2097 Posted February 5 Posted February 5 Our current setup is Hybrid with SSO with office.com As far as i can tell the AD connect tool is working fine . I have a single user ( Despite me changing their password ) cannot access office.com this week ( i tried logging in with a private browser also ). It states username or password incorrect. BUT ! , if they login to the domain computer , SSO allows them access to office.com fine . Its also affecting samlearning and satchel . I have gone through everything i can think of and done a fresh resync from the AD connect tool , but the issue persists . Anyone had anything similar ? Thanks
AlphamaleZed Posted February 5 Posted February 5 Go to admin.microsoft.com and check the user under the site and if they have a mailbox license and the mail attributes are correct.
2097 Posted February 5 Author Posted February 5 Indeed everything is correct . They were working ok uptil Monday this week . They can login on the domain ( local machine ) , and SSO allows them to login to office.com with the same password ( But does it automatically ) He cannot from a normal computer login using hes microsoft credentials on any other device , it simply says username or password wrong.
AlphamaleZed Posted February 5 Posted February 5 5 minutes ago, 2097 said: Indeed everything is correct . They were working ok uptil Monday this week . They can login on the domain ( local machine ) , and SSO allows them to login to office.com with the same password ( But does it automatically ) He cannot from a normal computer login using hes microsoft credentials on any other device , it simply says username or password wrong. whats on proxy addresses in AD? looks like a mismatch.
2097 Posted February 5 Author Posted February 5 9 minutes ago, AlphamaleZed said: whats on proxy addresses in AD? looks like a mismatch. Thanks for helping . I have compared the ProxyAdddresses attibute on both ad and Entra They both are the same They begin with x500:/o=ExchangeLabs and end in their username . I can also see when i change the password in AD it does update office.com logins . Its a very strange issue on just a single account
AlphamaleZed Posted February 5 Posted February 5 5 minutes ago, 2097 said: Thanks for helping . I have compared the ProxyAdddresses attibute on both ad and Entra They both are the same They begin with x500:/o=ExchangeLabs and end in their username . I can also see when i change the password in AD it does update office.com logins . Its a very strange issue on just a single account aint that legacy? must be some old accounts lol Try: SMTP:[email protected] smtp:[email protected] - (if needed) SMTP is primary and smtp is alias you can add loads of aliases. also check on the AD attributes the "Account" section is correct for user login name as well as pre 2000 name are correct to avoid mismatch.
2097 Posted February 5 Author Posted February 5 1 minute ago, AlphamaleZed said: aint that legacy? must be some old accounts lol Try: SMTP:[email protected] smtp:[email protected] - (if needed) SMTP is primary and smtp is alias you can add loads of aliases. also check on the AD attributes the "Account" section is correct for user login name as well as pre 2000 name are correct to avoid mismatch. We used to host inhouse Exchange - Domain controllers probably still have the old attributes from the inhouse exchange. The accounts are only a few years old . But this one has experianced this issue only since monday. Im starting to think it might be something on the cloud end with possible Risky User ( possible conditional access ) so will end up looking there ! Thanks for your help 1
NegativeKillDeath Posted February 5 Posted February 5 Do you have a different region keyboard at log on screen and once logged in? And do they have a special character in their password that might map different on say US keyboard layout?
2097 Posted February 6 Author Posted February 6 Nope , I am trying these direct from my machine . ( so i know the passwords going in correct ) Something is def going on within the microsoft backend . I have another user whos been "Microsoft Cloud Locked Out" since yesterday . Manage to get them "Unlocked" , but now the password doesnt work and i cannot log her in either . So i now have two accounts with the same issue They are not in Risky users . I have reset their password , and can see that the passwords synced correctly They both seem to be able to login to the domain and SSO works fine ? so they can access all their files . SatchelOne , Samlearning and all Teams within school !
2097 Posted February 6 Author Posted February 6 (edited) Another thing what is confusing , If i use my test account , type the password in incorrect 5 times and it locks the account ( On Office.com ). These accounts dont seem to be locking , despite it saying the password is incorrect ? Edited February 6 by 2097
DWilson1997 Posted February 6 Posted February 6 What is it saying in the Entra sign in logs? What are the conditional access policies saying are being applied to the login? Is there any risk level associated with the sign in?
2097 Posted February 6 Author Posted February 6 Hi Its saying the following Sign-in error code 50126 Failure reason Error validating credentials due to invalid username or password. Additional Details The user didn't enter the right credentials. It's expected to see some number of these errors in your logs due to users making mistakes. No risk assigned , I have gone back a month in the singin logs , seems they both have been experiancing this issue for atleast a month
2097 Posted February 9 Author Posted February 9 Have now found another user with a similar/same issue . I have done the following Deleted their online account - Re-ran sync took which effectivly re-enables it - Didnt work. Upgraded the Entra connect tool to the latest version - Didnt work . Not really sure what else i can do , I think at some point they have been blocked for multiple incorrect logins and for some reason not cleared .. But theres no instances where i can unblock .
