17 ms·
My daughter's school took over my personal Microsoft account
- cristiioan 4y agoWith the mess that is Microsoft accounts system, I'm not surprised to hear this.
- earlyam 4y agoMy wife basically had all the problems you guys are talking about with her Minecraft account. When Mojang was independent none of this stuff was an issue but with MS you're practically pulling your hair out to do really basic stuff. 100% pure regression with account management.
- BizarroLand 4y agoI've had coworkers locked out of their personal Google Accounts all because they or their child logged into a school google account on their work laptops while also being logged in on their personal google account on their work laptops. It's a pain in the tail to resolve, but it can at least be resolved without calling the school.
- jessekv 4y agoSomething similar happened to my personal Atlassian account.
- bachmeier 4y agoI gave Atlassian my school email address as verification that I worked at a university to get a free Bitbucket account. Ten years later, they not only locked me out of the Bitbucket account and gave access to someone at the university, and then refused to tell me what they'd done, they also gave my Trello account to them. The thing about the Trello account is that I used a non-school email account for that. I never at any point gave them information about my school account. I opened the account on the day Trello was announced, when they didn't even have paid plans. I'm guessing they were able to link me somehow, and they used that information to give my account away. Clearly Atlassian is not a company that should ever be trusted with important data. In my case, if I had any information about grades in my account, it would have been a violation of FERPA. You can't casually hand out that information to random strangers.
- thriftwy 4y agoI can already see a bunch of managers aggressively giving orders to implement account organizations while deflecting all questions from the ones implementing it.
- sundvor 4y agoMicrosoft's organisation vs use of accounts is certainly a hot mess.. I'll be watching responses here and hopefully find out why my personal account sometimes says certain settings are managed by "my organisation". What freaking organisation is always my response; I've never been able to figure it out.
- nvrspyx 4y agoI've changed things in Group Policy (e.g., disable Bing/web search in Windows search) because there's no user-facing setting to disable some things and mine says the same. If you've done similar or used any debloat/privacy tools/scripts, that's probably the cause. Additionally, go to Accounts in Settings and double-check that you're not logged into any "work or school" accounts. The one thing I can't stand is that if you log into a non-personal Microsoft account in an app, there's a dialog that is very confusing[1]. It asks if you want to use that account everywhere on your device, but there's a box checked by default to let the organization manage your device, a button that says "Yes", and what looks like a hyperlink that says "This app only". I always uncheck the box before clicking "This app only", but I wonder if keeping that box checked would still enable organizational device administration. It screams "dark pattern" to me. 1: https://i.stack.imgur.com/gmp00.png https://i.stack.imgur.com/gmp00.png --- Just to add a tip for others: If you want to use Edge for the Windows optimizations and PlayReady support for streaming services, but don't want to deal with all the annoyances, you can disable many of them via Group Policy[2]. For example, you can disable the "Search Bing in sidebar" option that shows up in context menus[3] that I always seem to accidentally click when I'm trying to search for something I highlighted. I also use Group Policy to set the default search and homescreen settings because then it won't annoy you with the recommendation to set it to Microsoft defaults every time it updates. Firefox is my main browser, but I use Edge for streaming Netflix and the like because I don't get 4K playback via Widevine. It annoys me because Edge would actually be a great browser if the Bing folks weren't constantly trying to shove things down my throat and filling it with dark patterns. 2: https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies https://learn.microsoft.com/en-us/deployedge/microsoft-edge-... 3: https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies#searchinsidebarenabled https://learn.microsoft.com/en-us/deployedge/microsoft-edge-...
- cornholio 4y agoLarge corporations with a captive market inevitably reach the digital bureaucracy stage, where the exaggerated mass of their workforce breaks under its own weight, and they become inept at doing basic things. This is a great thing for small startups, else we would only have a single huge corporate conglomerate doing everything with cutthroat efficiency.
- larsrc 4y agoIt's not just the company bureaucracy, it's also laws and regulations. It's great to be a startup in the US where you have a large and fairly rich customer base. But when you go international and have to deal with all the myriad laws there, often contradictory or poorly defined, your code will be messy. Very messy. Plus these laws keep changing and your customers keep moving to different jurisdictions or giving you wrong information. Add to that various attempts at fixing problems, adding features, partially removing unsuccessful features, supporting old systems, framework/library migrations in various states of completeness, different developer's ideas of how to do things, and that rockstar developer who wrote really obscure code and then left to grow pomelos, and you have an incredible mess without even having to bring in company bureaucracy.
- LeonB 4y agoThe way Microsoft accounts work is almost completely opaque to users. I’ve been in similar scenarios — the switch directory or switch organisation technique usually worked for me - but wasn’t enough for this person. They never really give you enough information to tell what’s going on… maybe it’s a security risk to have consumers who are anything other than bewildered Kafkerian characters struggling against a faceless bureaucracy? I suppose we should not question their wisdom and be thankful that we can log in at all. Atlassian manage to make it even more confusing than Microsoft. So there’s that.
- LeonB 4y agoNow, if Microsoft bought Atlassian — that would be absolute theoretical maximum limit of peak confusion when logging into an app. “Warning: You are about to login to Microsoft Atlassian Fogbugz Trello. Have you cleared sufficient space in your calendar, notified your next of kin, put your affairs in order, and taken your sedatives?”
- makeitdouble 4y agoThe fun part being it always looks fine and smooth for the first 30 minutes. It's once your sessions start expiring or you're trying to use the other services in meaningful ways that the journey begins.
- Brian_K_White 4y agoLike you would get anything as considerate as a warning.
- eastbound 4y agoAtlassian ID was a negative point when choosing software. We, as an Atlassian plugin maker, chose GitLab internally, and Notion, both because at least it was properly integrated and didn’t have the awful Atlassian ID and switch between apps…
- aprilnya 4y agoI’m gonna have nightmares about this
- jackjeff 4y agoMy rule of thumb is to NEVER use a Microsoft account for anything unless I’m forced to. And then I’ll create a brand new account for each use case. I so regret converting my Minecraft account. The old Mojang stuff was so much more reliable.
- oefnak 4y agoYou didn't have a choice, right?
- Liquix 4y agoCorrect. If you didn't mind having a Mojang account (small, indie, Swedish company; respectable privacy policy) but would prefer not to create a Microsoft account, your money is as good as gone and there is no way to play the game officially.
- asddubs 4y agoif you just want to play offline, the prism launcher still lets you authenticate using the old mojang accounts. (which is not to contradict your claim, as it's not an official launcher). I held out for a really long time, but a friend wanted to play minecraft with me so I finally caved. If they ask me to add a phone number I'll probably just abandon the account though, and look into piracy of the game I purchased.
- skowalak 4y agoAfter converting, my brand new MS account got locked for 'suspicious activity' within minutes. To get back access to the game I had paid money for, I had to... you guessed it: add my phone number. Really makes me consider just not playing anymore.
- xigoi 4y agoTry Minetest instead. I particularly like the Mesecraft game for it.
- lultimouomo 4y agoIs this a surprise? I assumed everyone's experience of Microsoft accounts was something like this. Every single detail seems designed by someone who read Kafka and took the wrong lesson out of it.
