Microsoft.AAD.BrokerPlugin Errors Are Signing Users Out Across Multiple Tenants

0
1
Asked By MellowOrbit42 On

Several users across three separate organizations were unexpectedly signed out of OneDrive and Outlook. The affected devices show the error "Microsoft.AAD.BrokerPlugin WebAccountProvider did not register with DCOM within the required timeout," along with AzureAdPrt: YES and WamDefaultSet: ERROR (0x80080300). We initially spent several hours troubleshooting without finding a fix, and then saw similar reports from four more users. Has anyone else encountered this issue, and are there known causes or reliable fixes?

3 Answers

Answered By PixelMaple63 On

Endpoint security software was another possibility, but the affected systems were using SentinelOne rather than Trend Micro. Removing SentinelOne temporarily did not resolve the issue, so it probably isn't the primary cause. Given that all affected machines are Lenovo Legion Go devices, I would investigate a recent Lenovo firmware or driver update next.

Answered By CedarFox7 On

It may be worth checking whether the tenants use an identity provider where legacy authentication was recently disabled. Changes in federation or authentication policy can sometimes affect the Web Account Manager and broker plugin.

MellowOrbit42 -

These tenants aren't federated with another identity provider, so that doesn't appear to be the cause. We also noticed that every affected device is a Lenovo Legion Go.

Answered By QuietHarbor19 On

Check the TPM on each affected device and confirm that it is healthy, enabled, and accessible by Windows. A TPM or device-registration problem can interfere with the broker plugin and cached work-account tokens.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.