2097 Posted February 23 Author Posted February 23 Just to update , We now have quite a few that are having this issue . Passthrough seems to allow them access within school , But as soon as you use a private browser or a device outside they get password incorrect mostly . No one else ever had this issue ?
NicholasEsping Posted February 23 Posted February 23 (edited) 8 hours ago, 2097 said: Just to update , We now have quite a few that are having this issue . Passthrough seems to allow them access within school , But as soon as you use a private browser or a device outside they get password incorrect mostly . No one else ever had this issue ? Have you tried updating the proxy and target address to the SMTP:[email protected] format? I have not seen office 365 work with only x500:/o=ExchangeLabs listed for these. Also do you see any sign in attempts in their sign in logs when you are getting the username/password error? Edited February 23 by NicholasEsping
NegativeKillDeath Posted February 24 Posted February 24 Is password Hash Sync enabled in your Entra Connect Sync?
2097 Posted February 25 Author Posted February 25 On 23/02/2026 at 20:27, NicholasEsping said: Have you tried updating the proxy and target address to the SMTP:[email protected] format? I have not seen office 365 work with only x500:/o=ExchangeLabs listed for these. Also do you see any sign in attempts in their sign in logs when you are getting the username/password error? I havent changed any of the Proxy address's , All our accounts are the same , They have the X500 , but also have the SMTP:[email protected] . So far , i have found only issues with accounts from a specific year . ( Single OU ) , moving that account out of the OU and syncing also didnt solve it . The error is for each signin Sign-in error code 50126 Failure reason Error validating credentials due to invalid username or password. But , Obviously the password is correct . I have tried changing it also. If i type in the account password wrong multiple times it never locks out onsite or in azure. ( like they are not linked ) , But the account details match the correct SID etc and picked up the movement of OU ( So i do know its refering to the correct account ) I have been passed on twice now , But no one at microsoft at the moment is "Assigned" .
2097 Posted February 25 Author Posted February 25 On 24/02/2026 at 08:37, NegativeKillDeath said: Is password Hash Sync enabled in your Entra Connect Sync? Indeed it is . I have forced a delta initial to forcesync everything again , But still does not work.
robintech Posted February 27 Posted February 27 On 25/02/2026 at 10:23, 2097 said: Sign-in error code 50126 Failure reason Error validating credentials due to invalid username or password. Does Entra say the "Authentication Details" is Password Hash Sync when it fails. Also any expired passwords as maybe that would cause weirdness as Entra might not be syncing expiry? Also a PowerShell comparison of a working vs non working account only highlighting differences sometimes helps find something. Fascinating problem though
2097 Posted February 27 Author Posted February 27 Going through the logs i get the following Passthrough Authentication request failed. RequestId: Reason: '1326' Googling comes up a little more about it .A job for Monday i think
2097 Posted March 2 Author Posted March 2 Noticed the following on the MS admin Portal Quote Title: Some admins or users may be unable to access multiple Microsoft 365 services User impact: Admins or users may be unable to access multiple Microsoft 365 services. More info: This specifically impacts Microsoft 365 services that have the SecurityEnabled property changed to False by the Group Configuration Processor. While we work on deploying our fix to update the SecurityEnabled property from False to True, admins can run the following cmdlets to mitigate the impact. MY users who are affected , They are part of Teams Class's Which have the SecurityEnabled property set to False . I have now removed a user from these teams , going to see what then happens.
2097 Posted March 3 Author Posted March 3 19 hours ago, 2097 said: Noticed the following on the MS admin Portal MY users who are affected , They are part of Teams Class's Which have the SecurityEnabled property set to False . I have now removed a user from these teams , going to see what then happens. Unfortunatly , that didnt help much ! The only thing i have found out so far , all these users are the same year group and possibly the same class. Apart from Joint teams , they have no other connection.
2097 Posted March 3 Author Posted March 3 SOLVED ! For anyone else having this issue . I use an automated script to create exam accounts. We create the exam accounts with their user ID e.g. 1234 with a letter on the end . Turns our when i did the last class i didnt include the letter on the end when it came to their UPN So we had duplicates running ! so it was causing some majour issues there ! Looks like the script bypasses the AD validation as you wouldnt normally be able to do it . Microsoft IDFIX tool saved the day ! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now