- LeoPanthera 4y agoI really hate comments like this. What exactly do you expect to achieve by saying "Well of COURSE this thing is awful. You should have known that." Just accepting every horrible thing in the world must be so sad.
- lultimouomo 4y agoYou don't need to accept it. Just don't use Microsoft. (If your school forces you to, create a throwaway account for that, and let the principal know that you are not a happy customer)
- b800h 4y agoAnd then your child has a Mojang account, and then you can't use Minecraft because the throwaway account is associated with your phone number, and it's tied into the Active Directory of ..... This sort of scenario. Or a million others.
- lultimouomo 4y agoHaving an account for your child schools is kind of a necessity. Using Minecraft is not. It seems to be a nice game and children like it; it sucks that Microsoft bought it. Still not a good enough reason to use Microsoft.
- b800h 4y agoThat's why my kids now play MineTest. Despite having bought them Java Minecraft before that was an issue. Shame the money was wasted. Product changed. Ought to be able to get our money back.
- greggsy 4y agoDespite the implication of malice that other comments seem to be directing at Microsoft, this just seems like a bit of an oversight (i.e. inexperience) on behalf of the school’s IT team. Nonetheless, I would have expected MS to ensure that the process includes clearer guidance for the account owner, and for deliberate decisions to be made by the school to enable this type of action. They did a very good job of providing clear advice to BYOD users during the MDM onboarding process in InTune, and it’s confusing that this didn’t occur in this case.
- tgv 4y ago> this just seems like a bit of an oversight (i.e. inexperience) on behalf of the school’s IT team. The school's IT team should never have had the means to do that.
- tacker2000 4y agoYea why would some random schools IT be able to add some random account to their org?? Thats a rights/policy issue that needs to be addressed.
- josephg 4y ago> this just seems like a bit of an oversight (i.e. inexperience) on behalf of the school’s IT team. No matter how inexperienced they are, it shouldn’t be possible to put an external Microsoft account into this weird state without the account holder’s permission. And the “leave organisation” button shouldn’t leave the account in some weird unrecoverable state. This all reeks of sloppy product design on Microsoft’s part. Is my Microsoft account one bad domain administrator away from being taken from me? That’s unacceptable.
- deleted 4y ago[deleted]
- paranoidrobot 4y agoI agree that its not malice, but its not 'a bit of an oversight'. It's a long time pattern of behavior from Microsoft about their utter lack of any care or thought for how to manage their MS Accounts system.
- RedShift1 4y agoSome company that offered services to us used Azure AD for their authentication into their portal, so when you registered with them it actually created an Azure AD tenant. The user was not aware of this, but this started to become a real headache not only because users could apparently create Azure AD tenants out of nowhere, in some weird way I still don't understand, but certainly through user interaction, other users that had nothing to do with that portal also got added into this Azure AD! It took some shady workarounds to get control over this rogue Azure AD tenant and clean up the mess it caused. At this point we keep the Azure AD around not because we want to use it, but to stop anyone else from creating one with one of our domain names.
- helsinkiandrew 4y agoI'm realizing more and more that relying on a large organization for a service where you are 1 of hundreds of millions of customers is a bad idea. First customer service will be automated or even non existant, and very poor. Secondly the product will have been 'tweaked' so many times for new markets and product extensions that it will be very fragile when you do something at the edges of its functionality (not what the other hundreds of millions are doing). It shouldn't really be this way - it tells a lot about software engineering that a product run by a few enthused people alone can often (but by no means must) have better support and service than a product with huge resources.
- zamnos 4y agoA father with a daughter that goes to a school, and the father has a Microsoft account, is nowhere near an "edge of functionality". Sounds more like Microsoft has a too-complex login system on their hands, one that needs a ton of backend rework to happen in order to simplify the system for the user (and the developer)'s sanity. Also, a software engineering product run by a large organization is going to have tons more functionality under its much bigger umbrella compared to a small team with a much smaller product. Consider AWS vs Digital Ocean. Both great companies, but AWS's umbrella of offerings is vast compare to Digital Ocean.
- helsinkiandrew 4y ago> is nowhere near an "edge of functionality" No, but something unusual went wrong and getting it fixed will be harder at MS than a smaller company. There probably isn't a single person who understands why without a fair amount of research. Without the publicity, MS would be inclined not to spend the effort to fix. > Also, a software engineering product run by a large organization is going to have tons more functionality This was exactly my point - the large product with tons more functionality will likely be more brittle, harder to use, and get support for if something breaks. If you aren't using that functionality, you often won't be well served by the company. I had this experience with EverNote. I'm also a very happy AWS customer, but I think that is because their products are a set of (fairly) independent products, rather than one huge system.
- makeitdouble 4y ago> It was created when I transitioned my Xbox LIVE account to a Microsoft account on 2014-03-07 (the LIVE account was created back in 2006, and neither it nor my Microsoft account were ever joined to any other domains). Hoping this raised issue helps cleaning up some of the mess, I find it fascinating how bizantine microsoft have become. I also have a skype account that became some other other account, but was using the same email as my mojang account that got ported to live accounts. I kinda hope everything is neatly bound in the backend as I login through the live.com portal, but it feels like a miracle that it still works at all. It was the same kind of fun trying to log to flickr with a old converted yahoo account. Or dealing with amazon after merging multi-coutry accounts.
- omnibrain 4y ago> Or dealing with amazon Amazon used to allow having multiple accounts with the same email, but different passwords. And don’t ask what happens to personal accounts that get accidentally invited to corporate accounts via email adresses formerly used for the personal account.
- makeitdouble 4y agoI think it's still complicated. I wouldn't try to play too much with it, but you can use the "same" account across each of their national portals except parts of it seem to be local to the country, and many amazon apps don't have a notion of country (e.g. when logging to the prime app you only use the email and password, and it guesses from there. It actually finds the right item from an app downloaded from a different country's app store). I made a point to separate mail addresses by country to avoid getting hosed, but I'd imagine the fun trying to access Prime or kindle purchases from an account that has them in multiple national stores.
- Macha 4y agoYeah, at some stage I had accounts on Amazon.de, Amazon.co.uk and Amazon.com with the same email. My .de and .co.uk accounts eventually got merged (no notification, just found one day I needed to start using my .co.uk password to log into .de), but my .com one is still semi-seperate and I need to go to amazon.com to manage my kindle ebooks still.
- capybara_2020 4y agoThis really goes to show what depending on online authentication from a large corp can do. Even worse, Microsoft is now trying to force online accounts onto Windows machines. Google already does it with Android. Which means for some reason if you lose access to your email, you are locked out of not only your online accounts but your local devices also. We really need to separate authentication from services and devices. With strong safe guards around that account and an actually support system.
- amatecha 4y agoYeah, that shit is why I took a brand-new NVIDIA Shield back to the store immediately after getting it home - it literally cannot be used without signing into a Google account. I bought it thinking, "hey nice, I can use this 4K Android home theatre device without Google being involved, since it's from NVIDIA and thus hopefully free of all that crap". I even did my homework on this: no material included with the product, nor NVIDIA's online product page, indicated that an Android account is strictly required to actually use the product. I ended up doing some more searching after returning the product, and finally found a singular customer support page that happens to mention it. Gotta love it...
