Microsoft Entra account lockouts caused by user token logging mishap

Microsoft

Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged into internal systems.

On Saturday morning, numerous organizations reported that they began receiving Microsoft Entra alerts that accounts had leaked credentials, causing the accounts to be locked out automatically.

Impacted customers initially thought the account lockouts were tied to the rollout of a new enterprise application called “MACE Credential Revocation,” installed minutes before the alerts were issued.

However, an admin for one of the impacted organizations shared an advisory sent by Microsoft stating that the issue was caused by the company mistakenly logging the impacted account’s user refresh tokens rather than just their metadata.

After realizing they logged actual account tokens, they began invalidating them, which accidentally generated the alerts and lockouts.

“On Friday 4/18/25, Microsoft identified that it was internally logging a subset of short-lived user refresh tokens for a small percentage of users, whereas our standard logging process is to only log metadata about such tokens,” reads an advisory from Microsoft posted on Reddit.

“The internal logging issue was immediately corrected, and the team performed a procedure to invalidate these tokens to protect customers.  As part of the invalidation process, we inadvertently generated alerts in Entra ID Protection indicating the user’s credentials may have been compromised.”

“These alerts were sent between 4/20/25 4AM UTC and 4/20/25 9AM UTC. We have no indication of unauthorized access to these tokens – and if we determine there were any unauthorized access, we will invoke our standard security incident response and communication processes.”

Microsoft says impacted customers can give the “Confirm User Safe” feedback in Microsoft Entra for the flagged user to restore access to their accounts.

The company says they will publish a Post Incident Review (PIR) after the investigation is finished, which will be shared with all impacted customers.

Microsoft shared the following statement regarding the incident.

“We inadvertently generated security alerts for customers and have mitigated the issue.  We sent a notification to all impacted customers and will continue to provide support as needed,” Microsoft told BleepingComputer.

Lawrence Abrams
Read More

Latest

Newsletter

Don't miss

Famous birthdays for April 5: Sterling K. Brown, Mike McCready

Music 1 of 3 | Sterling K. Brown arrives...

Yashraj, Abdon Mech, Divyam Sodhi and All The Songs to Know This Week

Music From pop-rock band Last Minute India’s inward-looking new...

Starmer ‘deeply concerned’ by Kanye West’s UK festival booking

Music You don't have permission to access "http://news.sky.com/story/keir-starmer-deeply-concerned-by-kanye-wests-wireless-festival-booking-despite-antisemitic-remarks-13528071"...

The Vogue Business Funding Tracker

Introducing the Vogue Business Funding Tracker, a running list highlighting the most notable and intriguing investment and M&A activity in fashion and beauty. From emerging disruptors to legacy giants undergoing major changes, we spotlight the deals that are shifting the dynamics of the sectors we cover, including fashion, beauty, tech and sustainability. April 2026 Icicle

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day