Identity & MFA

Practical troubleshooting paths for MSP technicians dealing with real-world support failures.

What This Category Covers

Identity tickets need sign-in evidence. Separate disabled account, password state, MFA method, Conditional Access, device compliance, risk, and token/session state before resetting credentials.

First Layer to Isolate

Exact sign-in attempt first: result, policy, method, risk, and device state.

Useful Tools, Logs, and Portals

  • Entra sign-in logs
  • Conditional Access report-only/result details
  • Authentication methods
  • Identity Protection risk
  • Audit logs

Before You Escalate

  • Timestamped sign-in checked
  • Method and CA result captured
  • Account/device state verified
  • Risk state reviewed

Articles in This Path

Pick the closest symptom and work from there.

Authenticator number matching works but sign-in still deniedAzure AD Connect sync errors after schema changeBreak glass account excluded from MFA cannot sign inBreak-glass account sign-in succeeds but portal access remains restrictedConditional Access policy report only mode differs from live resultEntra joined device shows compliant yet conditional access blocks sign-in from browserEntra sign-in logs show success but app still says unauthorizedGuest user redemption completes but collaboration apps still deny accessHybrid join succeeds but primary refresh token missingIdentity & MFA alerts indicate success while end-user experience never changesIdentity & MFA configuration survives testing but resets after restart or syncIdentity & MFA credential or certificate rotation breaks an existing integrationIdentity & MFA feature works in web app but fails in desktop clientIdentity & MFA healthy dashboard status masks a failing production workflowIdentity & MFA new deployment works for pilot group but not for production rolloutIdentity & MFA policy change applies in admin console but target users never receive itIdentity & MFA quarantine or protection action triggers but recovery workflow failsIdentity & MFA workflow succeeds for one account but fails for shared or delegated accessLegacy app password disabled and scanner workflow breaksLegacy authentication blocked report spikes after mailbox migration weekendMFA phone call option missing for one pilot group after policy changeMFA prompts delayed or never arrivingNew user signs in successfully but self-service password reset registration never completesPassword writeback succeeds but users cannot unlock accountsPasswordless sign-in works on mobile but desktop browser still prompts for passwordSign-in risk policy flags impossible travel after VPN rolloutTeams sign-in loop after MFA enrollmentTemporary Access Pass created but user cannot redeem it on first loginUser can enroll Microsoft Authenticator but number matching prompt never arrivesUser removed from MFA group but legacy sessions still prompt

Identity & MFA quarantine or protection action triggers but recovery workflow fails

Field Summary

Identity & MFA quarantine or protection action triggers but recovery workflow fails is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA configuration survives testing but resets after restart or sync

Field Summary

Identity & MFA configuration survives testing but resets after restart or sync is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA workflow succeeds for one account but fails for shared or delegated access

Field Summary

Identity & MFA workflow succeeds for one account but fails for shared or delegated access is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA feature works in web app but fails in desktop client

Field Summary

Identity & MFA feature works in web app but fails in desktop client is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA alerts indicate success while end-user experience never changes

Field Summary

Identity & MFA alerts indicate success while end-user experience never changes is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA credential or certificate rotation breaks an existing integration

Field Summary

Identity & MFA credential or certificate rotation breaks an existing integration is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA new deployment works for pilot group but not for production rollout

Field Summary

Identity & MFA new deployment works for pilot group but not for production rollout is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA healthy dashboard status masks a failing production workflow

Field Summary

Identity & MFA healthy dashboard status masks a failing production workflow is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Identity & MFA policy change applies in admin console but target users never receive it

Field Summary

Identity & MFA policy change applies in admin console but target users never receive it is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Guest user redemption completes but collaboration apps still deny access

Field Summary

Guest user redemption completes but collaboration apps still deny access is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.