9 ms·
Can't sign in with FIDO2 key on office.com
- Analemma_ 3y agoCan someone from Microsoft share why the login flow on all things Office/O365 is such a disaster? No other major company is so bad about this. You get bounced between a half-dozen domains (which I assume is somehow the root cause of the issue here), the "keep me signed in" check box literally does nothing, and so on. And you can't even blame it on trying to integrate incompatible legacy systems, this is all on Microsoft's first-party services.
- jiggawatts 3y agoThe latest madness is that logging on to Azure Portal with Firefox requires about ten clicks on the user name. As in: I log in, jump through the MFA hoops, and then it goes back to the list of user names to make me re-select the account I just used to log in. Mind you, it always did this, which meant that I couldn’t just open a Portal link in a new tab — I’d have to select my account (again) for each tab. But now I have to click at least ten times! It’s broken. Authentication is broken and there’s no one at the wheels.
- nathanaldensr 3y agoThere are probably no actual wheels to begin with, knowing Microsoft.
- esafak 3y agoI have spent weeks just trying to log onto Teams to communicate with an MS contracting shop. I still have not managed to log in. It is infuriating beyond belief.
- magicalhippo 3y ago> You get bounced between a half-dozen domains At work one of the cdn domains they use fails to resolve until it suddenly works. Haven't bothered to look into it yet, but generally takes about 10-15 minutes to sign into anything related to Azure AD / Office365. Can resolve it just fine on the command line, just in the browser where it doesn't work.
- tremon 3y agoSame with the Azure Portal, I can regularly DoS microsoft by opening the portal from a bookmark in Edge, or by switching Azure tenants (via the official button, which has also seen three different locations in the past year). It signs in, loads the intended page, then redirects to the home page, which performs the sign-in again, then redirects to the Azure portal welcome screen, which redirects to the home page, which performs the sign-in again -- at which points Microsoft usually "solves" the redirect loop by informing me that I've tried to login too many times and I should try again in five minutes. With the additional bonus that even after things miraculously stabilize, I'm not on the page I wanted to go but on the welcome screen. Pasting the intended link again in the browser bar seems to have a 10% chance of triggering the redirect loop again. It's so comically bad, I'm glad my employer is paying me for my time and not my productivity.
- leokennis 3y agoAnd the domains look ancient or shady as well. Live.com, aka.ms, msn.com…if you didn’t already know they were genuine Microsoft accounts you’d be smart to assume you were being scammed.
- ano-ther 3y agoThey also introduced 2F verification pop ups that don’t show up in the task bar and are therefore not selectable when they are behind another window.
- tredre3 3y agoAlso some of that bouncing around involves passing your email into the URL (?account=you@outlook.com) which is just bizarre in current day (tm).
- easton 3y agoMy AAD account is permanently screwed up because I left and rejoined the company I’m at (intern conversion, so I got a new AAD account with the same email). I get signed out constantly, especially on mobile where my coworkers do not. Trying to sign into ADO sends me to a screen prompting me to configure a new org because it gets confused by two accounts existing with the same email in the same org even though one of them was deleted along with the underlying AAD account. It also just 500s sometimes when trying to login saying there’s something weird happening during authentication, I have to restart the browser to make it work. As far as I know there’s no way to fix any of it, so I’m stuck with half working SSO.
- kstrauser 3y agoAh, their famous Stochastic Sign-On.
- CogitoCogito 3y agoWhy don't they just give you a new email? I mean obviously it's stupid such a solution would be required, but wouldn't that solve your problems?
- easton 3y agoI think the actual easiest thing would be to get on the horn with MS and have them internally nuke my old ADO account, I’ve just never bothered to figure out who out of IT org could do such a thing. I’ve just learned all the workarounds instead.
- grenoire 3y agoDo these guys run integration tests of any kind? Makes it easy to assume malice in breaking fundamental features.
- campbel 3y agoRandom stuff breaking or things not working quite right is to be expected with Microsoft products.
- Waterluvian 3y agoOffice 365 Calendar broke for me a few weeks back and is still unusable. It forcibly leaps me weeks ahead whenever I try to scroll to today’s date. I literally cannot view my work calendar on my phone anymore. I often wonder if they’re even capable of knowing there’s an issue.
- jiggawatts 3y ago> integration tests of any kind No! Microsoft famously fired their entire QA team. Also… their technical writing team. And then they outsourced both support and the bulk of their development to India. You get what you pay for, and right now Microsoft is variously paying either zero or very little.
- makeitdouble 3y agoI'd see Microsoft hiring contractors, but do they outsource product development to external companies ?
- jiggawatts 3y agoNot sure about development, but Azure support is almost entire outsourced.
- makeitdouble 3y agoAt this point I think it's par for the course. There must be some support tiers where you'll get actual Microsoft employees deal with your issues (I don't think Apple's devs get a random contractor reading a script when they report server issues), but short of that I would feel lucky to even get a human to look at the question.
