Share via

Everyone locked out of tenant due to a faulty Conditional Access Policy

Nick Bobak 65 Reputation points
2024-04-25T23:18:45.7933333+00:00

We have been locked out of our tenant for almost 2 weeks now due to a faulty Conditional Access policy. During this week, there have been several conversations with a number of Microsoft support technicians, none of which seemed to have an understanding of the actual issue at hand or able to resolve the issue and all ended up assigning the case to a different team. We know exactly what is wrong and how to fix it. But we need the help of the Data protection team. Since this is a high impact incident and things are moving too slow via the regular support channels, we are trying to get in touch with them through this channel. We came across similar incidents on this forum and saw that they responded quickly. Our current support case number is 2404140040001624.

Microsoft Security | Intune | Security
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
Microsoft Security | Microsoft Entra | Other

Answer accepted by question author

Givary-MSFT 35,786 Reputation points Microsoft Employee Moderator
2024-05-02T09:39:09.2566667+00:00

@Nick Bobak Apologies for the delayed response. As per the last update which I have got from my engineering team, we have excluded one of the Global admin accounts from the conditional access policy which caused this lockout.

This exclusion would be valid for next 24 hrs, would request you to login to your tenant at earliest, make changes to the policy so that others can login/access resources.

From next time onwards try to have emergency accounts - https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access

Let me know if you have any further questions, feel free to post back.

Was this answer helpful?

2 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Alfredo Revilla - Upwork Top Talent | IAM SWE SWA 27,546 Reputation points Moderator
    2024-04-25T23:52:59.21+00:00

    Hello, the Data Protection team is usually stacked with several cases related to the same issue.

    That said, it would be a nice idea for Microsoft to strongly suggest and offer automatic break-glass/emergency account creation or ensure they won't get locked. Feel free to support ideas like this: https://feedback.azure.com/d365community/idea/42215546-8a90-ed11-a81b-000d3ae5ae95 so that the product team can consider them.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.