{"id":13520,"date":"2025-04-21T12:55:21","date_gmt":"2025-04-21T00:55:21","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=13520"},"modified":"2025-04-21T12:55:21","modified_gmt":"2025-04-21T00:55:21","slug":"widespread-microsoft-365-lockouts","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=13520","title":{"rendered":"Widespread Microsoft 365 lockouts"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>If you were forced to change your Microsoft password over the Easter Weekend, you weren\u2019t alone.<\/p>\n<p>&nbsp;<\/p>\n<h2>There have been a significant number of Microsoft Account Password Resets for &#8216;suspicious activity&#8217;\u00a0<strong><\/strong><\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>There are <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/1k2pmkz\/new_entra_leaked_credentials_no_breach_on_hibp_etc\/\">numerous posts around the internet<\/a> suggesting this is a widespread phenomenon.\u00a0 Some organisations have had more occurrences than others.\u00a0 \u00a0<\/p>\n<p>From what we are reading online, there is no discernible pattern. Both large and small organisations are affected, including tenants managed by partners and those with direct payments to Microsoft. \u00a0<\/p>\n<p>Organisations from all over the world, with a range of 365 licenses from Business Basic up to Enterprise E5, and licenses with and without Conditional Access are impacted.<strong><\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&quot;2_5&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_image src=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2025\/04\/Microsoft-Lockout.png&quot; title_text=&quot;Microsoft Lockout&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; border_radii=&quot;on|20px|20px|20px|20px&quot; box_shadow_style=&quot;preset1&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_column type=&quot;4_4&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_text _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<\/p>\n<p>Our observations match those of other IT partners.\u00a0 \u00a0The login message suggests that there is suspicious activity in the account.\u00a0 The Microsoft password might have leaked in the dark web, although dark web scans find no evidence of that.<\/p>\n<p>While Microsoft has not publicly confirmed the cause of these lockouts, Microsoft told one of the affected organisations it was caused by an issue with the rollout of a new Enterprise application called &#8220;MACE Credential Revocation.&#8221; \u00a0\u00a0\u00a0This seems to be a new Microsoft tool that is\u00a0used to detect leaked credentials and lockout potentially compromised accounts.\u00a0 For some reason, it has been pushed out fairly broadly around the world, over the long Easter Weekend.<\/p>\n<p><strong>We believe that we have identified all clients and users that have been impacted and are working through these, resetting passwords and offering support.\u00a0 Our support desk is pre-warned ahead of people returning to work on Tuesday after the long weekend.<\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you were forced to change your Microsoft password over the Easter Weekend, you weren\u2019t alone. &nbsp; There have been a significant number of Microsoft Account Password Resets for &#8216;suspicious activity&#8217;\u00a0There are numerous posts around the internet suggesting this is a widespread phenomenon.\u00a0 Some organisations have had more occurrences than others.\u00a0 \u00a0 From what we [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":13521,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[],"class_list":["post-13520","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/13520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13520"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/13520\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}