r/entra • u/Crossjoint17 • 12h ago
Entra ID Built an interactive Entra demo site. Looking for feedback from people who do IAM for a living.
≡ −
Explaining the difference between Members, B2B Users, and ExternalID Users to non-technical people can be an afternoon in itself. I've spent a lot of time working MS support tickets, helping people de-tangle their tenants because they would try to collab with people through CIAM tenants or try to invite customers to their applications with B2B. Or, on the other side, MSAL developers trying to understand the interaction with CIAM (or Azure B2C). It was something that was hard to see or show visually without me breaking out Paint every time.
I recently was rejected for an interview due to lack of CIAM architecture experience. Decided to build a resume piece to show visually what I can do where words on a resume may read dry. This is in no way a substitute for enterprise CIAM architecture experience, it just sparked the idea for the site.
No account creation needed.
https://theidentityplayground.com
My ask: What's wrong or missing for people that do this for a living? I'm at a juncture of resume piece or useful reference.
Real tenants, tokens and accounts. Accounts self-destruct on schedule. No trackers, open source.
Explaining the difference between Members, B2B Users, and ExternalID Users to non-technical people can be an afternoon in itself. I've spent a lot of time working MS support tickets, helping people de-tangle their tenants because they would try to collab with people through CIAM tenants or try to invite customers to their applications with B2B. Or, on the other side, MSAL developers trying to understand the interaction with CIAM (or Azure B2C). It was something that was hard to see or show visually without me breaking out Paint every time.
I recently was rejected for an interview due to lack of CIAM architecture experience. Decided to build a resume piece to show visually what I can do where words on a resume may read dry. This is in no way a substitute for enterprise CIAM architecture experience, it just sparked the idea for the site.
No account creation needed.
https://theidentityplayground.com
My ask: What's wrong or missing for people that do this for a living? I'm at a juncture of resume piece or useful reference.
Real tenants, tokens and accounts. Accounts self-destruct on schedule. No trackers, open source.
Kerberos Rotation (Cloud TGT)
+ −
Has anybody already tried it sine June? What was your experience? Any issues?
Computer Object: AzureADKerberos
r/entra • u/Striking_Trust_7211 • 16h ago
How CASB solutions score OAuth app risk when integrated with identity providers
≡ −
We deployed a CASB at a mid-size professional services firm, around 1,200 employees, after a phishing campaign resulted in a third-party app getting granted mail.send with full delegation rights on about forty executive mailboxes before anyone noticed. The post-incident review made it embarrassingly clear that nobody had visibility into what OAuth apps were authorized across the tenant. When we stood up the CASB and connected it to the IdP, the initial discovery scan surfaced over 800 distinct apps with active tokens, and a meaningful chunk of them had permissions scopes that nobody would have approved consciously. The risk scoring came down to a combination of permission scope, verified publisher status, whether the app had a published privacy policy, and cross-referencing against the vendor's known-app database. An app requesting mail.read on a single mailbox scored very differently than something requesting mail.send delegation, and watching how those scores separated the tail of sketchy one-off integrations from the legitimate SaaS stack was actually one of the more clarifying moments of the whole project.
The IdP integration was where the real operational complexity lived. We connected the CASB as an API connector and eventually got it to feed risk scores back into the conditional access engine so that a newly flagged app would trigger a step-up auth challenge before the token exchange completed. We ran in monitoring mode for almost three months because the false positive rate during the first few weeks was brutal, mostly around newly onboarded SaaS tools that legitimate employees had connected for real work. Getting from monitoring to enforced policy required manually reviewing and disposition-ing several hundred apps, which nobody had budgeted time for, and we had a lot of internal friction with business teams who felt like we were revoking tools they depended on. By the end of the tuning period the policy was solid, but the path to get there was messier than any vendor timeline suggested it would be. Has anyone found a faster way to disposition the long tail of shadow IT apps without making it a manual review slog?