- visarga 4y ago> and finally found a singular customer support page that happens to mention it That's the kind of results Google should be surfacing, but it lost the game, it is so useless now for precision searching.
- ta1243 4y agoGoogle should be surfacing things which paint google in a bad light?
- rmellow 4y agoIt does. "Google search sucks" returns what you'd expect. What GP is getting at is that Google Search breaks down often when you're looking for a very specific result, but one that is uncommon enough. Instead, you're often diverted to a "related" query result without them telling you.
- gchadwick 4y agoAuth with MS accounts is a giant mess. When I was a city councillor I had a corporate O365 account from the council (used for council email and virtual meetings over teams) and simply trying to sign out of the thing or switch to another account was always fraught (I've got a personal account that's basically just to associate my windows license with and a work account used for azure access). You'd often end up in a state where teams would just refuse to sign in and you'd need to reinstall it to get it to work again. Trying to be actively signed out is also a mess. You can use the teams app to join teams meetings others have setup and invited you too without teams access yourself. Though of course if you have an MS account teams can see it ends up trying to use it and then saying you don't get teams access via that account and trying to sign out and join the meeting with an account associated with it often just doesn't work. A colleague actually ended up requesting he got an o365 account with teams associated with his corp email because of this issue as he had occasional meetings with external people over teams. We have a corp o365 setup for our ops/admin team that engineering normally doesn't touch but because he had a teams invite sent to his corp email he got dragged into it.
- theK 4y agoYeah, the identity side of MS products is really dysfunctional. Every time I try to use teams or azure it ends up in hours of finding out the right procedure to log in or switch an account effectively. And then you get the people asking naively "why are you getting so mad at them"...
- ly3xqhl8g9 4y agoSolution: run Windows in a VM, one machine per account, nuke it from orbit when-not-if something goes awry. Hundreds of hours of frustration prevented from a system that is not even able to have the same UI across all its windows.
- ccouzens 4y agoOr run apps like Teams in a web browser. Web browsers have good isolation techniques like Chrome's profiles and Firefox's containers. Teams is written using web technologies so you're getting the same experience as the app.
- senectus1 4y agoyeah. if you have multiple account with Ms that use the same email address to sign in with, you're going to be in for a bad time.
- cfn 4y agoI had similar problems with Microsoft's accounts starting with MSDN many years ago. What I do now is creating a new email account when I need to access Azure on behalf of a client.
- fcatalan 4y agoMy kids' school and high school use Teams for some stuff. I have to use it occasionally for work too. The thing is that's nigh impossible to simply log out as one user and back in as another, so we have to take a lot of care of who used this or that device last. And don't get me started on the nightmare that is dealing with Minecraft accounts older than the Mojang acquisition. It's not only Microsoft. Trying to subscribe to third party stuff like Just Dance on the Switch is a kafkian experience that I couldn't solve. My daughter is angry with me for giving up.
- smallstepforman 4y agoMy son gave me a hard time for Valorant secure boot requirement on Windows 11 (but not 10). As a triple boot user (Haiku and Linux), secure boot is a no go on my box, since I reboot frequently.
- watermelon0 4y agoI assume most anti-cheat systems will sooner or later require Secure Boot and TPM, which makes a lot of sense. Additionally, it's more secure to have them enabled, and similar solutions have been used on iOS/Android/macOS for a long time now. Many Linux distributions have signed bootloader and kernel, to support secure boot, but otherwise I think you could either add your own signing keys for the Secure Boot, or chain either Linux or Haiku from a signed grub bootloader.
- Kwpolska 4y agoTo solve the Teams stuff, couldn’t you just use separate OS accounts?
- pjmlp 4y agoYep, Microsoft likes to merge accounts, up to five if I am not mistaken. So usually pressing the wrong option while logging with a new one and existing cookies from another one can land on this mess. Usually the only way out of the mess is somehow via Microsoft support, which I only saw being successful via MSDN sales contacts.
- userbinator 4y agoI'm assuming "deletion of your data" only includes any information that might be associated with the school... hopefully not the rest of my Microsoft account! Whenever I see such a serious warning, I will almost always take a long period of consideration before proceeding. Remember that you're dealing with a company which acts like they believe you shouldn't own your computer. If a company with that attitude believes they should warn you about something, it's certainly serious.
- remram 4y agoIf they offer no information, you can think as long as you want, you still have to make a random guess.
- donmcronald 4y agoIt's infuriating too because they're foisting the burden of queuing / testing a backup onto the user and across the entire user base it's probably a massive amount of wasted time. Also, Microsoft's UIs are filled with misused terminology. They use create, open, add, (delete, close, remove) etc. interchangeably. For example, in the OWA the process for removing a calendar you don't own is called delete.
- zwilliamson 4y agoLet’s see if Bing Search AI can fix this for Jeff?
- tragomaskhalos 4y agoSince most of the relevant training data is likely to be punters kvetching about Microsoft, it'd be amusing to see if this would propel it into an angry rant about its boss.
- thih9 4y agoI may have jinxed it; the other day i was thinking how impressive it is that Microsoft handles their decades old AD/azure/live/xbox/etc auth systems and that they all work together well. In this case, is there another company with a similarly old and complex auth system that does exemplary work?
- deleted 4y ago[deleted]
- tacker2000 4y agoShout out to geerlingguy, the creator of many helpful ansible packages!
- anoncow 4y agoIt’s good to see a mac.com email ID.
- harryf 4y agoAm I missing something or where is the part where he contacted the school or spoke to his daughter about it, _before_ writing blog posts and getting on Twitter? It's strange to me to take the discussion like this to public forums before talking to the people involved. It could be his daughter "gave" it to the school as an act of generosity for example.
- croes 4y ago>It could be his daughter "gave" it to the school as an act of generosity for example. That shouldn't possible in the first place.
- xxs 4y agoIt happened during the weekend, so there is none of the school administrators to help with - but that's not the worst. Such behavior should not be possible and his daughter should not be able to grant such permissions either. The school =should= know it's not a kid's account to begin with. None of the blame should be attributed to the school but Microsoft - there is no feasible way for the person to reclaim his account. In short - you are missing a lot.
- coffeefirst 4y agoThe solution is definitely to find someone in the school IT who can help unravel this mess. But the fact that it's even possible to reach a failure state like this is still worth public discussion. You're probably right, odds are his daughter hit "okay" on some screen... but it shouldn't even be possible to irrevocably hand over the keys to a private account.
- irusensei 4y agoI think something similar happened to my google cloud account. I’ve used to run some websites and CIs for some small clients then I got a jig for a bigger client and they included my account into their organization. It wasn’t as crippling tho and also easily reversible.
- WWLink 4y agoThat is absolutely insane and one of many reasons I hate microsoft with a passion. WTF kinda power trip are they on when they let domain admins just pwn accounts like that? How did OP end up in this situation? Was his email just on a distribution list and usurped that way? I don't get it. And I find it kinda freaky.
- amir734jj 4y agoPlease contact school system IT department. Your data is not lost. It's just under a different tenant.
