Several users were unexpectedly signed out of OneDrive and Outlook, and the issue has now appeared across multiple companies and three separate tenants. The affected systems report "Microsoft.AAD.BrokerPlugin...WebAccountProvider did not register with DCOM within the required timeout," along with AzureAdPrt: YES and WamDefaultSet: ERROR (0x80080300). We initially spent several hours troubleshooting without finding a fix. Has anyone seen this behavior recently, and are there known hardware, firmware, security software, or identity-provider causes?
4 Answers
Since the affected machines all appear to be Lenovo Legion Go devices, I would compare their BIOS, firmware, Windows build, and driver versions. A recent vendor update could explain why users across unrelated tenants began seeing the same broker-plugin and sign-in symptoms.
Check the TPM on each affected machine and verify that it is enabled, healthy, and responding correctly. TPM or device-registration problems can cause Azure AD PRT and Web Account Manager errors, even when the PRT itself appears to be present.
It may be worth checking whether any of the tenants use a federated identity provider where legacy authentication was recently disabled. Changes in that area can sometimes affect Web Account Manager and token registration.
Are the affected devices running Trend Micro or another endpoint security product? Security software can interfere with the broker plugin and DCOM registration. In this case, though, SentinelOne was installed, and removing it did not resolve the problem.

The affected devices appear to be Lenovo Legion Go systems, so we are also investigating whether a Lenovo firmware or driver update is involved.