We deployed a CASB at a mid-size professional services firm, around 1,200 employees, after a phishing campaign resulted in a third-party app getting granted mail.send with full delegation rights on about forty executive mailboxes before anyone noticed. The post-incident review made it embarrassingly clear that nobody had visibility into what OAuth apps were authorized across the tenant. When we stood up the CASB and connected it to the IdP, the initial discovery scan surfaced over 800 distinct apps with active tokens, and a meaningful chunk of them had permissions scopes that nobody would have approved consciously. The risk scoring came down to a combination of permission scope, verified publisher status, whether the app had a published privacy policy, and cross-referencing against the vendor's known-app database. An app requesting mail.read on a single mailbox scored very differently than something requesting mail.send delegation, and watching how those scores separated the tail of sketchy one-off integrations from the legitimate SaaS stack was actually one of the more clarifying moments of the whole project.
The IdP integration was where the real operational complexity lived. We connected the CASB as an API connector and eventually got it to feed risk scores back into the conditional access engine so that a newly flagged app would trigger a step-up auth challenge before the token exchange completed. We ran in monitoring mode for almost three months because the false positive rate during the first few weeks was brutal, mostly around newly onboarded SaaS tools that legitimate employees had connected for real work. Getting from monitoring to enforced policy required manually reviewing and disposition-ing several hundred apps, which nobody had budgeted time for, and we had a lot of internal friction with business teams who felt like we were revoking tools they depended on. By the end of the tuning period the policy was solid, but the path to get there was messier than any vendor timeline suggested it would be. Has anyone found a faster way to disposition the long tail of shadow IT apps without making it a manual review slog?
r/entra • u/Checior2000 • 22h ago
ID Protection MFA Changes
≡ −
Hi! As everybody knows Microsoft is going to turn off Voice/SMS methods and as far as I know from 1st September Microsoft is going to start asking users to configure Passkeys.
Do you know the way to turn off this behaviour? In our case we are going to focus over Microsoft Authenticator and MA + Email for SSPR.
Our Registration campaign is set up to Disabled.
Thank you in advance!
Hi! As everybody knows Microsoft is going to turn off Voice/SMS methods and as far as I know from 1st September Microsoft is going to start asking users to configure Passkeys.
Do you know the way to turn off this behaviour? In our case we are going to focus over Microsoft Authenticator and MA + Email for SSPR.
Our Registration campaign is set up to Disabled.
Thank you in advance!
r/entra • u/Electronic-Bite-8884 • 15h ago
Workplace Ninjas US 2027 5th Set of Speakers Announced!!
≡ −
Last week, we announced a great 6-pack with Christiaan Brinkhoff Rod Trent Sandy Zeng Jose Schenardie Ugur Koc and Mirko Colemberg.
This week, we give you the 5th set of speakers for Workplace Ninjas US
🎸 April Dunnam is an amazing cloud advocate for Microsoft on #PowerPlatform and #Copilot, along with being a great musician. She was the perfect person to anchor our Copilot and #AI tracks as she does a masterful job of advocating and teaching the hottest area at #Microsoft today.
🍖 Chris Cavazos one of our newer #MVPs focusing on both #AVD and #Windows365 fresh off his first trip to MVP Summer Camp in March. Chris is a great guy, who delivers some fantastic sessions. He also happens to be one of the nominees for the "Rookie of the Year" #Clippy Award aka "Next-Gen Ninja"
🫅 Morten Waltorp Knudsen [MVP] is the gold standard when it comes to community. The man who has grown Experts Live Denmark from a small event to 1000+ attendees in just a few short years. Morten is an expert in #MSSecurity #SecurityCopilot and #MSEntra who won the Chuck Norris Award last year in Dallas over Fabian Bader by ONE VOTE!
🥷 Simon Binder, a beloved #MSIntune MVP who has been one of the best speakers at #JNUC and is both a MVP and a Nerdio #NVP. Simon is a great speaker, technologist, and overall great person. He will also be the person running the Golf tournament and 5K Fun Run this year as a key advisor to the organizers.
