Office 365 Services including SPO, OneDrive, Outlook, Outlook Mobile, Azure Keeps Asking to sign in for certain users

Alance Jacob 96 Reputation points Microsoft Employee
2020-03-02T18:22:36.793+00:00

Hello Team,

Office 365 Services including SPO, OneDrive, Outlook, Outlook Mobile, Azure Keeps Asking to sign in for certain users

Log from Sign-in activity (Azure)

Scenario:1
Failure reason: Session is invalid due to expiration or recent password change. ( Outlook Mobile)
Conditional Access: Not applied ( Allowed Country Login, suspicious IP, etc..)

Scenario:2

Failure reason: Invalid username or password or Invalid on-premise username or password. ( Microsoft office)

Date /
Authentication method detail /
Succeeded /
Result detail /

3/1/2020, 6:51:38 PM /
PHS /
false /
Invalid username or password or Invalid on-premise username or password. /
Primary Authentication /

Troubleshoot & Support Tab
Status/
Failure/
Sign-in error code/
50133/
Failure reason/
Session is invalid due to expiration or recent password change./
Additional Details/
MFA requirement satisfied by claim in the token/

Users haven’t changed the password. I have verified with users and checked the log

I have checked the Azure Adsync and remediate the users from some of the sign-in risk policies. Azure Adsync looks good. MFA has not enabled for some users.

Any help appreciated!

Thanks
Alan Jacob

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Alance Jacob 96 Reputation points Microsoft Employee
    2020-09-11T19:48:20.023+00:00

    Hi All

    Sorry for the belated reply. The reason for the issue was one of our configurations in CAS, precisely the Geo-location.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2020-03-04T00:50:11.53+00:00

    Error 50133: if they're seeing this error, it is advised to close out all sessions and re-login.

    Is it possible that there might be some duplicate users with more than one object ID occurring through the sync so that they're logging in with one using the password for another?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.