Tenant lockout, both Global Admins, AADSTS50196 security-info registration deadlock, case 2608190040008441 stalled 6 days

Sean Green 0 Reputation points
2026-08-24T17:25:41.45+00:00

Requesting moderator assistance getting an existing Data Protection / Tenant Recovery case internally escalated.

Situation Both Global Administrator accounts on a Microsoft-direct production tenant have been locked out since 8/19/2026. Normal users authenticate fine. Password is accepted, "Let's keep your account secure" appears, security-info registration loops, the Authenticator challenge is never reached, and it terminates with AADSTS50196 LoopDetected. Reproduced on both GA accounts across multiple devices, browsers, private sessions, and networks. No break-glass account exists.

Diagnostic detail Tenant ID: 2ab87dba-924f-44e1-b9fc-3b262f0aa3ae Request ID: 132eb8ed-a123-48c4-8345-f423fe156300 Correlation ID: b27d25ce-601b-4324-bb66-23e65b3a347f Timestamp: 2026-08-24T16:34:47.044Z

The proof-up request from My Sign-Ins (client 0000000c-0000-0000-c000-000000000000) is issued with amr_values=ngcmfa and an essential acrs claim of urn:user:registersecurityinfo. Fresh MFA is required as a precondition for registering an MFA method, which the account cannot satisfy. This is a registration deadlock, not a client retry loop, so the standard AADSTS50196 token-caching guidance does not apply.

Case history 2608120010002185 - closed. Microsoft Support performed authentication/MFA configuration work under this case. The lockout began immediately afterward. 2608190040008441 - primary recovery case, open since 8/19, repeatedly said to be escalated to Data Protection / Tenant Recovery. No engagement received despite multiple promised callbacks. 2608210010000477 and 2608210010001259 - duplicates. 2608240040004238 - M365 case opened 8/24 from a separate tenant. Plus a Severity A Azure case opened 8/24 under a Standard support plan.

What I'm asking for

  1. Have 2608190040008441 reviewed, severity raised on business impact, and the duplicates merged into it.
  2. Have an engineer pull the change log from 2608120010002185 and check the tenant's Authentication methods policy and any Conditional Access policy targeting the Register security information user action.
  3. Issue a Temporary Access Pass to the affected GA. A TAP satisfies the MFA precondition and permits registration of new methods, resolving this without a full tenant recovery process.

I can complete DNS TXT domain verification, billing verification, and identity verification immediately. Happy to send tenant and account details by email rather than posting them.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.