User locked out of Microsoft account by MFA bug, complains of customer-hostile support
- Reference: 1634068745
- News link: https://www.theregister.co.uk/2021/10/12/user_locked_out_of_microsoft/
- Source link:
Gizdov is founder of KGE Consultancy Ltd in Edinburgh and an Arch Linux [1]Trusted User .
His problems began when he received an email informing him that his Microsoft account had been renamed. "I immediately clicked on the 'That was not me' button," he said in a [2]post , after which he managed to contact support.
[3]
He already had two-factor authentication on his Microsoft account. He still does not know why he received this email, which the support person implausibly claimed was because of someone else's sign-in mistake, but could not see any sign of compromise.
[4]
[5]
A Microsoft account is distinct from a Microsoft 365 account, and although it is mainly aimed at consumers it is hard to avoid, for logging onto a new Windows PC or obtaining apps from the Microsoft Store. "This specific Microsoft account is very important to me personally and professionally," Gizdov tells The Reg .
"Not only that, but Microsoft by policy require a personal account in order to be able to back up MFA and sync between devices."
[6]
If he lost access, "I'd have lost all my stuff and [it would have had] great impact on my starting business," he says.
Assets protected by a Microsoft account can include OneDrive files, Outlook.com or Hotmail email accounts, and even the Bitlocker key for an encrypted hard drive.
Gizdov decided to tighten the security on the account, by removing the option to sign in using his phone number, which Microsoft added automatically when he was forcibly migrated to use the Microsoft Authenticator app. He says he did not remove the phone number, merely the option to use it as a sign-in alias.
[7]
At that point, things went downhill fast. The page went blank and said "the URL is no longer available." Further, says Gizdov, "in under 30 seconds, all my devices were automatically logged out."
He drew on his extensive background experience with Microsoft's systems to fix the issue. Nothing worked. He could not log in; he could not reset the password; he got misleading errors like "we could not find an account with that username."
In the end he diagnosed the problem as "the account login still thinks that MFA should happen. However it cannot. I've been locked out of the account for good."
Time to contact support, for which he had to open a new Microsoft account. He says he spent "literally hours in the online chat" and was finally asked to submit an account recovery form. He did so, supplied all sorts of personal information, but "the automated recovery program" rejected all his efforts.
He contacted support again, was given a new account reinstatement form, but that did not work because… the account was not suspended.
Gizdov got in touch with a human support person (itself an achievement) and was told: "We have no reports of issues on our platform. There are no bugs. Please login with the required credentials as your account is set up for MFA. We will not escalate your issue as it is not a hacking attempt. Goodbye and have a nice day!"
Make sure you have a recovery code
[8]
Make sure you have a recovery code, advises Gizdov
Gizdov's account was saved by two things, he says. First, he remembered that he had stored an account recovery code in his password manager. A recovery code can be obtained via "Advanced security options" and then "Recovery code." This would have allowed him to recover the account but only after 30 days.
"Why would I give a 30-day notice to my hacker to secure their new account or wait 30 days to access my account in an emergency?" he says.
Second, his story was widely circulated and was spotted by Microsoft Identity VP Alex Simons, who [9]responded this morning on Twitter . "I am SO sorry. Please accept my apologies. Thank you for surfacing & including the details. The team has diagnosed. Was caused by a recent regression. Fix is being deployed. Will go live worldwide overnight. We will also debug and fix the support experience as well."
The bug was fixed and Gizdov says he was able to log in, though the system is still buggy and he gets errors like "we couldn't send a notification to your phone at this time", for example when trying to set up passwordless login. "It is a crazy loop of madness," he says.
What does he think of the support experience? "Microsoft support is trained and held up to the standard to refuse help and deny everything. Even to explicitly not listen to new reports by individuals," he tells us.
That makes no sense; but recall that the support agent specially refused to accept his bug report or help him resolve it. "Bugs will always arise, it's how they deal with them that's the problem," Gizdov tells us. "I'd had to rely on the luck of my post being popular on Hackernews to get anyone that can address the issue to see it."
Is part of the problem that Microsoft accounts are treated as a free offering? "I believe yes. Part of the problem is that even though I'm paying for lots of Microsoft services they treat all personal accounts as free and on top of that they do not have a dedicated team dealing with the issues," he says.
[10]It's time to delete that hunter2 password from your Microsoft account, says IT giant
[11]Microsoft warns against SMS, voice calls for multi-factor authentication: Try something that can't be SIM swapped
[12]COVID-19 security tips: Ensure you sack your staff without leaving their IT access enabled, says Secureworks
Is Microsoft worse than other companies? The closest equivalent perhaps is a Google account, although in our experience it is easier to contact someone at Microsoft than at Google (for consumer accounts). "I'd say Google has a better overall policy on MFA and more modern procedures, which reduces the chance of users ending up in that situation," says Gizdov, though he adds that his view is anecdotal.
He notes that Microsoft itself [13]recommends against using a phone for authentication, yet its own consumer system pushes users towards it. "The GSM and phone systems are inherently insecure as they've not kept up to date with the growth of security threats," he says.
Gizdov is indignant that "[Microsoft] claimed they hold no responsibility and it's all my fault. I believe that when I'm paying for a service and enter in a contract with a company, the company is responsible for delivering that service. Microsoft has failed on delivering their service and thus should be responsible."
