
Organizations worldwide are experiencing a wave of account lockouts due to false positives generated by Microsoft’s newly deployed “MACE Credential Revocation” application. The issue began affecting Windows administrators last night, causing significant disruption across multiple enterprises.
## What Happened
Administrators reported receiving numerous alerts from Microsoft Entra ID (formerly Azure Active Directory) claiming user credentials had been leaked on the dark web. These alerts automatically locked affected accounts out of their tenants, with some organizations seeing up to one-third of their user accounts impacted.
“Us as well… about 1/3rd of our accounts got locked out about ~1 hour ago. We’re a MSP so I’m assuming this is happening to our clients as well,” one administrator posted on Reddit.
## False Positive Indicators
Several factors suggest these were false positives:
– Affected accounts showed no signs of compromise or suspicious sign-in activity
– Many locked accounts were protected with Multi-Factor Authentication (MFA)
– Breach notification services like Have I Been Pwned showed no matches for these accounts
– Passwords were reportedly unique and not used on other sites or applications
## Microsoft’s Response
While Microsoft has not made a public statement, they reportedly confirmed to one affected organization that the issue stemmed from the rollout of the new “MACE Credential Revocation” Enterprise application. This feature is designed to detect leaked credentials and automatically lock potentially compromised accounts.
“Just got off with engineer. It is Tenant Lockout due to this MACE ninja rollout they did. No signs of compromise,” confirmed an administrator.
Multiple administrators verified that the application appeared in their tenants immediately before the alerts began.
Organizations experiencing a sudden influx of leaked credential alerts should investigate but recognize this may be related to the problematic MACE rollout rather than actual security breaches.
