Microsoft Entra Lockout Fiasco: The MACE App That Cried Wolf!

Locked out of your Microsoft Entra ID account? Blame it on the MACE Credential Revocation app and a minor refresh token mishap. Microsoft accidentally flagged regular users as high risk, causing mass lockouts. But don’t worry, there’s a fix, and no unauthorized access was found. Just another day in tech oops-ville!

Pro Dashboard

Hot Take:

Well, Microsoft sure knows how to throw a surprise party! Just when you thought your weekend couldn’t get any more exciting, they unleashed the MACE Credential Revocation app to lock you out of your own account. Who needs a night out when you can stay home and panic about compromised credentials instead?

Key Points:

  • The new MACE Credential Revocation app mistakenly flagged users as high-risk, leading to account lockouts.
  • An internal issue with Microsoft’s handling of refresh tokens was identified as the cause.
  • Microsoft invalidated certain tokens, triggering security alerts in Entra ID Protection.
  • They confirmed no unauthorized access was detected but are investigating further.
  • Admins can use the “Confirm User Safe” feature to resolve the issue.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?