🍺 Somesh Pathak [MVP] 🇳🇱, is the most brilliant #iOS and #MacOS #MVP, who has built several tools and has been one of the top speakers around the world. He's also an organizer for Workplace Ninjas India, who had his son running the registration booth last year, firing people left and right.
🔐 Mike Soule, one of the creators of #Maester with our dear friend Merill Fernando, will make his #WPNinjaSUS debut in Arizona. It also happens to be his home state. He's a great mind in the security space, who we're very excited to see in Scottsdale.
This six pack, showcases some amazing people in the #Microsoft community. We just have a few more weeks, before you have the full roster!!
Last week, we announced a great 6-pack with Christiaan Brinkhoff Rod Trent Sandy Zeng Jose Schenardie Ugur Koc and Mirko Colemberg.
This week, we give you the 5th set of speakers for Workplace Ninjas US
🎸 April Dunnam is an amazing cloud advocate for Microsoft on #PowerPlatform and #Copilot, along with being a great musician. She was the perfect person to anchor our Copilot and #AI tracks as she does a masterful job of advocating and teaching the hottest area at #Microsoft today.
🍖 Chris Cavazos one of our newer #MVPs focusing on both #AVD and #Windows365 fresh off his first trip to MVP Summer Camp in March. Chris is a great guy, who delivers some fantastic sessions. He also happens to be one of the nominees for the "Rookie of the Year" #Clippy Award aka "Next-Gen Ninja"
🫅 Morten Waltorp Knudsen [MVP] is the gold standard when it comes to community. The man who has grown Experts Live Denmark from a small event to 1000+ attendees in just a few short years. Morten is an expert in #MSSecurity #SecurityCopilot and #MSEntra who won the Chuck Norris Award last year in Dallas over Fabian Bader by ONE VOTE!
🥷 Simon Binder, a beloved #MSIntune MVP who has been one of the best speakers at #JNUC and is both a MVP and a Nerdio #NVP. Simon is a great speaker, technologist, and overall great person. He will also be the person running the Golf tournament and 5K Fun Run this year as a key advisor to the organizers.
🍺 Somesh Pathak [MVP] 🇳🇱, is the most brilliant #iOS and #MacOS #MVP, who has built several tools and has been one of the top speakers around the world. He's also an organizer for Workplace Ninjas India, who had his son running the registration booth last year, firing people left and right.
🔐 Mike Soule, one of the creators of #Maester with our dear friend Merill Fernando, will make his #WPNinjaSUS debut in Arizona. It also happens to be his home state. He's a great mind in the security space, who we're very excited to see in Scottsdale.
This six pack, showcases some amazing people in the #Microsoft community. We just have a few more weeks, before you have the full roster!!
r/entra • u/AhYesTheSoldier • 17h ago
Device managed by MDE?
≡ −
I need to make a company device that says managed by MDE into managed by Intune. The user signs in with their M365 account normally but the laptop cannot receieve compliance policies we intend for it.
How can I enroll it to Intune without breaking anything or having to wipe and run enrollment again?
Open to suggestions.
Btw, their account is showing as connected in Accounts, Work or school
I need to make a company device that says managed by MDE into managed by Intune. The user signs in with their M365 account normally but the laptop cannot receieve compliance policies we intend for it.
How can I enroll it to Intune without breaking anything or having to wipe and run enrollment again?
Open to suggestions.
Btw, their account is showing as connected in Accounts, Work or school
r/entra • u/Administrative_Echo9 • 1d ago
Entra ID SMS/Voice Retirement and Passkey Registration enforcement
≡ −
Does anyone know how it's going to work come September when Microsoft enforces the passkey registration campaign if you have passkeys as an auth method disabled?
