Everyone locked out of tenant due to a faulty Conditional Access Policy

Tommy Ekkerman 25 Reputation points
2024-02-27T13:14:59.8366667+00:00

We have been locked out of our tenant for over a week now due to a faulty Conditional Access policy. During this week, there have been several conversations with a number of Microsoft support technicians, none of which seemed to have an understanding of the actual issue at hand or able to resolve the issue and all ended up assigning the case to a different team. We know exactly what is wrong and how to fix it. But we need the help of the Data protection team. Since this is a high impact incident and things are moving too slow via the regular support channels, we are trying to get in touch with them through this channel. We came across similar incidents on this forum and saw that they responded quickly. Our current support case number is 2402230040005762

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
341 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,566 questions
{count} votes

Accepted answer
  1. Givary-MSFT 28,321 Reputation points Microsoft Employee
    2024-02-28T05:25:32.58+00:00

    @Tommy Ekkerman Thank you for reaching out to us, reviewed this case 2402230040005762, I see the support engineer has worked with the engineering team to exclude one of the user accounts from the conditional access policy which you have applied in your tenant.

    Exclusion of the user account is in place for your tenant/would be in that state for next 24 hrs, would request you to access the entra id portal and take further steps so that you restore the access.

    In such cases, always follow a best practice to create a break glass account https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful