Can't sign in with FIDO2 key on office.com
bugzilla.mozilla.org
bugzilla.mozilla.org
https://1password.community/discussion/139501/one-time-passw...
The fact that you can set a domain to MSA/TOTP or MSA-only, but not TOTP-only, is an incredibly scummy, but incredibly predictable move by MS.
As in: I log in, jump through the MFA hoops, and then it goes back to the list of user names to make me re-select the account I just used to log in.
Mind you, it always did this, which meant that I couldn’t just open a Portal link in a new tab — I’d have to select my account (again) for each tab.
But now I have to click at least ten times!
It’s broken.
Authentication is broken and there’s no one at the wheels.
At work one of the cdn domains they use fails to resolve until it suddenly works. Haven't bothered to look into it yet, but generally takes about 10-15 minutes to sign into anything related to Azure AD / Office365.
Can resolve it just fine on the command line, just in the browser where it doesn't work.
With the additional bonus that even after things miraculously stabilize, I'm not on the page I wanted to go but on the welcome screen. Pasting the intended link again in the browser bar seems to have a 10% chance of triggering the redirect loop again. It's so comically bad, I'm glad my employer is paying me for my time and not my productivity.
I get signed out constantly, especially on mobile where my coworkers do not. Trying to sign into ADO sends me to a screen prompting me to configure a new org because it gets confused by two accounts existing with the same email in the same org even though one of them was deleted along with the underlying AAD account. It also just 500s sometimes when trying to login saying there’s something weird happening during authentication, I have to restart the browser to make it work.
As far as I know there’s no way to fix any of it, so I’m stuck with half working SSO.
Even their Edge does not work, just Chromium. If possible, avoid MS login (or all their products in general)
I often wonder if they’re even capable of knowing there’s an issue.
No!
Microsoft famously fired their entire QA team. Also… their technical writing team. And then they outsourced both support and the bulk of their development to India.
You get what you pay for, and right now Microsoft is variously paying either zero or very little.
It's really really annoying because these people get penalised for escalating and they don't know much more than what it says in the docs. I read those before contacting them and it's always a hassle to get my case through to real support. They'll stall forever asking for more logs and more tests. I feel like I'm on trial defending that I really have a problem. Not a valued customer.
And mind you, this is already meant to be the "premium" support tier.
> (it's not an issue with Firefox's implementation. This can be demonstrated by spoofing the useragent as a Chromium-based browser and attempting the same login flow […]).
That check lies somewhere along the line between "having the direct goal of breaking authentication flow (pure malice)" and "is a completely legitimate programming error (pure incompetence)."
I am not ready to assume pure incompetence (and here's where I might be wrong).
In fact it's not completely unlikely that that is what happened here. Firefox still has incomplete support for the web authentication API [1], and in particular FIDO2 devices did not work if a PIN is set until Firefox 114 - only a few months ago! I'm not sure if this could be related, but Firefox also still does not support passkeys [2], so I'm sure someone will get blamed for anti-competitive behavior for that at some point.
If Microsoft solves the issue within the next 30 days, I will consider that you were right.
"30 days" is an arbitrary extension of the timeline for something that was reported 4 months ago to Microsoft, and should have been already fixed.
Today I switched Outlook to the new Outlook and then it couldn't access my email account because of some licensing issue? No other error or how to resolve.
Who allows things like this to be shipped without minimal QA is beyond my imagination...
You seem understandably frustrated. :/
"Microsoft 365 subscriptions include premium customer support, so if you need to contact Microsoft for help, you'll get our highest level of service."
Firefox is down to like 6% marketshare, barely above (what's left of) Opera. Even Edge has nearly twice the usage.
Is reasonable to expect a company to go out of their way to spend resources fixing something that works fine for 94% of their users, using any of several alternate browsers?
And this is Microsoft after all, the same company that's been through multiple browser wars and finally caved and joined the Blink family. Why should they care about Firefox?
Maybe that's a question for them to answer since they actively block it with user agent checks
If they truely did not care about Firefox, it would have worked.
It's the same issue on mobile as well, Google still serves the dumbed down search version to Firefox whereas the one they serve on Chrome fully works with a user agent change.
so, what I'm hearing is that FF should change its current U-A from `Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:120.0) Gecko/20100101 Firefox/120.0` to just `Mozilla/5.0` and skip the pretense :-)
In all seriousness, Chrome/Chromium actually had a plan to do some U-A simplification <https://www.chromium.org/updates/ua-reduction/> but it doesn't appear they're going as far as evicting the Chrome branding from it, nor (confusingly enough) dropping the Safari misnomer (since they don't use WebKit anymore)
So in other words: there's nothing wrong with the technical implementation of the browser engine, but Microsoft consciously degrades the experience for me if they know I run firefox.
Should MS care enough about 300 megausers to make sure their login flow works? Uh, yeah.
And yes, I support Internet Explorer, Lynx, and NetSurf.
I choose the former, because I think the extra effort is worth it. Resources are not unlimited, but it's also quite feasible, if you are creative and not lazy.
And if you cannot even support IE, I guess you think that textmode browsers, visually impaired support, slow network connections, and other accessibility modes are also not worth your time?
My point being, it’s great to support all modern browsers (which excludes IE altogether, but definitely including screen readers). If you’re a library, go ahead and support dialup and Lynx, too, if you can afford the dev time. If you’re an e-commerce site, and spending more than hobby time supporting Lynx and 56k, I might think you’re nuts for doing it.
Out of their way implies they have to do anything more than implement the standard and don't do browser sniffing, which has always been a bad practice and especially since feature testing has become more widespread. A sibling comment highlighted the part that it works if the user-agent is changed to Chrome.
So, here's my take to your original question: If a feature has a backing standard, companies, especially those above a certain size, should be forced to follow the standard for that feature and not include any kind of "only allow using this feature if we have tested it in the browser" code. If the company states they cannot do that (cause they have a policy to only allow features in browsers they've tested or whatever), they should be forced to support everyone.
Another good reason to force support for everyone should be if the company has their own browser.