
Microsoft Confirms Entra Account Lockouts Due to Token Logging Error
MicrosoftSecurity
This content is an AI-generated summary. If you encounter any misinformation or problematic content, please report it to cyb.hub@proton.me.
Microsoft has confirmed that the Entra account lockouts that occurred over the weekend were due to the invalidation of short-lived user refresh tokens, which were mistakenly logged in internal systems. This incident resulted in account lockouts for Entra users. Refresh tokens are essential for keeping user sessions active without requiring frequent re-authentications. The error affected users' ability to access their accounts, thereby disrupting associated services.