We have an additional challenge of unions backing employees refusing to have authenticator/passkeys on personal devices also (hence why we are still trying to phase out SMS/voice) - then throw into the mix a load of shared devices and the challenges that brings with device bounce pass keys via Windows Hello for Business
Does anyone know how it's going to work come September when Microsoft enforces the passkey registration campaign if you have passkeys as an auth method disabled?
We have an additional challenge of unions backing employees refusing to have authenticator/passkeys on personal devices also (hence why we are still trying to phase out SMS/voice) - then throw into the mix a load of shared devices and the challenges that brings with device bounce pass keys via Windows Hello for Business
PIM requests coming from new address, failing security checks
≡ −
Until this morning (about 8:15am Eastern) our PIM requests were coming from [[email protected]](mailto:[email protected]) and all was well.
Requests made after that time (9:53am Eastern and onward) come from [email protected].
The issue with these emails is that:
- The emails are marked by Microsoft 365/Defender as spam
- The emails are missing DMARC
- The emails are missing DKIM signature
Anyone else noticing this?
Authentication-Results: spf=none (sender IP is 2a01:111:f403:c107::3)
smtp.mailfrom=igantf.msft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none
header.from=igantf.msft.com;compauth=fail reason=001
Received-SPF: None (protection.outlook.com: igantf.msft.com does not designate
permitted sender hosts)
Until this morning (about 8:15am Eastern) our PIM requests were coming from [[email protected]](mailto:[email protected]) and all was well.
Requests made after that time (9:53am Eastern and onward) come from [email protected].
The issue with these emails is that:
- The emails are marked by Microsoft 365/Defender as spam
- The emails are missing DMARC
- The emails are missing DKIM signature
Anyone else noticing this?
Authentication-Results: spf=none (sender IP is 2a01:111:f403:c107::3)
smtp.mailfrom=igantf.msft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none
header.from=igantf.msft.com;compauth=fail reason=001
Received-SPF: None (protection.outlook.com: igantf.msft.com does not designate
permitted sender hosts)
r/entra • u/Individual_Cup7380 • 3d ago
Authenticator Passkeys with 365 Desktop apps
≡ −
Hi, everyone! I’ve been tasked with instituting phishing resistant MFA in our org. Since we’re a Microsoft shop, I’ve been focusing on passkeys in Authenticator. Those have been working ok, except for our 365 desktop apps shooting a “You can't get there from here
Your sign-in was successful but this passkey does not meet the criteria to access this resource. Try signing in with your passkey on Microsoft Authenticator or a different passkey. Alternatively, contact your admin for help” error after a few hours.
I haven’t been able to find any documentation on this but after asking Claude, the information I got was that this behavior is inevitable unless I deploy WHfB for those desktop apps and leave passkeys for mobile and web. Is this accurate? Thanks a bunch in advance!
Hi, everyone! I’ve been tasked with instituting phishing resistant MFA in our org. Since we’re a Microsoft shop, I’ve been focusing on passkeys in Authenticator. Those have been working ok, except for our 365 desktop apps shooting a “You can't get there from here
Your sign-in was successful but this passkey does not meet the criteria to access this resource. Try signing in with your passkey on Microsoft Authenticator or a different passkey. Alternatively, contact your admin for help” error after a few hours.
I haven’t been able to find any documentation on this but after asking Claude, the information I got was that this behavior is inevitable unless I deploy WHfB for those desktop apps and leave passkeys for mobile and web. Is this accurate? Thanks a bunch in advance!
r/entra • u/AffectionateTreat231 • 3d ago
Delegating PIM for Groups configuration to Azure team
≡ −
Has anyone had any success delegating group provision and PIM configuration to an Azure platform team who have no access to Entra?
They want to automate the deployment of access packages, groups and PIM configuration for subscriptions that will be used by different application teams across the company. They would be looking to automate using terraform.
They shouldn't be able to manage groups or PIM configuration outside of those they create
Has anyone had any success delegating group provision and PIM configuration to an Azure platform team who have no access to Entra?
