Source: BleepingComputer Author: Lawrence Abrams URL: https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/
-
ONE SENTENCE SUMMARY: A widespread false-positive issue with Microsoft’s new Entra ID “MACE Credential Revocation” app mistakenly locked numerous user accounts.
-
MAIN POINTS:
-
Microsoft Entra ID’s new MACE app rollout triggered widespread false account lockouts.
-
Alerts began last night, locking accounts that had unique passwords and MFA protections.
-
Admins reported thousands of lockout notifications across multiple organizations.
-
Reddit threads confirm multiple businesses experienced significant user account impacts.
-
Affected accounts showed no suspicious activity or matching data breaches.
-
Microsoft privately attributed the issue to errors during MACE app deployment.
-
The MACE Credential Revocation app detects leaked credentials to protect user accounts.
-
Lockouts were mistakenly flagged as leaked credentials from dark web breaches.
-
Microsoft has not yet publicly acknowledged or explained the incident officially.
-
Administrators should verify alerts but recognize mass lockouts likely due to rollout issue.
-
TAKEAWAYS:
-
Carefully monitor automated security rollouts for potential false positives.
-
Confirm alerts with independent breach notification tools like Have I Been Pwned.
-
Maintain clear communication channels with vendors to quickly resolve issues.
-
Consider temporarily disabling automated lockout actions during major updates.
-
Ensure rapid internal communication to minimize user disruption during incidents.