A Microsoft Entra security update is locking users out of their accounts


- Some Entra ID accounts were being flagged as having compromised credentials
- Seems it was just Microsoft “inadvertently generat[ing] [false] alerts”
- However, users were getting different explanations from Microsoft
Windows administrators have been reporting mass account lockouts across various organizations following a Microsoft Entra ID update.
Many believe these were false positives triggered in Entra ID’s new leaked credentials detection app (a new feature called MACE Credential Revocation), as affected accounts had unique and unused passwords.
One user posted to a Reddit thread that around half a dozen accounts had been blocked after credentials were supposedly found on the dark web, however those users didn’t have much in common, suggesting that it wasn’t a targeted attack.
Entra ID might be flagging false positives
“There are no risky signins, no other risk detections, everyone is MFA, it’s literally the only thing that’s appeared today, raising the risk on these people from zero to high,” the Reddit user explained.
Beneath the original post is a series of comments from other system admins who also experienced similar issues, with one user sharing a response from Microsoft suggesting that the accounts had been erroneously flagged:
“On Friday 4/18/25, Microsoft identified that it was internally logging a subset of short-lived user refresh tokens for a small percentage of users, whereas our standard logging process is to only log metadata about such tokens. The internal logging issue was immediately corrected, and the team performed a procedure to invalidate these tokens to protect customers.”
The notice sees Microsoft admit to “inadvertently generat[ing] alerts in Entra ID Protection” of supposed compromised credentials between 4AM UTC and 9AM UTC on April 20.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Another user said they were quoted “Error Code: 53003” for conditional access policy, while another was told that it was to do with an outage in their region – even though no outage had been reported or logged.
TechRadar Pro has asked Microsoft to clarify what happened over the weekend and why users appear to have received different explanations. Any update will be posted here.
You might also like
Some Entra ID accounts were being flagged as having compromised credentials Seems it was just Microsoft “inadvertently generat[ing] [false] alerts” However, users were getting different explanations from Microsoft Windows administrators have been reporting mass account lockouts across various organizations following a Microsoft Entra ID update. Many believe these were false…
Recent Posts
- Grok stops posting text after flood of antisemitism and Hitler praise
- Grok sure seems antisemitic after its recent update
- Confirmed: Nintendo’s Switch 2 can work with existing docks and webcams after replacing their firmware
- NYT Wordle today — answer and my hints for game #1481, Wednesday, July 9
- Apple’s design team will report to Tim Cook
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022