entra1-10 Exercise 1: The Litware Guests ========================================================= Source: Course chapters 6 to 8; Microsoft Learn pages on Conditional Access, cross-tenant access settings and the AADSTS reference. Re-check before quoting to a client. SITUATION Litware's staff (guests in Tailspin's tenant) are blocked since Monday; Tailspin's own staff are fine. Two Litware entries show AADSTS53003 with the Conditional Access policy "Require compliant device" = Failure. A third shows AADSTS50020. STEP 0 PRESERVE Save the three entries, the correlation IDs, the times and the policy name. Download the filtered sign-in log (Free keeps 7 days). STEP 1 WHO IS AFFECTED Only guests from one partner organisation, started at one moment (Monday). Chapter 6 table: "Only guests or external staff" -> guest account missing, cross-tenant inbound settings, untrusted MFA/device claims. STEP 2 RIGHT TENANT AND APP Confirm we are looking at Tailspin's tenant (tenant card). The enterprise app's Properties are probably healthy (Tailspin staff are fine), so the integration itself, its credentials and assignment are not the main suspects. Check Assignment required and whether the Litware guests (or a group they belong to) are assigned, in case it is also involved. STEP 3 THE LOG 53003 = BlockedByConditionalAccess. The CA tab names "Require compliant device" with result Failure: a device-compliance control, applied to guests. A guest's device is managed (if at all) by Litware, not Tailspin. Unless Tailspin trusts the device-compliance claim from Litware's tenant, a guest cannot satisfy "compliant device" in Tailspin's tenant. 50020 = UserUnauthorized: the account does not exist in this tenant as an external user. That is a separate cause: this third person may not have been invited or may be signing in with the wrong account. STEP 4 CONFIRM (THREE PLACES) - Log: CA tab shows the policy applied and failed; Device info tab shows the device not compliant/managed from Tailspin's view. - Portal: Conditional Access > Policies: when was "Require compliant device" changed or turned on, and does it include guests? Cross-tenant access settings: are device claims from Litware trusted (inbound trust settings)? - Audit log: policy or cross-tenant settings changes late last week or Monday morning (category CrossTenantAccessSettings for the latter). Story: not the credential (story 4). Do not rotate anything. LIKELY CAUSES, WITH CONFIDENCE A. A new/changed Conditional Access policy requires a compliant device for "all users" including guests (high confidence, because the log says so). B. Tailspin does not trust Litware's device claims in cross-tenant access trust settings (medium confidence; it would explain why guests fail but must be confirmed in the settings). C. One guest (50020) has no guest account in Tailspin's tenant (medium; needs the user list to confirm). This is a second, independent problem. FIX (the client's decisions, our request) - Ask Tailspin's security team to adjust the policy for this integration or for guests (for example, a different control for guests such as MFA, or trusting Litware's compliance/MFA claims in the trust settings, or an exclusion scoped to Litware guests). Do not ask them to turn the policy off. - For the 50020 user: Tailspin's administrator invites them as a guest and assigns them to the app, if Assignment required is Yes. - Test with one guest, then confirm the CA tab now shows Success. MESSAGE TO TAILSPIN (short) "Your Litware guests are being stopped by a Conditional Access policy that requires a compliant device, which they cannot meet from their own organisation's devices. This is a security setting and appears to have changed on Monday. We don't need it removed; we'd like your security team to decide how guests should be treated, for example by trusting Litware's device or MFA claims. One further guest has no account in your tenant. We can look at the policy and cross-tenant settings together with your administrator." PREVENTION Add guest and partner access to the onboarding checklist, ask Tailspin to tell us before policy changes that affect guests, and record Litware's access path in the register notes. WHAT NEEDS MORE EVIDENCE Whether the policy changed on Monday (audit log); whether trust settings exist for Litware; whether the 50020 user was ever invited. WHY THIS WORKS AS AN ANSWER --- It follows the playbook in order, separates two independent causes, avoids rotating a healthy credential, and states honestly what is confident and what is not.