Title: Some users with anonymous SharePoint Online links may be incorrectly prompted to sign-in
User impact: Users with anonymous SharePoint Online links may have been incorrectly prompted to sign-in.
More info: Specifically, SharePoint links created with the ‘Anyone with the link’ option may have been incorrectly prompting some users to log in with an account.
Impact may have affected users with SharePoint Framework (SPFX) customization deployed in the site.
Final status: We’ve determined that a recent change to how Microsoft Authentication Library (MSAL) handles requests contained a code issue, which was causing users with anonymous SharePoint Online links to have been incorrectly prompted to sign-in. We’ve reverted the offending change and confirmed with internal testing that the impact is remediated.
Scope of impact: Impact was specific to some users who are served through the affected infrastructure.
Start time: Friday, March 1, 2024, at 5:07 PM UTC
End time: Wednesday, March 20, 2024, at 5:36 PM UTC
Root cause: A recent change to how Microsoft Authentication Library (MSAL) handles requests contained a code issue, which was causing users with anonymous SharePoint Online links to have been incorrectly prompted to sign-in.
Next steps:
– We’re further reviewing the recent change to understand how the code issue was introduced and to understand what prevented it from being detected in our update testing and validation procedures, which will allow us to prevent similar issues in future updates.
This is the final update for the event.
Posted inUncategorized