After enabling identity protection, all admins are stuck in a risky sign in loop

Sheldon Dickinson 1 Reputation point
2022-01-10T10:50:02.687+00:00

I foolishly enabled some IP features without following guide and now my admin accounts are all locked out.

Issue appears to be that user is flagged as risky, is prompted to verify identity and reset password. however, we haven't enabled SSPR so the user then gets into a horrible loop.

163530-image.png

163611-image.png

163621-image.png

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. AmanpreetSingh-MSFT 56,876 Reputation points Moderator
    2022-01-10T11:03:04.017+00:00

    Hi @Sheldon Dickinson • Thank you for reaching out.

    If none of your Admin accounts is able to sign in to the Azure portal, it is considered as a lockout scenario. Unfortunately, in this case, there is no other option than opening a support ticket to get access to your tenant. Support team can engage the Data Protection team and will require some evidence that will prove your ownership of the Azure Account to unblock you.

    You can open a support ticket using the Azure portal (if you have another Azure account) as well as by calling customer service number for your country/region. Also, please go through Manage emergency access accounts in Azure AD to configure a break-glass account so that, going forward, you don't lock yourself out.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.