumer accounts had been discovered with credentials leaked on the darkish net or different places.

These accounts had been robotically locked out of the tenant, with quite a few customers impacted per group.

“Us as properly… about 1/third of our accounts bought locked out about ~1 hour in the past. We’re a MSP so I am assuming that is taking place to our shoppers as properly,” posted an admin on Reddit.

The locked-out accounts confirmed no indicators of compromise, akin to suspicious sign-ins, and had been protected with MFA. Moreover, breach notification companies like Have I Been Pwned (HIBP) had no matches for these accounts.​

One other report on Reddit additional corroborated that this was widespread, with an MDR supplier stating they obtained over 20,000 notifications from Microsoft in a single day concerning leaked credentials from totally different prospects 

Whereas Microsoft has not publicly confirmed the reason for these lockouts, Microsoft informed one of many affected organizations it was brought on by a difficulty with the rollout of a brand new Enterprise utility known as “MACE Credential Revocation.”

“Simply bought off with engineer. It’s Tenant Lockout because of this MACE ninja rollout they did. no indicators of compromise. He wants an hour to transform the ticket from compromise to lockout however can breathe a sigh of aid. It was Error Code: 53003 for conditional entry coverage,” an admin reported on Reddit.

A number of folks confirmed this utility was added to tenants proper earlier than they started receiving the alerts.

MACE Credential Revocation app is a Microsoft Entra characteristic used to detect leaked credentials and lockout doubtlessly compromised accounts.

Whereas all alerts of leaked credentials needs to be investigated to verify that an account was not compromised, when you obtained a flurry of alerts directly this rollout doubtless triggered it.

BleepingComputer contacted Microsoft with questions on this incident however has not obtained a response at the moment.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments