question

SheldonDickinson-6538 avatar image
0 Votes"
SheldonDickinson-6538 asked amanpreetsingh-msft edited

After enabling identity protection, all admins are stuck in a risky sign in loop

I foolishly enabled some IP features without following guide and now my admin accounts are all locked out.

Issue appears to be that user is flagged as risky, is prompted to verify identity and reset password. however, we haven't enabled SSPR so the user then gets into a horrible loop.

163530-image.png


163611-image.png

163621-image.png


azure-security-centerazure-ad-ssprazure-ad-identity-protection
image.png (38.8 KiB)
image.png (68.3 KiB)
image.png (15.6 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

amanpreetsingh-msft avatar image
0 Votes"
amanpreetsingh-msft answered amanpreetsingh-msft edited

Hi @SheldonDickinson-6538 • Thank you for reaching out.

If none of your Admin accounts is able to sign in to the Azure portal, it is considered as a lockout scenario. Unfortunately, in this case, there is no other option than opening a support ticket to get access to your tenant. Support team can engage the Data Protection team and will require some evidence that will prove your ownership of the Azure Account to unblock you.

You can open a support ticket using the Azure portal (if you have another Azure account) as well as by calling customer service number for your country/region. Also, please go through Manage emergency access accounts in Azure AD to configure a break-glass account so that, going forward, you don't lock yourself out.


Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.