- submeta 4y agoOver the years, an overwhelming number of services have been consolidated together. Whenever I require access to Office365 or Outlook, I find myself being redirected to numerous domains including msn, microsoft, live.com, and others that I cannot recall. The entire situation is chaotic and disorganized. And then, god forbid you have a problem.
- sumedh 4y ago> numerous domains including msn, microsoft, live.com, and others that I cannot recall. Dont forget the og domain, hotmail.com
- ciabattabread 4y agoAnd their newer, suspicious-looking domains: 1drv.ms (OneDrive file sharing) microsoftonline.com (something to do with Azure) b2clogin.com (replacement for microsoftonline.com)
- hoosieree 4y agolive.com outlook.com Windows Store xbox Skype Families Office 365
- kl343 4y agoFirmly agree with other posters that Microsoft's identity services leave a lot to be desired... but Jeff is being a bit sensationalist here. The school did not "take over" his MS account. At some point (likely amidst a mountain of other onboarding tasks for his daughter's enrollment) he would have received an invitation to join the school's Azure AD tenant as a guest/external user. In this case, he chose to join using his Microsoft account, rather than create a new email-based guest account. "Leaving" the school's org only breaks one side of the federation, and the guest account and it's association to the school's Azure tenant still remains. To resolve, he'll need contact the school and have them delete the account. Meanwhile, it probably would have been better to create the app beneath an Azure AD tenant belonging to the non-profit org in the first place.
- croes 4y ago>he would have received an invitation to join the school's Azure AD. Speculation. And even if he received such a mail, were the consequences made obvious to the user?
- alanfranz 4y ago> he would have received an invitation to join the school's Azure AD tenant as a guest/external user. He explicitly claims he didn’t, by the way.
- geerlingguy 4y agoI assure you I didn't (to the OP). And some people speculate my daughter may have logged into an account on my computer—there is no possible way, and at home she only uses one of two other devices (and at her school they don't have students log in off premises anyways), and my two computers are locked at all times when I'm not around. In addition, assuming she were able to get access to one of my computers, the password manager is behind face/Touch ID and locks automatically after each use. I spent a couple hours digging through all the emails we got from her school too, for the month preceding her entry into the school, and I saw nothing about any online logins, not even a link to any kind of portals or anything like that... just consent forms, welcome messages, and the like. I've been racking my brain for a logical explanation as to why my personal email (and the password associated with my personal Microsoft account—which has been used to login to Azure in 2020, years before this mess) has been associated with the school's tenant. I can't find any.
- hulitu 4y agoSame here. Then Microsoft Family Safety (sic) denied access to firefox and other programs.
- neodon 4y agoAm I the only one who uses browser profiles to separate my personal browsing from work or other organizations I'm a part of? When I mention this approach to people they give me a strange look like I'm crazy. In Chrome you just create a new profile for each identity you have. If you're opening random incognito windows or using different browsers all the time to log in with different identities, you should be creating profiles instead. Everything is separate including bookmarks, sessions, cookies, extensions, etc.
- smallstepforman 4y agoI take the next step, Vivaldi for personal and Chrome for work profiles. Firefox for non important profiles.
- petepete 4y agoFor Firefox users, Multi Account Containers are definitely the way to go. https://addons.mozilla.org/en-GB/firefox/addon/multi-account-containers/ https://addons.mozilla.org/en-GB/firefox/addon/multi-account...
- disgruntledphd2 4y agoI use separate browsers for work and personal. On a work machine, my personal stuff will be in Firefox and my work stuff in Chrome/Safari/whatever. It's just easier for me to manage that way. That being said, my work google account is connected to my personal phone which is probably gonna mess me up at some point.
- Kwpolska 4y agoI go even further, corporate laptop for work, personal laptop for personal stuff.
- quickthrower2 4y agoEssential if you are an employee. Same machine may be ok as a freelancer.
- Dalewyn 4y ago
- roxgib 4y agoI dodged a somewhat similar experience with Zoom. Took a contract with a company, and they tried to adopt my personal zoom account into their organisation (I was a contractor, so I was using my own email address while working for them). Fortunately I realised this might be annoying down the road and sent them an alias to use instead, but I imagine other people could get into strife - not that a Zoom account is a big deal and they seem to have better processes in place so it's possible it's easy to resolve, but it could easily cause a headache for a less tech savvy user. In general, be careful what you click agree to (I know, I know)
- b800h 4y agoMy suspicion is that what's happened here is that Jeff's daughter has used his laptop for something from school and clicked straight through an overly-inviting message that asked to join the account to the school's domain. I'm skeptical of the suggestion that the school admins were able to do this with no input, but I'm absolutely willing to entertain the idea that: a) AD login is a complete mess, and b) the UI is utterly misleading and near-unusable.
- geoelectric 4y agoHorrible UI if you can do a fundamental account change without some kind of password re-confirmation.
- basch 4y agosaved in the browser
- geoelectric 4y agoYeah, I realize it was just a continued session, but that's exactly what I mean. For things like password changes or privilege changes, there should always be a mandatory re-auth to make sure it's not someone else at keys. This is pretty much just best practice. When's the last time you could change your password without entering the original, short of a re-verification via email? Same idea here.
- basch 4y ago>a mandatory re-auth which, if the persons password is saved in their browser, would pass through to the website, granting a re-auth.
- geoelectric 4y agoOh, I misunderstood what you meant as the session token still being active. I got you now. I've been using 3rd party password managers (with a timeout for a forced reauth) long enough that I forgot when you let the browser do it it's not nearly so locked down.
- bugbuddy 4y agoThis has the feel of a Kafkaesque nightmare with a large serving of incompetence. There are some serious screw-ups going on here. Do they have QAs? What kind of tests do they actually do?
- CatWChainsaw 4y agoStarting with Windows 10 they just made their home users the beta testers/QA.
- mitch_f 4y agoI had a very similar experience with my former employer and the proof of concept tenant they setup for Office 365. My personal account was tied to that tenant, and whenever I tried to register an app - it was access denied. They even give you an option in the app registration interface in Azure: whether you want it to be in the company tenant or linked to your personal account. Regardless of what I tried, access denied. After a few weeks of this, I attempted to “Leave” the proof of concept tenant. Yes, I clicked the scary leave button that tells you your data will be deleted. Access denied. One of the options Microsoft suggests is to get in contact with the global admins to help out. Considering that tenant was abandoned 8 years ago, it was going to be difficult to get in contact with the global admins. I even contacted my former employer and requested they remove me. Their response? “We abandoned that tenant years ago, no one can access it”. I created a support case with Microsoft for their Azure AD service requesting they remove my account from the tenant. After some back and forth, repeating myself a few times, trying to explain what I save wanted to do in multiple different ways, and a screen share, I still wasn’t able to leave the organization. The case was escalated, and eventually I got on a call with the support rep and a manager. We went through the “leave the organization” process together, and miraculously, it allowed me to leave. This was several months ago, by the way, and no data loss with my personal account that I can tell (so far), although I can’t guarantee when you click that scary button, your data will be safe. I’m not sure what technical witchcraft took place for this to happen, because it was the exact same set of steps I had tried 25 times before. My only point in this story is to say it would probably be worth a shot creating a support case with their Azure team, and being a squeaky wheel, in the behemoth cog that is Microsoft, that gets the grease.
