Share via

Global Administrator locked out after enabling Conditional Access – AADSTS500192 certificate required but no CBA configured

Brian Ingram 10 Reputation points
2026-03-01T11:47:13.2266667+00:00

Details

I am a Global Administrator in a Microsoft 365 tenant (cloud-only, no on-prem AD DS). After recently hardening security and enabling Conditional Access policies, I can no longer access the Microsoft Entra admin center or other admin portals.

When attempting to sign in, I receive the following error:

AADSTS500192: Either no valid certificate was detected on the device, or the user canceled the certificate selection.

There is no smart card, no client certificate, and no certificate-based authentication configured in the tenant. This is a standard Windows device without Windows Hello for Business certificate trust configured.

Environment details:

  • Cloud-only Entra ID tenant

Global Administrator account

Break glass Global Administrator account also affected

No on-prem PKI

No Entra CBA configuration completed

Conditional Access recently modified

Microsoft-managed policies were enabled:

Multifactor authentication for admins accessing Microsoft Admin Portals

  Require phishing-resistant multifactor authentication for admins

  
  Custom Conditional Access policies exist that may apply to:

  
     All users

     
        Global Administrators

        
           All cloud apps
```It appears a Conditional Access policy requiring either:

Certificate-based authentication

Or phishing-resistant MFA (authentication strength) has been enforced without excluding a break glass account, and without having certificate-based authentication properly configured.

Current issue: All Global Administrator accounts are blocked from portal access due to certificate requirement.

Questions:

What is the supported recovery path when Conditional Access requires certificate-based authentication but no certificates are deployed?

Is there a backend method to disable CA policies when all Global Admin accounts are blocked?

Can Microsoft Support temporarily disable Conditional Access enforcement at the tenant level?

I have Request ID, Correlation ID, and Timestamp available if needed.

This is an urgent administrative lockout scenario.

---
Post that exactly as written.

Do not edit it.

Then wait for official Microsoft response.

You are in a Conditional Access self-lock configuration. That is recoverable, but it requires Microsoft intervention if break glass is also blocked.Details

I am a Global Administrator in a Microsoft 365 tenant (cloud-only, no on-prem AD DS). After recently hardening security and enabling Conditional Access policies, I can no longer access the Microsoft Entra admin center or other admin portals.

When attempting to sign in, I receive the following error:

AADSTS500192: Either no valid certificate was detected on the device, or the user canceled the certificate selection.

There is no smart card, no client certificate, and no certificate-based authentication configured in the tenant. This is a standard Windows device without Windows Hello for Business certificate trust configured.

Environment details:

Cloud-only Entra ID tenant

Global Administrator account

Break glass Global Administrator account also affected

No on-prem PKI

No Entra CBA configuration completed

Conditional Access recently modified

Microsoft-managed policies were enabled:

   Multifactor authentication for admins accessing Microsoft Admin Portals
   
```yaml
  Require phishing-resistant multifactor authentication for admins

  
  Custom Conditional Access policies exist that may apply to:

  
     All users

     
        Global Administrators

        
           All cloud apps
```It appears a Conditional Access policy requiring either:

Certificate-based authentication

Or phishing-resistant MFA (authentication strength)  
 has been enforced without excluding a break glass account, and without having certificate-based authentication properly configured.

Current issue:  
 All Global Administrator accounts are blocked from portal access due to certificate requirement.

Questions:

What is the supported recovery path when Conditional Access requires certificate-based authentication but no certificates are deployed?

Is there a backend method to disable CA policies when all Global Admin accounts are blocked?

Can Microsoft Support temporarily disable Conditional Access enforcement at the tenant level?

I have Request ID, Correlation ID, and Timestamp available if needed.

This is an urgent administrative lockout scenario.

---
Post that exactly as written.

Do not edit it.

Then wait for official Microsoft response.

You are in a Conditional Access self-lock configuration.  
 That is recoverable, but it requires Microsoft intervention if break glass is also blocked.
Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. kagiyama yutaka 3,430 Reputation points
    2026-03-01T19:29:22.8833333+00:00

    when every GA gets locked behind that 500192 cert wall, the only real way back is a sev‑A n having support freeze ca eval so u can slip one clean sign‑in again. keep ur req‑id close — that’s the thread they pull to find the exact policy hit n lift the block without touching anything else.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.