Will he continue to use a Microsoft account? "Yes, I will as unfortunately Microsoft is so big and seeps into everything, so barely any IT professional nowadays can get by without a Microsoft account." His advice to others, though, is that "people need to create and keep safe an account recovery code."
The problem is a tough one for the identity provider, as making account recovery too easy could help hackers, and providing human support is expensive, but that does not excuse the factors in Gizdov's experience.
Simons was the right person to reach, and the speed of the fix was in a sense impressive. The issue about debugging "the support experience" is a bigger challenge though, and there are others less expert than Gizdov, or less fortunate on social media, who have unresolved issues. ®
Get our [14]Tech Resources
[1] https://wiki.archlinux.org/title/Trusted_Users
[2] https://kgizdov.medium.com/the-efficiency-of-microsoft-e50ea81f69f5
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWYFnTzdiVHh4vbMGGhSpgAAABI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnTzdiVHh4vbMGGhSpgAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWYFnTzdiVHh4vbMGGhSpgAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnTzdiVHh4vbMGGhSpgAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWYFnTzdiVHh4vbMGGhSpgAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://regmedia.co.uk/2021/10/12/recovery.png
[9] https://twitter.com/Alex_A_Simons/status/1447800867785113601
[10] https://www.theregister.com/2021/09/16/microsoft_passwordless/
[11] https://www.theregister.com/2020/11/11/microsoft_mfa_warning/
[12] https://www.theregister.com/2020/10/15/secureworks_report/
[13] https://techcommunity.microsoft.com/t5/azure-active-directory-identity/it-s-time-to-hang-up-on-phone-transports-for-authentication/ba-p/1751752
[14] https://whitepapers.theregister.com/
"Clicked on" in this case probably means copied the URL, inspected the URL, verified that it did in fact go to a Microsoft-owned domain which it did, verified that it was an expected domain name which it was, and one that a standard user couldn't edit which it wasn't, and then put it in a browser. Like we do all the time because people do send legitimate URLs in emails. They don't need to pad out that part of the description when it wasn't a malicious link, do they? Your assumption and the conclusion you imply, despite that conclusion having nothing to do with the problem reported, is not useful.
We just made a service that runs on an Android "burner phone" to forward the MFA code bullsh*t to our IRC channel.
Not playing Microsoft's insecurity game. They are just slowing everyone down.
No-one should be storing sensitive data on a Microsoft service anyway so who cares? Just use it like you would a public toilet.
Please list any services you run so I know to avoid them. I'm guessing you do store sensitive information on that service, or you wouldn't have the account, and you have other security problems involving more important accounts. I'd like to make sure the information that gets leaked isn't mine.
No Support
I pay for Office365, and had an issue with photo image file integrity on OneDrive ( they change the metadata in the image file). Raised a support case, lots of back and forth supplying all the evidence, logs, etc. They promised to get back to me. Then it went quiet. My requests for an update on the case are ignored. Support Case number now in limbo. I will not be renewing my subscription.
"so barely any IT professional nowadays can get by without a Microsoft account."
If any IT professional has got an MS account it's because they want one.
Similar thing with google
Paid for a developer account. Used a private email address. Login was only allowed from certain ASNs. Changed ISP and then could no longer log in.
Spent two days tried to find someone at the crack security team. Ended up speaking with someone wanting to flog domain names. Thankfully, I had logged in from a cloud machine and because the cookies were there from my original ISP, there was a history of this machine. Otherwise there would have been no way to log in again.
Nothing has changed
My first experience with MS support was in 1990, they were unhelpful, they told me that what I was trying to do couldn't be done. They were wrong. My second experience was earlier this year, their response was exactly the same as before and just as inaccurate. It's not a bug fix that's needed - it's a complete rewrite of the corporate culture.
Re: Nothing has changed
My experience from the early 90s turned me from Window to a unix professional. Their support denied an issue that I had proven was with a MS driver for a plotter.
Since then the only time I deal with Windows is for my wife's gaming rig. I stay well away from anything that comes the diseased minds of Redmond as only madness and ruin lie in their domain.
the stories you hear on r/realms or r/minecraft are horrific - minecraft players are being migrated to MS accounts, and in the case of issues, trying to get hold of a real person is a nightmare. In the case of realms which is subscription based, it is poor form - they are paying customers.
Early on in my life, I decided two things:
1. No Microsoft
2. No Java
I am very happy with those choices.
Lowest Common Denominator
I can't even begin to imagine how many nonsense support requests they will have to work through on a daily basis. Having experienced both the consumer and professional support they're very much geared for "keep restarting your pc until the problem is fixed".
> providing human support is expensive
This is what I find annoying. The size of the profits being made by these companies and they can't pay for support staff?
And when you do find that rare human, they have a script that says the company is perfect without bugs. Why are staff not allowed to use their own brains any more?
ARGH!
I 2FAiled recently...
I left both my yubikeys 1600 miles away, because I wasn't used to needing them, and didn't need either ring of physical keys at my destination, so left them safely at home.
A week without access to some accounts is refreshing, or so I tell myself.
A genuine IT professional would not click willy-nilly on a link on an unsolicited email.