- richdougherty 4y agoA few years ago I got an email saying that an unknown Microsoft account had been renamed from one of my email addresses to a new email address I don't own. It appears that someone was able to link an MS account to my email with no verification, then rename the account, again with no verification. Best case is that it's someone who used my email as a recovery email for their MS account and changed it. But with the mess of MS accounts, I'm always nervous they've got some residual control of my real account which is also linked to that email. Unfortunately I've never been able to get confirmation from MS that things are OK. There are plenty of questions about this particular renaming issue on the web, but no answers.
- jb1991 4y agoThat last update is like the old Blue Screen of Death, cloud-style. Take comfort that some things never change!
- atemerev 4y agoWell, I found that I am mostly using my Linux desktop specifically because it doesn’t require me to obligatory sign in into the services I don’t want to use. Unlike Apple, Microsoft and Google. And also this is why I don’t use Ubuntu anymore.
- geerlingguy 4y agoApple, fortunately, doesn't require any account signins to use anything that comes out of the box on a Mac, iPad, or iPhone. I know this because I have one of each running in my home with no associated cloud accounts whatsoever. They do nag you a bit (not aggressively like Microsoft, who is like "are you sure you want a terrible experience using this computer?"), but it is entirely possible to be productive outside of the iOS ecosystem, which does require an account to load apps.
- kccqzy 4y agoA large number of software engineers, even those at rival companies, actually use Macs for their work. If Apple forces those users to set up an online account for basic functionality, I'm sure Apple would lose so much business, because those companies aren't going to want to deal with iCloud.
- dcow 4y agoI can’t give Azure money if I tried. And I have repeatedly. About 10 years ago I created an Azure account with my normal email and my US address. I did some stuff but never had a reason to use Azure in a situation where I’d pay for resources. Some years later I wanted to check out Azure for a small project. I go to log in and it tells me I need to add billing or something. I enter my credit card info and get to the address section. My zip code won’t validate. That’s odd. It’s saying it wants numbers and letters. Wait why does it think I’m in Canada? I’m in California. CA? Hmm. Anyway should be easy let me fix the Country. Oh it’s greyed out. YOU CAN’T CHANGE THE COUNTRY?! Surely this must be a bug. File a support request. Nope can’t change country. Escalate and explain that I can’t add a credit card because I am not a CA resident and don’t have a Canadian payment method. They tell me they can’t change for tax reasons. But they never took my money because I can’t pay them… I go on to tell them I never even selected Canada there must be some UI bug when they first rolled out the new account format. They said theres a known issue where this can happen. I ask them to fix. They can’t because taxes. They tell me I have to create a new email if I want to use Azure. I wont do that because I have virtue. I try two more times over the course of 6 or so years. Both times I’m escalated to someone who thinks they can fix the problem for me. I think at one point there was a technical work order put in to delete my Azure account so I could try again. But somehow it always gets thwarted. So what happened? I’ve been able to piece together that Azure transitioned to a new account model between when I first created my account and when I tried again the first time. The old model was independent of your MS account. The new one not so much. Somehow Azure migrated my legacy account with a US address and morphed it into an account with a Canadian country set. This Canadian account is intimately linked to my normal MS live account which has a US address and payment info nonetheless. An early version of the Azure account migration UI locked in your country before verifying your payment/address. For “tax reasons” you cant change but it’s totally fine that my US live account has a Canadian Azure account and that, if I was able to do things as MS wants, I’d be paying for MS apps and services with a US card and Azure resources with a Canadian one. Because that’s better for taxes?! So to this day I can’t use Azure because I’m not willing to change my live account login email address, my main email address, to something else just to work around MS’s bullshit. Because yes, now it’s all the same and your azure account is your live account. That’s a known issue and we have a simple workaround: just kindly make a new email address…
- jawadch93 4y ago[dead]
- wouldbecouldbe 4y agoOne of the magical things microsoft has accomplished is that governments and corporates trust them so much. Some kind of Stockholm syndrom. Here in the Netherlands they somehow have convinced local governments (like cities & provinces) that working with them is still GDPR compliant, even thought they should only work with EU based companies to store data. But other companies like DigitalOcean, AWS and Google cloud (especially Google is evil) are not GDPR compliant As a dev learning web development when IE was still a thing I still have horrible experiences with them
- deleted 4y ago[deleted]
- hyuibg 4y agoI had an interesting situation a while back where my then corporate login appeared amongst my personal Microsoft accounts as possible options to log into upon installing Microsoft office iOS apps on a personal device - given that org’s corporate policies don’t allow logging in that way I could fathom how it was appearing (it might have been linked to once trying to use Authenticator for 2FA) but it was a bit odd seeing it as a prompt on downloading a fresh iOS Excel. It seems to have stopped now but was a bit odd!
- andyjohnson0 4y agoMy work laptop has a weird combination of a personal microsoft account that (I think) is linked to the windows licence, and a corporate account that is linked to O365, sharepoint, etc. Office works, as does OneDrive [1], but I've never been able to access SharePoint (probably not a bad thing). Azure just doesn't work for me, and even Microsoft support couldnt figure out why. I'm usually pretty positive about Msft but their identity stuff is a mess. [1] except that I have two OneDrives that appear to form a Venn diagram with a partial intersection that i can never quite figure out....
- thrdbndndn 4y agoYou can have multiple OneDrive accounts on the same computer, I personally never have issues with it (I have three).
- ashgoyal 4y agoThis is a giant mess. Frankly, i don't understand how they architected it. If i open a word, excel or ppt document from another companies SharePoint because they added me as a guest, Microsoft promptly signs me out of the desktop office 365 apps and then says that i am using unlicensed office365. How was this missed when designing the security and authentication systems?? This is basic foundational stuff!
- hyperman1 4y agoThat's easy to answer: It is not architected, it is organically grown. Product A adds a sign in. Product B from another team adds another sign in. Product C,D,E do the same. Each team has some special magic sauce that makes their system work better with their product, but worse with all others. Now the corporate infighting starts, as management squeezes all these sign-in systems together, and everyone looses if any other but their system wins. So some compromise is created, based more on political prowess than technical requirements. The result is an API from hell, taking fragments from everyone, even if they conflict. Everyone pushes and pulls their existing systems until it fits in the compromise, trying to minimizing damage. Weird cracks appear everywhere. we've all seen the organizational charts meme: https://www.euroresidentes.com/tecnologia/noticias-internet/wp-content/uploads/sites/5/2015/05/Organizational-Chart-for-Apple-Amazon-Facebook-Google-Microsoft-and-Oracle1.jpg https://www.euroresidentes.com/tecnologia/noticias-internet/... Remember how each organization builds a solution based on their organogram. Look at microsoft in the meme. Look at the sign in mess. Understand. I predict strange, probably exploitable and surely unsolvable problems in the MS sign-in system for at least the next decade, just like their programming practices of the '90s had entirely predictable security consequences for a decade when the internet appeared.
- hn_version_0023 4y agoThis is exactly spot-on. 20+ years of this and you have a mess of gigantic proportions.
