Login issues affecting email-based 2‑factor codes

Resolved
Updated

Incident Post Mortem: Login Issues Affecting Email-Based 2Factor Codes

Summary

Between Saturday 11 July at 12:00 PM AEST, when we received the first customer report, and late evening on Monday 13 July, some Calxa users experienced issues completing the email-based 2factor authentication step during login. Affected users saw a “Claim not verified: [Email Address]” error even after entering a valid email code. SMS and authenticator app verification continued to function normally.

Microsoft later confirmed this was caused by a platform issue within Azure Active Directory B2C, triggered by a recent service change that resulted in unexpected claim verification failures.

Microsoft completed their mitigation at 11:15 PM AEST on Monday 13 July, and after a period of monitoring, we confirmed that no further issues were found or reported, and all sign in methods were functioning normally.

Incident Details

What Happened

A Microsoft service change introduced a condition that caused Azure AD B2C to intermittently return incorrect claim verification messages during email‑based 2FA. This resulted in some users being unable to complete the login process using email codes.

The issue was intermittent and difficult to reproduce consistently, which contributed to delays in diagnosis and escalation.

Impact

  • Users relying on email‑based 2FA intermittently could not complete login
  • Some users were able to successfully sign in by waiting a few minutes before resubmitting the final verification step
  • Other 2FA methods (SMS, authenticator apps, backup codes) continued to work normally
  • Trial sign‑ups were also affected due to email verification requirements

Root Cause Analysis

Microsoft confirmed the root cause as:

“A recent Azure AD B2C service change that introduced a condition causing email verification workflows to return incorrect claim verification messages.”

Contributing factors:

  • Intermittent nature of the issue made reproduction difficult
  • Microsoft could not initially verify the issue as a platform service fault, and weekend support limitations delayed confirmation
  • Microsoft was initially unable to link our support case to the correct underlying service, which delayed access to the diagnostic logs needed to confirm the root cause

Calxa Response

Our team:

  • Responded immediately upon first awareness by internal team
  • Reproduced the issue and isolated it to email‑based 2FA
  • Raised multiple Severity A cases with Microsoft
  • Escalated through our Azure Customer Success Manager
  • Provided continuous updates on the Calxa Status Page
  • Guided customers toward alternate 2FA methods where possible

Preventative Measures & Next Steps

  • We will encourage customers to set up additional 2‑factor authentication options (such as authenticator apps or SMS)
  • We will introduce periodic reminder campaigns to help ensure users have multiple verification methods configured
  • We will improve weekend and after‑hours detection by:
  • exploring ways for customers to report outages more directly
  • exploring ways to enhance our AI chat assistant to identify and escalate urgent out of hours issues
  • Longer term we have a project scheduled for 2027 to evaluate alternative authentication service providers, now including requirements to enforce multiple 2‑factor methods at sign‑up

Conclusion

This incident was caused by an Azure AD B2C platform issue affecting email-based 2FA verification. Microsoft has fully mitigated the issue, and after extended monitoring, we confirmed that no further issues have been found or reported. All signin methods are functioning normally.

We apologise for the inconvenience this caused and appreciate your patience while we worked through the issue with Microsoft. We are taking clear steps to improve resilience, strengthen authentication options, and enhance our ability to detect and respond to issues promptly.

Avatar for Shem Bogusz
Shem Bogusz
Resolved

We’ve completed our monitoring and can confirm that no further authentication issues have been found or reported since Microsoft’s mitigation steps were deployed. All sign‑in methods are functioning normally, and the incident is now considered resolved.

We’ll be conducting an internal review of this incident and will publish a post‑incident report in the coming days to outline the timeline, contributing factors, and improvements we’re making to strengthen future resilience.

Thank you for your patience while we worked through this issue.

Avatar for Shem Bogusz
Shem Bogusz
Recovering

We’re seeing strong signs of recovery following the service issue affecting email‑based 2‑factor verification. Microsoft has confirmed the underlying cause and completed mitigation steps, and authentication flows are now behaving normally.

All users should now be able to sign in, and we haven’t observed any further authentication issues since mitigation. When you access your account, we recommend setting up an alternate 2‑step verification method (such as an authenticator app or SMS) as a best‑practice to strengthen your login options.

We’ll continue to monitor closely throughout the early business hours to ensure the service remains stable and no further issues are reported.

Avatar for Shem Bogusz
Shem Bogusz
Identified

Microsoft has now acknowledged this as a service issue affecting Azure AD B2C email‑based verification. They’ve identified a recent change on their side that may be contributing to the problem and are actively deploying corrective updates while monitoring recovery.

Avatar for Shem Bogusz
Shem Bogusz
Updated

We’re continuing to investigate the issue affecting email‑based 2‑factor verification. While we don’t have new technical details to share yet, most users are able to sign in by leaving the verification window open for a few minutes and then clicking Continue.

If you can log in, we recommend setting up an alternate 2‑step verification method (such as an authenticator app or SMS) to avoid further disruption.

We’ll provide another update as more information becomes available.

Avatar for Shem Bogusz
Shem Bogusz
Updated

We’re continuing to work closely with our authentication provider to resolve the issue. While we don’t have new information to share right now, investigation is ongoing and we’ll update again as soon as we have something concrete.

Avatar for Shem Bogusz
Shem Bogusz
Updated

We’re continuing to investigate and are working closely with our authentication service provider to resolve the issue. In most cases, leaving the verification window open for a few minutes and then clicking Continue does allow the login to proceed. We’ll provide further updates as soon as we have more information.

Avatar for Shem Bogusz
Shem Bogusz
Investigating

We’re aware that some users are currently seeing an “Claim not verified: [Email Address]” error when entering a 2‑factor authentication code sent by email.

All other verification methods (SMS, authenticator apps, backup codes) continue to work normally.

Our initial checks suggest the issue is intermittent. In some cases, leaving the verification window open for a short period and then clicking CONTINUE again allows the login to proceed successfully.

We’re actively investigating and will provide further updates as soon as more information is available.

Avatar for Shem Bogusz
Shem Bogusz
Began at:

Affected components
  • Calxa Online Web App