What This Category Covers
Identity tickets need sign-in evidence. Separate disabled account, password state, MFA method, Conditional Access, device compliance, risk, and token/session state before resetting credentials.
First Layer to Isolate
Exact sign-in attempt first: result, policy, method, risk, and device state.
Useful Tools, Logs, and Portals
- Entra sign-in logs
- Conditional Access report-only/result details
- Authentication methods
- Identity Protection risk
- Audit logs
Before You Escalate
- Timestamped sign-in checked
- Method and CA result captured
- Account/device state verified
- Risk state reviewed
Articles in This Path
Pick the closest symptom and work from there.
Entra sign-in logs show success but app still says unauthorized
Field Summary
Entra sign-in logs show success but app still says unauthorized is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.
Conditional Access policy report only mode differs from live result
Field Summary
Conditional Access policy report only mode differs from live result is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.
Legacy app password disabled and scanner workflow breaks
Field Summary
Legacy app password disabled and scanner workflow breaks is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.
Hybrid join succeeds but primary refresh token missing
Field Summary
Hybrid join succeeds but primary refresh token missing is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.
Break glass account excluded from MFA cannot sign in
Field Summary
Break glass account excluded from MFA cannot sign in is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.
Authenticator number matching works but sign-in still denied
Field Summary
Authenticator number matching works but sign-in still denied is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.
Password writeback succeeds but users cannot unlock accounts
Field Summary
Password writeback succeeds but users cannot unlock accounts is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.
Azure AD Connect sync errors after schema change
Field Summary
Azure AD Connect sync errors after schema change is a Microsoft 365 ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.
MFA prompts delayed or never arriving
Field Summary
Delayed or missing MFA prompts can be a user device issue, a method registration issue, Conditional Access behavior, push notification delivery, or an identity provider service problem. The fastest path is to check sign-in logs and prove whether the prompt was generated, delivered, denied, or never required.
- Read more about MFA prompts delayed or never arriving
- Log in to post comments
Teams sign-in loop after MFA enrollment
Field Summary
A Teams sign-in loop after MFA enrollment is usually identity token state, desktop cache, authentication method registration, or Conditional Access behavior. Prove whether Teams web works and what Entra sign-in logs say before reinstalling Teams.
- Read more about Teams sign-in loop after MFA enrollment
- Log in to post comments