- deleted 4y ago[deleted]
- vermooten 4y agoWhenever my MS account did stupid stiff like this, I'd just create a new one. I ended up with 4 before moving my life outside of the MS ecosystem.
- ckdot 4y agoI experienced similar with logging in into outlook.com and the teams app on Mac. Accounts from different companies were mixed up. If I tried to login with my account from company A I got redirected to the login page of company B. It’s a real mess.
- Meph504 4y agoI can say for sure your issue, but I have seen very similar before, and what has likely happened is that your personal email was added as an alternate email in their tenant, sometimes this is for account recovery or MFA. If you have your daughter login to her school account, and remove your email from her account. Your account will revert to a normal microsoft account. You will however have very limited access to azure with a personal account, and doing things like registering an app is going to be unlikely unless you have your own tenant, or added to some other tenant.
- lynguist 4y agoI really, really hope that this traction on Hacker News will make Microsoft fix this for good. Anything that gains such traction gets fixed eventually, but I want them to fix the root cause, not just this instance of it.
- einpoklum 4y agoOh, that's nice of them - now you can stop using a "personal Microsoft account", which is really not something you want to have. Too bad that they didn't let you make a copy of what you had - mistakenly - stored on that account though. PS - Suggest you don't make the mistake of replacing that with a personal Google account.
- quickthrower2 4y agoThe shitness of MS accounts plus the almost requirement (modulo working around the asshole design) that you need one for windows means my next driver will be linux. Done with this shit.
- beAbU 4y agoSimilar thing happened to me. Worked on a project for a big bank. My work email was given access to their Active Directory or whatever for certain sharepoint folder access. My work machine is signed into my /personal/ microsoft account for login, and then also signed into my work-personal account (i.e. MS account with my work email, but a self created personal one - we're not an MS company). At some point I was kicked off my Xbox, had to do a password reset dance to get access again, all because Big Bank's password expiry policy somehow leaked into my personal MS account thanks to being signed into both accounts on the same pc. And now, my company got an Active Directory for us, purely to make interfacing with other MS-powered clients easier. Imagine the nightmare of my work account, originally created by myself, and the conflicts with my new "work or school" AD account. It's such a mess.
- lloydatkinson 4y agoThis seems like the kind of monumental Microsoft auth fuck up that you'll need someone "big" and well known at Microsoft to escalate it
- YPPH 4y agoGoogle and Microsoft couldn't be further apart in their login architecture, and their distinguishing of personal and work accounts. Google does an excellent job, everything is unified and sensible. Microsoft, on the other hand, is a mess. It looks like everything is mishmashed together. Sometimes logins will fail completely and you get weird error messages which look out of place in a production environment. Take but one bad example. If you look carefully, the sign in page for OneDrive is slightly different to the sign in page for other Microsoft services. It has functional differences too, namely, OneDrive's login page doesn't offer you FIDO2 passwordless authentication. Meanwhile, over on Google, everything goes through a unified login screen (accounts.google.com).
- stbenjam 4y agoGoogle’s handing of multiple accounts is still terrible though since everything is based off an index in order of sign in. Share or bookmark a work link? /u/2 is embedded in it. If later the personal account was the second login, you’d get access denied. They’re better at offering a switch account ui in some places but definitely not most.
- macNchz 4y agoThis is one of the main reasons I love Firefox’s “Multi Account Containers” extension. I can easily keep logins segregated and don’t need to worry about whether any given part of Google’s ecosystem plays nicely with their account picker.
- jvolkman 4y agoIf you're bookmarking, you can edit the URL and use `?authuser=foo@bar.com` instead. So instead of: https://mail.google.com/mail/u/1/#starred https://mail.google.com/mail/u/1/#starred bookmark: https://mail.google.com/mail/?authuser=foo@bar.com#starred https://mail.google.com/mail/?authuser=foo@bar.com#starred The URL will be immediately rewritten as the proper /u/# for that user (which, as you say, depends on login order). Not sure why it's like this, but I could see it being related to not wanting PII in the URL.
- watwut 4y ago
- hyperman1 4y agoTwo of my experiences: Some years ago, my android tablet could only read my work's office365 mail if I allowed a microsoft app to reconfigure the security. Next thing I know, I can only log in on it with my work AD account. But the WIFI is disabled, I can't enable WIFI without logging in, and WIFI is required for the AD logon process. It took a factory reset and complete erasure to pull it out of that one. Lost a good (paid) app in the process. I also learned the corporation can remotely erase the tabled whenever they like, and neither their security nor their hardware team were good thinking trough the consequences of their actions. Second was a teams install used by me and some other people to videochat each other. One day, the school invites us to a meeting, after which teams decided the account now belongs to the school. Meetings with another institute were now impossible, as team's tiny brain could not allow the school and the institute to mix. For now, I deal by creating a new microsoft account for each meeting, and nuking the teams install afterwards. My general attitude with microsoft is now: On non-MS browsers, delete all caches and settings when done, or use a different profile. On non-MS OSes, delete any login account they touched. When using any MS system like edge or windows, require different physical or virtual computers for each identity, they will leak into each other.
- mikelward 4y agoI added my daughter's school account in Teams on my phone so I could submit her homework. Later, I filled out my taxes in Excel and saved them. It had uploaded them to my school's default OneDrive shared folder. It never asked me if I wanted to use that account as my default, and never told me it had changed accounts. It took me 10 minutes of non-sensical "file is locked" messages before I could delete my private data from my school's drive. Some apps such as Microsoft Authenticator won't even let me remove the account.
- HereBeBeasties 4y agoIf you're on Android, Microsoft Authenticator shows accounts that are registered with the Android system. To remove one, in Android itself go to Settings / Passwords & accounts.
- mikelward 4y agoThank you! That's removed my account from all Microsoft apps, including Teams, but that's probably better than the alternative.
- nextlevelwizard 4y agoSome what related just last week someone from my company's IT department contacted me about adding my work MacBook to some Microsoft spyware scheme so they could start administering it and he was very stricken when I didn’t want to do it. At start he tried go get me on board with carrots like being able to print - an activity I haven’t performed in over five years. And it ended with “this is our policy” I told him that good luck coming all the way from India to wrestle my laptop from my hands. Don’t know if this will end with me looking for a new job, but what I know is that I won’t be installing whatever rap they are pushing. I am an adult and know how to admin my own computer
- niklasrde 4y agoAs somebody who worked in IT before and who had to wrestle a bit with policy in the past - I recommend you don't see your work MacBook as your "own computer". Because it's not. The company shouldn't restrict you from doing your job and reasonable and competent IT departments know which users needs what access (including root access) to perform their role, but they do also have a duty to the company and its equipment and frankly have the right and resoanable need to install admin tooling. Try and see it from their perspective.
- zelphirkalt 4y agoIt's not merely about who owns the device though. It is also about the environment a person has to work in and that, I would say, is more relevant here. Do I want to be spied upon while working? No. Do I want to feel like in a surveillance state for 8h of my day? Do I need this feeling in my life? No and no.
