Microsoft Resolves Entra ID Token Logging Issue Causing False Security Alerts

Microsoft has identified and addressed a technical issue that triggered widespread false security alerts in its Entra ID Protection system. The problem occurred between 4:00 AM and 9:00 AM UTC on April 20, 2025, when many users received notifications suggesting their credentials had been compromised on the dark web.
Dual Causes Identified
The company attributed these false alarms to two concurrent issues:
- An internal token logging error where Microsoft inadvertently logged short-lived user refresh tokens for a small percentage of users, contrary to standard practice
- The simultaneous rollout of the new MACE Credential Revocation security feature, which generated numerous false positives
System administrators reported the unusual nature of these alerts on social media platforms and forums, noting that even accounts with strong security measures like multi-factor authentication and unique passwords were being flagged as compromised.
Microsoft’s Response
Microsoft has taken several steps to resolve the situation:
- Corrected the token logging issue and invalidated affected tokens
- Confirmed no evidence of unauthorized access to the tokens
- Provided guidance for administrators to resolve the erroneous high-risk flags using the “Confirm User Safe” feature
- Initiated a Post Incident Review (PIR) to investigate both issues
Recommendations for Administrators
For those affected by these alerts, Microsoft recommends:
- Clearing false high-risk flags through Entra ID Protection
- Reviewing sign-in logs for lockout-related error codes
- Resetting passwords for affected accounts as a precaution
- Enabling independent dark web monitoring through third-party tools
- Opening support cases if issues persist
This incident follows Microsoft’s April 2025 Patch Tuesday update, which addressed 126 vulnerabilities, including an actively exploited zero-day vulnerability (CVE-2025-29824), though these issues are unrelated.
Microsoft continues to monitor the situation and has committed to sharing the Post Incident Review results with affected customers through official channels and open support cases.