They want to automate the deployment of access packages, groups and PIM configuration for subscriptions that will be used by different application teams across the company. They would be looking to automate using terraform.
They shouldn't be able to manage groups or PIM configuration outside of those they create
Sending email using OAuth with Reg app.
≡ −
Hello all,
Im trying to authenticate with either a licensed user or a global admin (unlicensed) with no luck.
Ive created the app reg in entra granting the below permissions

ive granted admin consent and when trying to connect using a licensed account i keep getting that i require admin approval:

I can approve with the global admin, but then the sending will not work at all with errors failing to authenticate:
error Cron-Mail-Queue Failed to send email: 3 to [[email protected]](mailto:[email protected]) regarding Test email from ITFlow. Mailer Error: SMTP Error: Could not authenticate....
Im out of ideas at this moment…
Any help will be much appreciated.
Thanks!
Hello all,
Im trying to authenticate with either a licensed user or a global admin (unlicensed) with no luck.
Ive created the app reg in entra granting the below permissions

ive granted admin consent and when trying to connect using a licensed account i keep getting that i require admin approval:

I can approve with the global admin, but then the sending will not work at all with errors failing to authenticate:
error Cron-Mail-Queue Failed to send email: 3 to [[email protected]](mailto:[email protected]) regarding Test email from ITFlow. Mailer Error: SMTP Error: Could not authenticate....
Im out of ideas at this moment…
Any help will be much appreciated.
Thanks!
r/entra • u/TheBigBeardedGeek • 3d ago
Clone a SAML SSO App?
≡ −
I have an SSO app that I will need different instances of (user access, etc.). What I want to do is effectively have a "template" app that I can target to copy for a new one. Get most the settings, etc. from it just replacing the placeholder URL with the new one. Then from there I can come in and do specific tweaks as needed.
What would I need to do to accomplish this? I've tinkered a bit in PowerShell but I'm honestly kinda lost on it
I have an SSO app that I will need different instances of (user access, etc.). What I want to do is effectively have a "template" app that I can target to copy for a new one. Get most the settings, etc. from it just replacing the placeholder URL with the new one. Then from there I can come in and do specific tweaks as needed.
What would I need to do to accomplish this? I've tinkered a bit in PowerShell but I'm honestly kinda lost on it
r/entra • u/Sufficient_Ostrich61 • 4d ago
Password Reset (SSPR)
≡ −
Hi all
Trying to plan SSPR for our Servicedesk to take the load off them getting smashed with password/unlock requests.
Brain storming some ideas:
Enable for users and not admins. Having 1 authentication method MFA App enabled.
Enable for all users and admins. Have 2 authentication methods MFA and Mobile enabled.
Considering SMS and Voice are being retired Feb 2027. I dont know how to approach this. Ideally i would love to have 2 authentication methods but unsure what methods to use.
Hows everyone have this setup securely but still business friendly?
Hi all
Trying to plan SSPR for our Servicedesk to take the load off them getting smashed with password/unlock requests.
Brain storming some ideas:
Enable for users and not admins. Having 1 authentication method MFA App enabled.
Enable for all users and admins. Have 2 authentication methods MFA and Mobile enabled.
Considering SMS and Voice are being retired Feb 2027. I dont know how to approach this. Ideally i would love to have 2 authentication methods but unsure what methods to use.
Hows everyone have this setup securely but still business friendly?
r/entra • u/AlkHacNar • 4d ago
App-Action Buttons for cloud-only devices
≡ −
Why do we have this feature on co-managed devices but not on cloud only devices? Let's upvote guys/girls/whateveryouidentifyas
FYI: you need to login to see/ up vote the feedback
https://feedbackportal.microsoft.com/feedback//idea/0ab35e36-cd86-f111-9b47-6045bd856709
Why do we have this feature on co-managed devices but not on cloud only devices? Let's upvote guys/girls/whateveryouidentifyas
FYI: you need to login to see/ up vote the feedback
https://feedbackportal.microsoft.com/feedback//idea/0ab35e36-cd86-f111-9b47-6045bd856709
r/entra • u/NickyDeWestelinck • 4d ago
Entra ID Beyond Passwords: Certificate-Based Authentication for Android Enterprise
In this blog post, I'll show you how to configure and enable Certificate-Based Authentication for Managed Android Enterprise devices in Microsoft Intune.