- pastdiscovery 4y agoFrom their perspective: Worker cost 50 money. How company get 50 money? Worker not work so much, maybe? How to quantify? What if spy? Company tell IT monkey to give developer monkey spy. Our computer, company can do a little spy. Company catch smoke break. Company catch walk break. Company give worker "performance improvement plan." Company fire worker. Company now have 100 money. Company smart. Company efficient. Company legally protected from retaliation. Company give executive monkey 30 money as reward for small overhead. Company offer manager monkey 7 money. Company offer IT monkey 3 money. Company brag about in annual report.
- mbreese 4y agoI had the same thing happen to me, just because I was added to the parent mailing list for my kids’ school. I wanted to try an Azure service (Codespaces), but was denied. It took a lot of back and forth with the schools admin to figure out what happened. I was able to get my account released, but I wasn’t brave enough to try what Jeff did. Like Jeff, this did not leave me impressed with MS Azure at all. How could joining (or being added) to a mailing list imply you are now part of an organization? How does one go from LDAP to that hosted AD mess?
- geerlingguy 4y agoI'm guessing hosted AD saves an organization $X/month in consulting fees with an added promise that "Microsoft will be able to keep this thing online better than a machine in your building." It brings plenty of other headaches though.
- eric-burel 4y agoI couldn't find the link back to an issue I've filed about auth in Teams, but certain authentication issues are specific to using iOS and do not exist on Windows... Namely, when invited in an organization, I cannot connect because I have a free personal account, but only on iOS. Windows and web are ok. Support tried to sell me a paid account, of course. As a freelancer I've lost a full day of work at the beggining of the pandemic due to this, thankfully I now have only one client (a school too) using Teams so I don't have to switch accounts.
- jcpham2 4y agoWhat I find hilarious about this is if you were an Exchange server admin around the time Exchange made the “web” swap from 2007->2010->fully EAS web managed by 2013 the guys like me were following Microsoft MVP articles on re-Hosting exchange for separate orgs on the same active directory infrastructure with UPNs basically the email as the major identifier It’s funny because Azure seems like it’s just a hacky scaled up version of what MSPs we’re doing with hosted exchange 15 years ago.
- gorbypark 4y agoMicrosoft auth and billing is infuriating. I once made the stupid mistake of signing up for a trail of Office 365 through an account managed by a company I was doing contract work for. We were developing a Team apps. Anyways, I used my personal credit card for the trial, completely forgot about it and finished that contract. After a while, that company was bought and merged with another, basically disappearing as far as their own infrastructure goes. The trial ended, Microsoft start charging my credit card, and it was literally impossible to stop it without access to the account that was managed by the now defunct company. While it was pretty hard to talk to an actual person, I did twice, and after months of back and forth via email, I was advised to just do a charge back with my credit card company. Microsoft (probably automatically) disputed the chargeback, and I spent many more weeks disputing the dispute, having to prove to my credit card there was no way to cancel and Microsoft actually told me to do a chargeback. I'm sure I'm somehow banned from Microsoft accounts using that credit card, although I've never tried.
- low_tech_love 4y agoI've never heard a single person who had positive experiences with Microsoft's cloud services (OneDrive or One*) and yet, every organizations seems to be slowly taken over by it.
- Terretta 4y ago> and yet, every organizations seems to be slowly taken over by it Microsoft Office is a big deal. It's where the worker lives. This is because Google didn't spend the money to make workplace software better than Office, only clunky web apps; while Microsoft spent the money to make web apps (nearly) as good as the workplace software everyone uses. Google chose not to displace 80% of features of the incumbent, while the incumbent added the 20% Google had thought was enough. So 85% of business workplaces and workplace users are O365/M365 workplaces and users. Btw, if you make SaaS and don't support "Login with Microsoft..." or their (very easy to integrate) SAML SSO, you're leaving 85% of your TAM on the bench. See https://www.xsplit.com/user/auth https://www.xsplit.com/user/auth as an example of a sign-in that enables every workplace and identity.
- frankfrankfrank 4y agoI’m not sure what people expect from anything associated with Microsoft. After literally many decades now of horrible Microsoft products and services that never ever reach the threshold (excel possibly being the lone exception), why would anyone expect anything other than abysmal things from Microsoft. It’s what happens when you let a robber Baron type corporation seize monopolistic control and there is effectively not real pressure to compete and get their things in order because there is a cultural assumption based on corruption/lobbying and the monopolistic lock-in will resolve any slight challenges. I don’t mean to solely focus on Microsoft, but they are the dominant example in their domain and the biggest example in tech. As a society it should have never been allowed to even be possible that things like the government, including public schools, become so captured by Microsoft’s disastrous ecosystem. People give Apple some justified flak for lock-in issues, but at least there it feels more like Apple trying to keep the horrors of especially Microsoft and Google at bay … formal dress required for entry.
- jackmott42 4y agoC#, F# and visual studio code have been fantastic in recent years.
- wyager 4y agoMS fired all the MSR programming language people working on F# and C# a few years ago, so you can probably expect the trend of C# and F# improvement to taper off.
- chazeon 4y agoI remember using Outlook on iOS a few years ago. I had an Outlook account that has a secondary address is a Gmail which i can log in with. Now if I log into that account, I cannot use Gmail with that outlook. This is how messy accounts are handled by Microsoft and it’s why i’m not so surprised by the article.
- theshrike79 4y agoWe have a similar issue with Google: Our team has a Google sheet with some scripting that uses the data in the sheet to generate data to another system. This needs to be run using the company Google account. Now someone opens the sheet, runs the script and it just doesn't work. Why? Google just randomly decides to pick one of these: - The personal Google account the user has logged in to - The account used by Chrome - The company account We haven't found a pattern to this yet. It works better for some people and worse for some depending on the time of the day, position of the planets and maybe a third unknown factor.
- jvolkman 4y agoDo people bookmark this script with the `/u/0` or `/u/1` URL component that depends on login order? See the comment elsewhere in this post about "authuser" which might help.
- insane_dreamer 4y agoI avoid Microsoft account logins like the plague. They've caused me nothing but trouble.
- mariojv 4y agoYikes. Lots of weird auth-related news coming out of Microsoft in the past week or so. A coworker shared this vulnerability disclosure the other day: https://www.praetorian.com/blog/azure-b2c-crypto-misuse-and-account-compromise/ https://www.praetorian.com/blog/azure-b2c-crypto-misuse-and-... I’d be curious about a follow up if the author ever figures out how the account takeover happened. I wonder if logging into the account on a school device resulted in automatic enrollment or something.
- annoyingnoob 4y agoAre you using Windows as your Desktop OS? Go into Settings then Accounts, remove the local copy of your account(s), then try to login to Microsoft the way you want.
- vgel 4y agoMicrosoft bought Mojang in 2014 and forced people to merge their Minecraft accounts into Microsoft accounts in 2021. Microsoft bought Github in 2018. We'll see what happens in 2025...
