I have been studying for AZ-104 for about a month. I keep re-reading the material and not comprehending it because I can not do the exercises. I am pretty upset about having invested so much time - only to be completely blocked because the only learning tool that is available to actually comprehend the material and pass the exam does not work.
Today I decided to try everything again to make the login work. Of course, every time I try to log in Azure wants to re-install Authenticator on my phone and make me set up a new account even though my paid Azure subscription uses MFA just fine.
So I decided to let it re-install - I scanned the QR image and got this notification on my phone:
******@outlook.com#EXT#@triplecrownlabs.onmicrosoft.com is trying to login.
I have no idea who or what triplecrownlabs.onmicrosoft.com so I googled it and found this issue:
https://github.com/Azure/azure-cli/issues/30139
"triplecrownlabs.onmicrosoft.com" is no tenant of mine perhaps it is some placeholder for the sandbox.
In any case I did not approve the login and it timed out. I deleted the authenticator account that was set up on my phone.
On my computer, I hit the back button (or refresh - I don't remember) and was able to log in without completing the MFA auth(!!!)
Remarkably, I was also able to use the sandbox. I was pretty amazed that I was able to bypass MFA so I logged out and closed all browser windows and tried to repeat the above, this time documenting every step. This time the Microsoft Authenticator set up did not complete and I was able to log in and bypass it again.
Steps to reproduce:
Open private browser window
Log into learn.microsoft.com.
Navigate to this page: https://learn.microsoft.com/en-us/training/modules/host-domain-azure-dns/4-exercise-create-dns-zone-a-record
Click Activate Sandbox
Click on sign in On the right pane
AADSTS500200 error will occur. Left pane will show Sandbox activated. Right pane will continue to show sign in button.
Open a new private browser window
Log into Azure portal using same account in steps above.
At "More Information required" dialog, click Next
The screen flashes a couple times and a success dialog is displayed. NO MFA.
Click Done and you are logged into Azure, BYPASSING MFA and can now use the sandbox.
This appears to be a real security problem - I am using a paid Azure account and I am now able to log in and bypass MFA.
I'm out of time for this. I spent the entire evening documenting this when I should have been studying for the exam. If I have some time tomorrow I'll work on it more.
Microsoft please fix this - thank you.