Identity & MFA

Minimal guidance for messy support realities.

Entra sign-in logs show success but app still says unauthorized

Issue Summary

This article covers a Identity & MFA issue where Entra sign-in logs show success but app still says unauthorized. Use the path below to confirm scope, rule out simple causes, and move from user-safe checks into deeper administrator remediation without changing the article URL or taxonomy.

Conditional Access policy report only mode differs from live result

Issue Summary

This article covers a Identity & MFA issue where Conditional Access policy report only mode differs from live result. Use the path below to confirm scope, rule out simple causes, and move from user-safe checks into deeper administrator remediation without changing the article URL or taxonomy.

Legacy app password disabled and scanner workflow breaks

Issue Summary

This article covers a Identity & MFA problem centered on Legacy app password disabled and scanner workflow breaks. Use the path below to verify symptoms, separate workstation-level causes from service-side causes, and escalate cleanly if standard repair steps do not hold.

Hybrid join succeeds but primary refresh token missing

Issue Summary

This article covers a Identity & MFA issue where Hybrid join succeeds but primary refresh token missing. Use the path below to confirm scope, rule out simple causes, and move from user-safe checks into deeper administrator remediation without changing the article URL or taxonomy.

Break glass account excluded from MFA cannot sign in

Issue Summary

This article covers a Identity & MFA issue where Break glass account excluded from MFA cannot sign in. Use the path below to confirm scope, rule out simple causes, and move from user-safe checks into deeper administrator remediation without changing the article URL or taxonomy.

Authenticator number matching works but sign-in still denied

Issue Summary

This article covers a Identity & MFA issue where Authenticator number matching works but sign-in still denied. Use the path below to confirm scope, rule out simple causes, and move from user-safe checks into deeper administrator remediation without changing the article URL or taxonomy.

Password writeback succeeds but users cannot unlock accounts

Issue Summary

This article covers a Identity & MFA issue where Password writeback succeeds but users cannot unlock accounts. Use the path below to confirm scope, rule out simple causes, and move from user-safe checks into deeper administrator remediation without changing the article URL or taxonomy.