• O365 Modern Auth Login Loop

    Author
    Topic
    #2275051

    Reaching out to the hive mind because we’re all stumped.

    We have O365 through corporate, Modern Auth and MFA enabled. We recently changed domains (locally, not corp-wide), @foo.bar to @fizz.bar, and have been having trouble ever since. Most times just rebuilding their Outlook profile fixes it, but for some users once it gets to the Modern Auth page, you enter the new email address, it acts like it’s about to go to the password screen, but then it just goes back to the email entry.

    It would make sense that users changing email addresses might have to redo their profile, stuff gets clogged, but brand new users who have never logged into anything before are also having this problem.

    Windows 10, Office 2016/2019, AD. We’re in a separate forest than corporate, no trust relationships, but our O365 accounts are all managed in their forest that has an AAD sync. Corporate reports we’re the only ones with this issue, which makes sense because we’re the only ones out here changing our email addresses.

    Last time I pushed updates was 6/1/2020-ish, it was shortly after Woody moved us to MS-DEFCON 4. Don’t think it was an update, some computers are shared and a few users can use Outlook on it just fine while others can’t. Our DC forwards DNS to corp’s servers, so we’re pretty convinced it’s not DNS.

    For some people it did trigger after they had to update their corp password (only once did clearing out Credential Manager fix it). At this point I’m thinking it’s not anything in our environment, something is up with corp’s AAD sync. They use MIM/FIM to manage users and on new accounts when I enable mailboxes I have seen a couple new flags be given values that I know the older accounts don’t have.
     
    Am I missing something glaringly obvious? Any ideas as to what could be going on?

    Thanks, all!
    JoDrRe

    Viewing 1 reply thread
    Author
    Replies
    • #2275059

      And you’ve made sure that cached credentials aren’t left behind?  open a command prompt put in this below and see if there is something left behind?

       

      rundll32.exe keymgr.dll,KRShowKeyMgr

      Susan Bradley Patch Lady/Prudent patcher

      2 users thanked author for this post.
      • #2275115

        AAH! IT’S YOU! Big fan.

        There were some saved creds in there for a returning user, so I blew them away and was able to get her profile fixed on that machine.

        I haven’t had a chance yet with a new user, so I’ll give that a shot and report back.

         

        Thanks!

        1 user thanked author for this post.
    • #2399351

      Came across my post while searching for the same thing. Commenting for posterity; had a user come to me with a laptop he hasn’t used in a while (but it stays plugged in and updated) and wanted his Outlook set up so he could work remotely for a few days due to *gestures broadly*.

      Same symptoms, kept looping on the email screen. Repaired Office, checked Credential Manager (empty), checked Susan’s suggestion (empty), tried our previous workaround (press Enter a bunch of times and maybe you can trick it)… nothin’. Grabbed another laptop, signed into the network as him, same issue with Outlook.

      The fix? Unplug from the domain network and join the guest wifi.
      It didn’t auto-fill his email address (since it couldn’t pull from AD) so I put in his name and email, skipped password, hit Next, and Modern Auth appeared and let me put in his password.

      So it either was our firewall blocking something (odd) or since it was technically a manual setup maybe it tried calling MA differently?

      In a year when this happens again and I come across this thread again maybe I’ll have a better explanation.

    Viewing 1 reply thread
    Reply To: O365 Modern Auth Login Loop

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: