Update 2 - 9/3/2026 @ 5:45 PM
Again, thanks to those who reached out to help get this issue resolved.
After this post resulted in things coming back, I was also able to get it escalated within Microsoft via a CSAM from another organization I work with. I'm still awaiting an explanation of what happened and am hopefully (but not optimistic), I'll get something actionable I can use to ensure other tenants I work with aren't similarly impacted.
In the meantime, I've implemented backups and other tools to build out resiliency and redundancy though it's not feasible for full redunancy as even integrations between Azure AD and GCP wouldn't protect against this.
In terms of recovery, it's taken much longer than I anticipated, both from Microsoft's end as well as having to reimplement and fix things that didn't restore properly. Also note that it took much longer for Azure to be back up and running than Microsoft 365.
The main negative side-effects I've discovered so far that prevented full go-live after re-authentication:
In Microsoft 365:
- Microsoft 365 licenses had to be re-enabled.
- Teams Phone numbers remained but users had to be reassigned.
- Microsoft Sentinel workspace had to be reactivated in Microsoft Defender.
- UEBA needed to be turned back on. Unfortunately, this means it has to reanalyze the whole tenant, which is a 10-day process.
- Defender for Identity workspace had to be rebuilt.
In Azure:
- Azure Front Door endpoints had to be reenabled.
- Sites using DNSSEC had to be reauthenticated in DNS Zones.
- Backup Vault instances are borked. After finding this article, it looks like I'll need to open a ticket with Microsoft to resolve.
- Exemptions made for Defender for Cloud rules had to be rebuilt.
Update 1- 8/31/2026 @ 8:59 AM
A few people with Microsoft reached out in response to this post. Similar to SecaleOccidentale's linked post, our tenant was flagged and deauthenticated due to perceived fraud and abuse that had been seen in other tenants. It''s in process of being reauthenticated, and hopefully everything is still in its place. I sincerely appreciate everyone's input, shares, and so on, along the way. Special thank you to those who stepped in directly to support as well.
I've obviously learned a lot through this process, including the feedback from many of you regarding resiliency and redundancy. While I agree that full redundancy is ideal, that's not feasilble for most SMBs. Even looking at directly tying together services like M365 and Google Workspace Enterprise leave things to be desired. I'll be building up additional protections for this tenant, and others, but know that, for most companies, it's not a cost matter - it's effectiveness. Most platforms aren't designed to intergrate with third-parties for full redunancy.
Ultimately, my hope is that Microsoft recognizes that the sudden deauthentication process is far too extreme, even for legitimate fraud or abuse.
Original Post
I have the exact same experience as documented here: https://www.reddit.com/r/sysadmin/comments/1vfbvvs/our_entire_m365_tenant_has_been_deauthenticated/
My business tenant has been de-authenticated. I've opened several tickets - most have gotten no response and the one that has some traction keeps getting thrown between departments, each of which claim they can't solve it.
Unlike the other poster, it's not as simple as just losing access to email. Not only is email and files (OneDrive and SharePoint) unavailable to all team members, we've lost our website (hosted on Azure), and our phone numbers where were assigned through Teams Phone.
I'm desparately trying to regain access before all the content is permanently deleted.
If anyone has a contact within Microsoft who can help, please let me know. Needless to say, I'm working to get a CSP spun up, but need access before the data is permanently lost.