Source: BleepingComputer Author: Lawrence Abrams URL: https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/
ONE SENTENCE SUMMARY:
A widespread false-positive issue with Microsoft’s new Entra ID “MACE Credential Revocation” app mistakenly locked numerous user accounts.
MAIN POINTS:
- Microsoft Entra ID’s new MACE app rollout triggered widespread false account lockouts.
- Alerts began last night, locking accounts that had unique passwords and MFA protections.
- Admins reported thousands of lockout notifications across multiple organizations.
- Reddit threads confirm multiple businesses experienced significant user account impacts.
- Affected accounts showed no suspicious activity or matching data breaches.
- Microsoft privately attributed the issue to errors during MACE app deployment.
- The MACE Credential Revocation app detects leaked credentials to protect user accounts.
- Lockouts were mistakenly flagged as leaked credentials from dark web breaches.
- Microsoft has not yet publicly acknowledged or explained the incident officially.
- Administrators should verify alerts but recognize mass lockouts likely due to rollout issue.
TAKEAWAYS:
- Carefully monitor automated security rollouts for potential false positives.
- Confirm alerts with independent breach notification tools like Have I Been Pwned.
- Maintain clear communication channels with vendors to quickly resolve issues.
- Consider temporarily disabling automated lockout actions during major updates.
- Ensure rapid internal communication to minimize user disruption during incidents.