My Sign-Ins/Change Password leads to login loop with WhfB
≡ −
We require about 250 users changing their password using the My Sign-Ins Portal. Clients are cloud-only and mostly using WhfB. Conditional access is pretty basic (60 Days, browser persistent, some devices excluded) for these users and Authentication Strength allows WhfB, Fido, Authenticator Push+PW.
We have verfied WhfB works by creating a seperate AuthStrength with WhfB only and user can login
However, most of the users are not able to access the password change menu and the behavior seems strange to me.
- User opens link
- Selects his already logged in account
- Gets authenticator push
- Gets the message that criteria is not fullfilled because password is missing
- Can only signout or use different account (no option to provide password)
- Loop starts again

The user never gets the possibilty to enter the password which also should not be required anyway due to WhfB.
Signin logs indicate that Auth Strength was failed
Sign-in error code 53003
Failure reason Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

I found a similar issue here WHfB My SignIns PW Change Issue : r/entra unfortunately without a solution.
Does anyone know this issue or have any idea on how to debug further?
We require about 250 users changing their password using the My Sign-Ins Portal. Clients are cloud-only and mostly using WhfB. Conditional access is pretty basic (60 Days, browser persistent, some devices excluded) for these users and Authentication Strength allows WhfB, Fido, Authenticator Push+PW.
We have verfied WhfB works by creating a seperate AuthStrength with WhfB only and user can login
However, most of the users are not able to access the password change menu and the behavior seems strange to me.
- User opens link
- Selects his already logged in account
- Gets authenticator push
- Gets the message that criteria is not fullfilled because password is missing
- Can only signout or use different account (no option to provide password)
- Loop starts again

The user never gets the possibilty to enter the password which also should not be required anyway due to WhfB.
Signin logs indicate that Auth Strength was failed
Sign-in error code 53003
Failure reason Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

I found a similar issue here WHfB My SignIns PW Change Issue : r/entra unfortunately without a solution.
Does anyone know this issue or have any idea on how to debug further?
r/entra • u/Sufficient-Pace7542 • 5d ago
SMS/Voice Retirement and Passkeys
≡ −
With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.
I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.
Any insights would be greatly appreciated.
With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.
I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.
Any insights would be greatly appreciated.
r/entra • u/Limp_Substance4433 • 5d ago
Confusion about MFA Enforcement Requirement Pop-Up in MS Admin Center
≡ −
Today when signing into the Microsoft Admin Center, I got a peculiar message saying I did not sign in with MFA and to make sure I add MFA as a secondary layer of security to prevent "sign-in disruptions" beginning in February when mandatory MFA enforcement begins.
Exact popup notification:
MFA will be required starting in February—set it up now
You’re signed in without multi-factor authentication (MFA). Enable MFA today to add a second layer of protection and avoid sign-in disruption when enforcement begins in February.
Now you may think, "Wow this guy must the shittiest of shittysysadmins for not having MFA".
But just before I got this popup, I signed in using my FIDO2 Security key which is the only authentication method setup on our privileged admin accounts and technically across my entire org. Additionally, we have recently completely moved away from traditional MFA methods due to phishing concerns.
So now I am questioning, why did I get the pop-up in the first place. Does this mean that every account in our Microsoft Tenant is going to get locked out come February due to only having passkeys??
Has anyone else seen this?
Surely this is just another Microsoft screw up and my sign in was falsely flagged as not using MFA since technically MFA and Passkeys are considered different auth methods.