- AdrianB1 4y agoIt is a mess and there is more to it. I have 2 Microsoft accounts on the same email address, one is a personal account I created ~ 10 years ago and one that appeared out of the blue a few years ago. The second one seems to be created by my employer, when I try to login it is rerouting me to the job 2FA. The weirdest thing was when I tried to schedule an exam with Microsoft and it appears as free on the work account, for some reason, but not free on my personal account. I also had OneDrive set up on my personal desktop. After years of working well, one day I got an error and I had a look: it merged my personal OneDrive with the work one, so my Witcher 3 saved games were on my company's storage. I guess this happened because I tried to add my work account in Outlook to read email on that computer too. Since then, I am doing all the work related tasks in a Virtual Machine with a local Windows account and no email, no Teams, no OneDrive, etc.
- devmor 4y agoIt is for this very reason that I have a half dozen Microsoft accounts, Google accounts and so forth. Using your personal accounts for any business purposes is likely to end up like this either sooner or later (when the provider decides to change some organization schema). Given the advent of and ease of use of password managers, I'd rather just have another set of credentials than risk the inconvenience.
- barelysapient 4y agoJust don’t Microsoft. Seriously. It’s not worth the aggravation.
- timbit42 4y ago...or Google, or Apple, or Facebook, or Amazon...
- AtNightWeCode 4y agoMS messed up the design of their user and auth system completely. I can't even setup fingerprint for login on my local machine without Windows forces me to connect it to my onedrive account. An account that has nothing to do with my Windows account.
- itbeho 4y agoQuestion from a non-Windows user: In this situation would the school admin have access to the author's personal data?
- nerdile 4y agoNo
- nerdile 4y agoWhy didn't you just click Change Directory in the Azure portal and go back to your personal AzureAD where you can create your app registrations? What has happened here is that you have essentially two accounts: One is your consumer MSA, and the other is an account in the school's Azure AD instance that uses federated sign-in with an external account (your MSA). Except, the real mess comes from the fact that there's one login page for both, and sites such as the Azure portal that support both identities and can't really tell which one you expect to assume. Plus, the Azure portal lets you switch between Directories at any time. You can: * Sign out completely (login.microsoftonline.com/logout.srf) and sign back in. The reason the sign-in page asks for your sign-in email first is because then it uses that to decide which directory (MSA or someone's AAD) to sign you into * Change directories - (in fact I'd recommend creating your own Directory instead of using the one that was automatically created for you from your MSA name)
- nerdile 4y agoIf you want to see a real mess: * Create a consumer MSA based on a Gmail account * Invite that MSA into an AzureAD directory * Try to sign in as that user to that directory. Good luck!
- kiernanmcgowan 4y agoMicrosoft's auth is needlessly aggressive at all edges - I had a Windows 10 gaming PC that I didn't create a live account for. Everything works fine, until I install Halo Infinite via Steam and have to log in with a Microsoft account which then causes the OS to also login with the same account. Absolute insanity that this is even possible. At the end of the day its something I'm more disappointed than upset about. Its scammy, gross, and reflective of a company playing catchup by force.
- deleted 4y ago[deleted]
- bluGill 4y agoThis is potentially illegal hacking by the letter of the law. You can have a lawyer send a restraining order, and if they don't fix this take it to court. Of course they will then be forced to in turn sue Microsoft, who may discover the court orders all auth turned off until they can fix this.
- NorwegianDude 4y agoMicrosoft is well known to not take security serious at all. Some years ago people was able to contact Skype business support and change the password of accounts as long as they could tell them some of the contacts and the email of the account. Absolutely insanely irresponsible.
- linuxhansl 4y agoThat happened to us, and what followed was a 8 week nightmare. 1. My son's school MS account took over his private account, only because he linked the two accounts. 2. Suddenly my son's Windows said it was un-authorized. 3. We called Microsoft, they could not fix it. 4. We called the manufacturer of the machine (they shipped Windows as OEM). They could not fix it. 5. Called MS again. They gave us a new activation code. Did not fix it. 6. Called MS again, this time they said to reinstall Windows (This is not a joke). 7. Upon re-installing, Windows would not activate. No error message, no nothing it would just hang in the activation loop. 8. Called MS. They had no clue. Claimed H/W issues. 9. Called manufacturer again. Also claimed H/W issues. I said that I can access the internet from the machine while it was hanging in activation, so network was not the problem. 10. Manufacturer sent someone out (I had bought warranty). He switched the SSD with a new version of Windows... The did exactly what I did. Same problem, would not activate. 11. Some back and forth with MS and the manufacturer involving many reboot and (I kid you not) turning off all wireless routers... MS still would not activate. Manufacturer (and MS) did not believe me. So they sent someone again. Did the same thing, again. Did not work. 12. Manufacturer said I needed to send in the machine. So I did. I included a note about what the problem and to please not just re-install Windows, because the activation was the problem. 13. Got the machine back... They had just re-installed Windows. Would not activate. 14. Started to get upset. After some pressing manufacturer agreed to send a new machine. 15. First they sent someone out again. Did the same thing again. Forced me, again, to turn all wireless routers off, so that (he claimed) Windows would activate without network. Again... Did not work. Activation just hung. 16. Eight weeks into this we ended up getting a new machine (yes, not kidding) from the manufacturer and now the same version of Windows (from the same memory stick) on the same hardware, same drivers, all the same, would happily register. I cannot even begin to express how annoying and useless this was. And MS and manufacturer were helpless and useless. Personally I have stopped use Windows over 2 decades ago - only using Linux, but my son wanted a gaming machine, and so I relented. :)
- gessha 4y agoHave you heard of our lord and savior, Proton It might not work for some of the multiplayer games that youngins play although it might work.
- Tronno 4y agoMy limited personal experience with Microsoft accounts mirrors the anecdotes elsewhere in the thread. HOWEVER, the article glosses over the real story: a child obtained complete, unsupervised access to the author's computer, and wouldn't you know it, they broke something. I suspect there would be far less interest if the headline read "my kid ordered $20k worth of Robux and I can't get a refund".
- HomeDeLaPot 4y agoAt my previous employer, a mid-size company that used a lot of Microsoft products, my team had a developer intern go the ENTIRE SUMMER without access to Azure DevOps (source code, CI/CD, etc...) because he got some weird error when he tried to sign in. His account was cursed or something. Microsoft support apparently couldn't fix it. Our administrators couldn't fix it. Dozens of hours were burned on this issue, and I think he ended up just coding at someone else's computer since we pair programmed most of the time. The funny part is he joined another team full-time later on; they must have finally resolved it somehow.
- theknocker 4y ago[dead]
- koksik202 4y agoNot this guy again
- brokenmachine 4y agoMy partner has a Win11 laptop that is connected to her Microsoft account. Is it possible to convert that to a local login?
- CatWChainsaw 4y agoShould be under account settings somewhere. Loads of walkthroughs online to consult as well. But depending on your circumstances, like if she doesn't care about being in the Microsoft ecosystem, it might be safer to create a fresh local account and delete the MS account from the laptop, just to prevent any crosstalk.
- dormento 4y agoWindows is not fit for production anymore. Any business using Windows workstations is in danger, and should accordingly map it as an existential risk.
- kassian_sun 4y agoNot directly related to account issues, but I have one (and only one) password saved in Microsoft Authenticator and I can't delete it since ~3 years ago, every time it just says "Cannot delete password". I hope one day some engineers at Microsoft will notice this error in their logging system and fix this bug.