AADSTS50076: Due to a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to access

Jabulani Motloung 191 Reputation points
2023-07-27T04:51:29.4833333+00:00

Hi,

We are unable to access our tenant and any of our Azure subscriptions due to this error:

AADSTS50076: Due to a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to access.

No change was made at a tenant level. Help to resolve this will be highly appreciated.

Regards

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,041 questions
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Christopher Rautner 76 Reputation points
    2023-07-28T06:03:33.15+00:00

    We had the same Problem occuring today in one of our tenants (the others had no problem). We used our Emergency Admin (no MFA Activated) and revoked the MFS Sessions for our users. After that we where able to login as usual.

    If you should not have such an emergency admin you can try to create a new user via m365 admin center


4 additional answers

Sort by: Most helpful
  1. Dillon Silzer 57,831 Reputation points Volunteer Moderator
    2023-07-27T05:12:57.5933333+00:00

    If you are unable to access any of your Administrator accounts, then I would recommend you reach out to Microsoft Business support:

    Global Customer Service phone numbers (see For Business users):

    https://support.microsoft.com/en-gb/topic/global-customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2

    As Will mentioned, you should always have a break-glass account when testing out these policy changes.


    If this is helpful please accept answer.

    1 person found this answer helpful.
    0 comments No comments

  2. Will 425 Reputation points
    2023-07-27T05:05:39.9333333+00:00

    Errr are you not able to access it even with your emergency break glass accounts?

    MSFT usually recommends that you make at least 2 of these accounts with onmicrosoft.com domain (cloud only) so that one can always have a way in.

    These accounts would be out-of-band in a manner of speaking for most everything:

    • No federation
    • Exceptions from conditional access policies
    • MFA with another method like FIDO2
    • etc
    0 comments No comments

  3. Jabulani Motloung 191 Reputation points
    2023-07-28T16:04:20.1+00:00

    Hi All,

    Issue has been resolved.

    So revoking MFA sessions and waiting for about 30 minutes (well in my case) resolved the issue.

    Regards

    0 comments No comments

  4. Atul 0 Reputation points
    2025-01-02T14:03:42.3633333+00:00

    This is indeed a nasty bug and because of this Microsoft Azure kept me me away for three days from subscription that I was given access to. This issue suddenly emerged. When everything was working fine, one fine day I just stopped getting notification to Microsoft Authenticator, without any reason!

    Solution is you need your admin (in my case it was my client's admin) to revoke MFA for your user id.

    1. Admin need to go here: https://portal.azure.com/#home
    2. Then <Your org>| Users -> Users -> <your username>
    3. You will see screen something like this ((The screenshot below shows these options disabled but for an Admin it should be enabled) AdminNeedToRevokeReregisterMFA_to_pot_on_forums
    4. Here the admin has to click on "Require re-register multifactor authentication" and "Revoke multifactor authentication sessions"
    5. Ask admin to do this for all directories (with and without subscriptions)
    6. Once done, try logging in to your Azure account and try to access subscription on https://portal.azure.com#home This time it will run you through wizard as if you are adding Microsoft Authenticator for the first time. Once the wizard is complete you are all set.

    This is so bad on the part of Microsoft that they didn't even care to see if authenticator has received or not the notification (verification numbers) they sent to it!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.