Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Spong

1005 posts

Uber Geek

Trusted

#208617 20-Feb-2017 00:51
Send private message

I have a client with an Exchange Online (365) email account that was originally setup by their previous tech who is no longer on speaking terms with my client. The account is now up for renewal and the tech is trying nasty blackmail techniques before they'll release the login and password and details they used to set this up. I have limited experience of this so wondered if there was a method of gaining access? I don't fancy my chances dealing with MS themselves. Any help gratefully accepted . 





Tivo upgrades to operate with the new OzTivo EPG, support and service. Over 400 performed here so far. See: www.hillcrest.net.nz


Create new topic
michaelmurfy
meow
13244 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1722850 20-Feb-2017 01:11
Send private message

I've had this before and it is indeed quite nasty. You could try talking to Microsoft and asking them if they're able to verify your domain via a TXT record (like they did with the initial verification). This way, you're able to verify you're indeed the domain holder and hopefully get you admin access in the process.

 

That's what I've done years ago however not sure of the process these days.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.




nitrotech
1285 posts

Uber Geek


  #1722854 20-Feb-2017 06:56
Send private message

Get the partner of record changed to the new tech then the new tech will be able to make the necessary changes

Spong

1005 posts

Uber Geek

Trusted

  #1723175 20-Feb-2017 18:01
Send private message

This has been worse than getting teeth pulled so far. I've spoken to 2x CSR's in the Microsoft Office 365 Data Protection Team and after extended explanations they've both sent me off to the Password Recovery process that assumes I'm the original IT Pro with their email address and mobile number. I knew this wouldn't be easy, but they just don't seem to grasp the situation. If only Nathan Mercer was around? Maybe he'd be able to help. 





Tivo upgrades to operate with the new OzTivo EPG, support and service. Over 400 performed here so far. See: www.hillcrest.net.nz




SATTV
1648 posts

Uber Geek

ID Verified

  #1723181 20-Feb-2017 18:19
Send private message

Are there any users that are a password admin?

 

If so they could reset the admin account password.

 

Failing that, I think the only thing you could do is migrate them as a new tenant using something like sky kick or migration whiz.

 

As you don't have the admin you wont be able to use impersonation, you will have to have everyone's password.

 

Good luck.

 

John

 

 





I know enough to be dangerous


loceff13
1065 posts

Uber Geek


  #1723185 20-Feb-2017 18:31
Send private message

In before OP realizes it's just a bad client who shortchanged the former IT guy or something.


bagheera
539 posts

Ultimate Geek


  #1723188 20-Feb-2017 18:34
Send private message

how the  authentication setup - if adfs, then reset his password on the local domain and login, same if it password sync, but wait 30 min, if it pure AAD, then it talk to your MS account manager if you got one to start jumping up and down, if not, it will be log call with MS and keep pushing up the support level till get to someone that can a: verify the account and b: reset the password.

 

 

 

edit: when you get the account back, setup more then one global admin, one of which is lock away in a safe for a "oh, what you mean we have no admin left" days.


nathan
5695 posts

Uber Geek
Inactive user


  #1724729 22-Feb-2017 20:45
Send private message

Spong:

This has been worse than getting teeth pulled so far. I've spoken to 2x CSR's in the Microsoft Office 365 Data Protection Team and after extended explanations they've both sent me off to the Password Recovery process that assumes I'm the original IT Pro with their email address and mobile number. I knew this wouldn't be easy, but they just don't seem to grasp the situation. If only Nathan Mercer was around? Maybe he'd be able to help. 



I miss you too

I don't really know anything about this any more, but I FW this thread onto someone else still at MSNZ who will know what to do.

Your admin almost sounds like blackmail. Very short sighted thing to do in the small World we live in now

 
 
 

Free kids accounts - trade shares and funds (NZ, US) with Sharesies (affiliate link).
Spong

1005 posts

Uber Geek

Trusted

  #1724787 22-Feb-2017 22:26
Send private message

Well the end result was that we just couldn't get any further with this. The Microsoft Office 365 Data Protection team simply wouldn't budge because the blackmailer - the previous IT person (A South African guy, not that it's relevant) who had been negligent in several areas, had setup and owned the account, and had ensured all details relating to the Global Administrator were his. Obviously we couldn't provide his credentials. MS have strict guidelines and follow them to the letter it seems. 

 

It seems this could happen to others, so it surprises me that Microsoft don't appear to have a system in place to deal with it. The USA based CSR admitted they'd seen this before. The end result has been that my client (the domain holder and owner of the business) has given in and paid the ransom, despite being against his principles, as it was cheaper than the alternative of transferring the domain to a new account and losing the existing history. 

 

...Ransomware without the benefit of a backup...





Tivo upgrades to operate with the new OzTivo EPG, support and service. Over 400 performed here so far. See: www.hillcrest.net.nz


antoniosk
2358 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1724801 22-Feb-2017 22:56
Send private message

If you've got the information, your client can now sue the guy.

Blackmail is blackmail and a crime - even if setttled in civil court, the guys name will come up in future searchs,

And as another poster said.... nz is a very small place, and blotting your own copybook is indeed very dumb.





________

 

Antoniosk


1101
3122 posts

Uber Geek


  #1724921 23-Feb-2017 09:37
Send private message

antoniosk: If you've got the information, your client can now sue the guy.

Blackmail is blackmail and a crime - even if settled in civil court, the guys name will come up in future searchs,

 

In general, as none of us have all the facts....  :-)

 

Often, in cases like this, its a simply a case of IT not co-operating untill they get paid whats owed them
Its not blackmail or extortion if that IT guy is just refusing to help or deal with them while money is owing, or a contact was broken.
Ive worked at companies where that has happened .Some IT guys will even use remote access and secretly starting causing issues untill paid.
Or, could be the IT guy is just a nasty piece of work, who knows ?

 

Suing is really just throwing $10K++ at lawyers. Not a realistic or quick option for many small business.

 

 


paulb001
40 posts

Geek

Trusted

  #1724989 23-Feb-2017 10:25
Send private message

Hi guys, you can contact Office 365 Billing Support, and they can run you through an Admin ACCOUNT reset, by requesting proof of identity, company letter head and proof of domain ownership. The customer must initiate this and contact them on 0800 194 197. Note however that MS will not get involved in issues where there is debts owing and a tenant is setup and completely managed by a 3rd party. Note also that a delegated admin and Partner of record can reset p/w anytime, so you would have to remove these as well.

 

 

 

Its a worthwhile reminder that like an on premise server, customers should always control the admin login and password details for THEIR servers/services.

 

Any issues reach out to me on nzcloud@microsoft.com

 

 

 

 





Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.