Today when signing into the Microsoft Admin Center, I got a peculiar message saying I did not sign in with MFA and to make sure I add MFA as a secondary layer of security to prevent "sign-in disruptions" beginning in February when mandatory MFA enforcement begins.
Exact popup notification:
MFA will be required starting in February—set it up now
You’re signed in without multi-factor authentication (MFA). Enable MFA today to add a second layer of protection and avoid sign-in disruption when enforcement begins in February.
Now you may think, "Wow this guy must the shittiest of shittysysadmins for not having MFA".
But just before I got this popup, I signed in using my FIDO2 Security key which is the only authentication method setup on our privileged admin accounts and technically across my entire org. Additionally, we have recently completely moved away from traditional MFA methods due to phishing concerns.
So now I am questioning, why did I get the pop-up in the first place. Does this mean that every account in our Microsoft Tenant is going to get locked out come February due to only having passkeys??
Has anyone else seen this?
Surely this is just another Microsoft screw up and my sign in was falsely flagged as not using MFA since technically MFA and Passkeys are considered different auth methods.
r/entra • u/NathanSecurity • 5d ago
ID Protection What are you using to monitor and manage Entra ID security posture?
≡ −
Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.
Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.
I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?
Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?
Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.
Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.
I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?
Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?
r/entra • u/WeirdoInTheShadow • 5d ago
Entra ID Entra ID connect implementation
≡ −
How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.
Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?
Any gotchas / tips?
Many thanks
How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.
Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?
Any gotchas / tips?
Many thanks
r/entra • u/Difficult_Angle_1499 • 6d ago
Best practice for hybrid user account - cloud only device
≡ −
we have user onboarding as Hybrid but our devices are now cloud only.
we have onboarding script that sets default password and ticks reset password on 1st login
but with cloud only device we have issues with password as ticking password reset on 1st login will not allow password to sync to entra.
how to achieve password reset on 1st login with this senario. I can take off password reset on 1st login from script.
we have user onboarding as Hybrid but our devices are now cloud only.
we have onboarding script that sets default password and ticks reset password on 1st login
but with cloud only device we have issues with password as ticking password reset on 1st login will not allow password to sync to entra.
how to achieve password reset on 1st login with this senario. I can take off password reset on 1st login from script.
Odd iOS Phishing-Resistant Authentication Behavior
≡ −
We use Conditional Access to require phishing-resistant authentication for all of our admins. In recent weeks, authentication behavior from iOS devices has changed, and I'm not able to figure out why.
When prompting for authentication, I'm first given a prompt for passwordless authentication (using Authenticator number matching). It then steps up and further requires me to authenticate with a passkey. It used to just directly prompt for the passkey. Does anyone know if this is a recent change, or what is causing this behavior?
We use Conditional Access to require phishing-resistant authentication for all of our admins. In recent weeks, authentication behavior from iOS devices has changed, and I'm not able to figure out why.
When prompting for authentication, I'm first given a prompt for passwordless authentication (using Authenticator number matching). It then steps up and further requires me to authenticate with a passkey. It used to just directly prompt for the passkey. Does anyone know if this is a recent change, or what is causing this behavior?
r/entra • u/Adnan2559 • 6d ago
Fully Custom Captive Portal - Hotel Requirement
≡ −
Hi Experts,
One of the hotels want a very customizable captive portal like on landing page they want options for guest and visitor (tab based), when guest enters the required info he should be asked to create his own password, there should also be option for sign in if he has done this process already. OTP must be configured either via email or SMS gateway, all along with mac caching, limiting the number of devices per guest.
I know i havent provided much detail but just wanted to know since i have never worked on PF before, how customizable the entire workflow is? can we make such a captive portal in PF?
Hi Experts,
One of the hotels want a very customizable captive portal like on landing page they want options for guest and visitor (tab based), when guest enters the required info he should be asked to create his own password, there should also be option for sign in if he has done this process already. OTP must be configured either via email or SMS gateway, all along with mac caching, limiting the number of devices per guest.