- esafak 3y agoMeanwhile their TOTP uses a nonstandard "ms-msa" protocol, forcing you to use their authentication application. https://1password.community/discussion/139501/one-time-password-for-a-microsoft-account https://1password.community/discussion/139501/one-time-passw...
- okasaki 3y agoI use FreeOTP with it just fine.
- olyjohn 3y agoI use Keepass with it just fine.
- aetherspawn 3y agoWorks fine with 1Password One Time password.
- taspeotis 3y agoI use it with 1Password?
- esafak 3y agoAre you sure you tried reading a URL with the ms-msa protocol? I'm on 1PW MacOS 8.10.20
- franga2000 3y agoThere's a "use different authenticator app" button, but it can be disabled by the domain admin and that might be the default depending on when your Azure AD domain was set up. The fact that you can set a domain to MSA/TOTP or MSA-only, but not TOTP-only, is an incredibly scummy, but incredibly predictable move by MS.
- miohtama 3y agoBill Gates would laugh in his grave
- riffic 3y ago8 months old too
- 13of40 3y agoIf you filter by status, there's nothing in that feedback channel that's had its status changed for several months, and none of the issues there are marked fixed, so there's probably some other way this sort of thing is meant to be reported. According to their help page in outlook.com: "Microsoft 365 subscriptions include premium customer support, so if you need to contact Microsoft for help, you'll get our highest level of service."
- _8j50 3y agoDamn, I depend on this. I tried to use fido2 on my flipperzero, MS blocks that as well. Kind of a bummer when you think about it with companies picking and choosing what keys/clients to allow when it should be up to the user.
- Waterluvian 3y agoSo is it definitely not a Mozilla issue but there’s no sensible issue tracker for it as a Microsoft issue? You seem understandably frustrated. :/
- bastard_op 3y agoIt's Microsoft's typical passive-aggressive way of trying to drum up users for edge being a chrome clone now, since begging you to stay didn't work when the only thing you use edge for is to download another browser. What else is new?
- solardev 3y agoUnpopular question: At what point should companies officially deprecate support for a minority browser? Firefox is down to like 6% marketshare, barely above (what's left of) Opera. Even Edge has nearly twice the usage. Is reasonable to expect a company to go out of their way to spend resources fixing something that works fine for 94% of their users, using any of several alternate browsers? And this is Microsoft after all, the same company that's been through multiple browser wars and finally caved and joined the Blink family. Why should they care about Firefox?
- deleted 3y ago[deleted]
- realusername 3y ago> Why should they care about Firefox? Maybe that's a question for them to answer since they actively block it with user agent checks If they truely did not care about Firefox, it would have worked.
- worble 3y agoAt what point are Firefox going to drop having a unique user-agent and just adopt chromes? There are so many support issues they could avoid if they just did this, I really don't see what the benefit is anymore.
- realusername 3y agoI'm not against the idea personally, the user agent doesn't have a purpose anymore and probably is the number one cause of "bugs" only affecting Firefox. It's the same issue on mobile as well, Google still serves the dumbed down search version to Firefox whereas the one they serve on Chrome fully works with a user agent change.
- mdaniel 3y agowhat's old is new again: https://webaim.org/blog/user-agent-string-history/ https://webaim.org/blog/user-agent-string-history/ so, what I'm hearing is that FF should change its current U-A from `Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:120.0) Gecko/20100101 Firefox/120.0` to just `Mozilla/5.0` and skip the pretense :-) In all seriousness, Chrome/Chromium actually had a plan to do some U-A simplification <https://www.chromium.org/updates/ua-reduction/ https://www.chromium.org/updates/ua-reduction/> but it doesn't appear they're going as far as evicting the Chrome branding from it, nor (confusingly enough) dropping the Safari misnomer (since they don't use WebKit anymore)
- zer0c00ler 3y agoLikely just 0 testing. Today I switched Outlook to the new Outlook and then it couldn't access my email account because of some licensing issue? No other error or how to resolve. Who allows things like this to be shipped without minimal QA is beyond my imagination...
- taspeotis 3y agoIt’s probably some sort of intrusion detection system saying Firefox + passkey has been seen 0.1% of the time … abort.
- Macha 3y agoHumble Bundle seems to have started doing that to me at times with a Firefox on Linux user agent. Support just gaslights me about clearing cookies and checking I typed the password correctly, even though it will work if I use Chrome or just wait a few days.
- snitch182 3y agoI have tried to use a fido2 key years ago and it did not work. I think you need some proprietary sort-of standard key.
- lousken 3y agoI have opened ticket with them for couple months about this now. I am pissed. To be honest, the fix is to switch the user agent to Chrome on Linux, but still. Even their Edge does not work, just Chromium. If possible, avoid MS login (or all their products in general)