Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Unmasking the silent saboteur you didn’t know was operating the present

    June 9, 2025

    Explainer: Trump’s massive, stunning invoice, in 5 charts

    June 9, 2025

    New PathWiper Malware Strikes Ukraine’s Vital Infrastructure

    June 9, 2025
    Facebook X (Twitter) Instagram
    UK Tech Insider
    Facebook X (Twitter) Instagram Pinterest Vimeo
    UK Tech Insider
    Home»AI Ethics & Regulation»Microsoft Entra ID Lockouts After MACE App Flags Legit Customers
    AI Ethics & Regulation

    Microsoft Entra ID Lockouts After MACE App Flags Legit Customers

    Declan MurphyBy Declan MurphyApril 24, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Microsoft Entra ID Lockouts After MACE App Flags Legit Customers
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Was your Microsoft Entra ID account locked? Discover out in regards to the latest widespread lockouts brought on by the brand new MACE Credential Revocation app and a Microsoft error in dealing with consumer refresh tokens.

    Just lately, many corporations skilled an issue the place their staff instantly couldn’t log into their Microsoft Entra accounts and expressed concern in a Reddit thread. Microsoft, the corporate behind Entra ID (beforehand known as Azure Lively Listing), has defined what occurred.

    Evidently a newly launched element of Microsoft Entra ID known as the MACE Credential Revocation app, which is designed to boost safety by figuring out compromised credentials, mistakenly flagged many common customers as excessive danger. This led to widespread account lockouts.

    Microsoft has traced the basis trigger to an inner logging difficulty with a function known as refresh tokens (how customers keep logged), which have been being logged inside Microsoft’s personal programs. Particularly, the usual course of is to solely log metadata about these short-lived tokens, and the issue arose when a subset of those tokens themselves have been being logged internally “for a small proportion of customers,” starting on Friday, April 18th, 2025.

    As quickly as they realized this error on Friday, April 18th, 2025, Microsoft took motion to repair it. To maintain their clients secure, they determined to make these particular tokens invalid, that means they’d now not work.

    Nevertheless, this course of of creating the tokens invalid mistakenly triggered alerts in Entra ID Safety. These alerts, despatched out on Sunday, April twentieth, 2025, between 4 AM and 9 AM UTC, made it look like customers’ login particulars may need been stolen.

    Microsoft has said that they don’t have any proof that anybody gained unauthorized entry to those tokens. “We have now no indication of unauthorized entry to those tokens – and if we decide there have been any unauthorized entry, we are going to invoke our commonplace safety incident response and communication processes,” the tech large famous.  

    For corporations whose customers have been locked out as a result of they have been wrongly marked as high-risk, Microsoft suggests an answer. Directors can use a function known as Affirm Consumer Protected inside Entra ID. This tells the system that though an alert was raised, the consumer’s account is definitely okay. Microsoft has offered a hyperlink to their assist documentation that explains find out how to use this function and perceive the danger alerts. 

    Microsoft remains to be trying into precisely what went improper and can share an in depth report, known as a Put up Incident Evaluation (PIR), with all of the affected clients and anybody who opened a assist ticket.

    To be notified when this report is accessible or to remain up to date on any future issues with Azure providers, Microsoft recommends organising Azure Service Well being alerts. These alerts can ship notifications by e-mail, textual content messages, and different strategies. 

    Jim Routh, Chief Belief Officer Saviynt, shared his ideas on the scenario with Hackread.com. He identified that though this brought about issues for some Microsoft enterprise clients over the weekend, there have been some optimistic elements.

    “The optimistic information is that the disruption occurred over the weekend, and at the moment (Monday), clients have the info together with the repair (corrective actions) obligatory for restoration,” he stated. ”The vulnerability and the motion taken (token invalidation) have been finally shared by Microsoft in an advisory comparatively shortly. This can be a signal of well being or resilience regardless of the inconvenience to some enterprise clients over the weekend,” Routh added.



    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Unmasking the silent saboteur you didn’t know was operating the present

    June 9, 2025

    New PathWiper Malware Strikes Ukraine’s Vital Infrastructure

    June 9, 2025

    OpenAI Bans ChatGPT Accounts Utilized by Russian, Iranian and Chinese language Hacker Teams

    June 9, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Unmasking the silent saboteur you didn’t know was operating the present

    June 9, 2025

    How AI is Redrawing the World’s Electrical energy Maps: Insights from the IEA Report

    April 18, 2025

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025
    Don't Miss

    Unmasking the silent saboteur you didn’t know was operating the present

    By Declan MurphyJune 9, 2025

    You possibly can have the perfect firewalls, hermetic encryption and the newest SIEM instruments. But…

    Explainer: Trump’s massive, stunning invoice, in 5 charts

    June 9, 2025

    New PathWiper Malware Strikes Ukraine’s Vital Infrastructure

    June 9, 2025

    Soneium launches Sony Innovation Fund-backed incubator for Soneium Web3 recreation and shopper startups

    June 9, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.