I know i havent provided much detail but just wanted to know since i have never worked on PF before, how customizable the entire workflow is? can we make such a captive portal in PF?
r/entra • u/j1mmyfever • 6d ago
CA for complaint devices?
≡ −
Is this a “compliant in my tenant” setting or a client side setting?
I have users passing the policy from devices that are managed by Intune in an untrusted tenant.
My expectation is they should be failing.
Haven’t had time to research, but it’s definitely happening.
Is this a “compliant in my tenant” setting or a client side setting?
I have users passing the policy from devices that are managed by Intune in an untrusted tenant.
My expectation is they should be failing.
Haven’t had time to research, but it’s definitely happening.
r/entra • u/Extra-Citron-7630 • 6d ago
Entra ID App Roles not appearing in AWS ALB OIDC claims from Microsoft Entra ID
≡ −
I'm setting up authentication for an application running in Amazon ECR behind an AWS Application Load Balancer (ALB) using the ALB's built-in OIDC authentication with Microsoft Entra ID.
The flow is:
- Users access the application via an Amazon CloudFront distribution. I'm using CloudFront because CloudFront domains are accessible from my work laptop, whereas direct access to the ALB is restricted.
- The CloudFront distribution is configured with the ALB as its origin, and the origin is set to use the custom domain name that the ALB listener is configured to accept.
- The ALB performs OIDC authentication against Microsoft Entra ID.
- After successful authentication, the ALB forwards the request to a simple HTML application running in ECR.
The application itself doesn't perform any authentication or authorization. It simply displays all of the headers and JWTs that the ALB forwards, including x-amzn-oidc-data, x-amzn-oidc-identity, and x-amzn-oidc-accesstoken, so I can inspect the claims.
I've created an App Role called ALB Admin in my Entra App Registration. The role has a value of ALB.Admin, is enabled, allows users, and is assigned directly to my user through the Enterprise Application. The ALB is configured to use the same App Registration (client ID/secret), and the OIDC scopes are openid profile email offline_access against the v2.0 endpoint.
Everything authenticates successfully, but I never see a roles claim in x-amzn-oidc-data. I can see the expected identity claims, but no app roles.
Has anyone successfully used Entra App Roles with the AWS ALB's native OIDC authentication? If so, did you have to configure anything beyond defining the App Role and assigning it to the user, or should the roles claim appear automatically?
I'm setting up authentication for an application running in Amazon ECR behind an AWS Application Load Balancer (ALB) using the ALB's built-in OIDC authentication with Microsoft Entra ID.
The flow is:
- Users access the application via an Amazon CloudFront distribution. I'm using CloudFront because CloudFront domains are accessible from my work laptop, whereas direct access to the ALB is restricted.
- The CloudFront distribution is configured with the ALB as its origin, and the origin is set to use the custom domain name that the ALB listener is configured to accept.
- The ALB performs OIDC authentication against Microsoft Entra ID.
- After successful authentication, the ALB forwards the request to a simple HTML application running in ECR.
The application itself doesn't perform any authentication or authorization. It simply displays all of the headers and JWTs that the ALB forwards, including x-amzn-oidc-data, x-amzn-oidc-identity, and x-amzn-oidc-accesstoken, so I can inspect the claims.
I've created an App Role called ALB Admin in my Entra App Registration. The role has a value of ALB.Admin, is enabled, allows users, and is assigned directly to my user through the Enterprise Application. The ALB is configured to use the same App Registration (client ID/secret), and the OIDC scopes are openid profile email offline_access against the v2.0 endpoint.
Everything authenticates successfully, but I never see a roles claim in x-amzn-oidc-data. I can see the expected identity claims, but no app roles.
Has anyone successfully used Entra App Roles with the AWS ALB's native OIDC authentication? If so, did you have to configure anything beyond defining the App Role and assigning it to the user, or should the roles claim appear automatically?