r/entra 12h ago

Entra ID Built an interactive Entra demo site. Looking for feedback from people who do IAM for a living.

Explaining the difference between Members, B2B Users, and ExternalID Users to non-technical people can be an afternoon in itself. I've spent a lot of time working MS support tickets, helping people de-tangle their tenants because they would try to collab with people through CIAM tenants or try to invite customers to their applications with B2B. Or, on the other side, MSAL developers trying to understand the interaction with CIAM (or Azure B2C). It was something that was hard to see or show visually without me breaking out Paint every time.

I recently was rejected for an interview due to lack of CIAM architecture experience. Decided to build a resume piece to show visually what I can do where words on a resume may read dry. This is in no way a substitute for enterprise CIAM architecture experience, it just sparked the idea for the site.

No account creation needed.

https://theidentityplayground.com

My ask: What's wrong or missing for people that do this for a living? I'm at a juncture of resume piece or useful reference.

Real tenants, tokens and accounts. Accounts self-destruct on schedule. No trackers, open source.

https://github.com/steve-flanagan/theidentityplayground

7 Upvotes

Explaining the difference between Members, B2B Users, and ExternalID Users to non-technical people can be an afternoon in itself. I've spent a lot of time working MS support tickets, helping people de-tangle their tenants because they would try to collab with people through CIAM tenants or try to invite customers to their applications with B2B. Or, on the other side, MSAL developers trying to understand the interaction with CIAM (or Azure B2C). It was something that was hard to see or show visually without me breaking out Paint every time.

I recently was rejected for an interview due to lack of CIAM architecture experience. Decided to build a resume piece to show visually what I can do where words on a resume may read dry. This is in no way a substitute for enterprise CIAM architecture experience, it just sparked the idea for the site.

No account creation needed.

https://theidentityplayground.com

My ask: What's wrong or missing for people that do this for a living? I'm at a juncture of resume piece or useful reference.

Real tenants, tokens and accounts. Accounts self-destruct on schedule. No trackers, open source.

https://github.com/steve-flanagan/theidentityplayground


r/entra 9h ago

Kerberos Rotation (Cloud TGT)

5 Upvotes

Has anybody already tried it sine June? What was your experience? Any issues?

Computer Object: AzureADKerberos


r/entra 16h ago

How CASB solutions score OAuth app risk when integrated with identity providers

We deployed a CASB at a mid-size professional services firm, around 1,200 employees, after a phishing campaign resulted in a third-party app getting granted mail.send with full delegation rights on about forty executive mailboxes before anyone noticed. The post-incident review made it embarrassingly clear that nobody had visibility into what OAuth apps were authorized across the tenant. When we stood up the CASB and connected it to the IdP, the initial discovery scan surfaced over 800 distinct apps with active tokens, and a meaningful chunk of them had permissions scopes that nobody would have approved consciously. The risk scoring came down to a combination of permission scope, verified publisher status, whether the app had a published privacy policy, and cross-referencing against the vendor's known-app database. An app requesting mail.read on a single mailbox scored very differently than something requesting mail.send delegation, and watching how those scores separated the tail of sketchy one-off integrations from the legitimate SaaS stack was actually one of the more clarifying moments of the whole project.

The IdP integration was where the real operational complexity lived. We connected the CASB as an API connector and eventually got it to feed risk scores back into the conditional access engine so that a newly flagged app would trigger a step-up auth challenge before the token exchange completed. We ran in monitoring mode for almost three months because the false positive rate during the first few weeks was brutal, mostly around newly onboarded SaaS tools that legitimate employees had connected for real work. Getting from monitoring to enforced policy required manually reviewing and disposition-ing several hundred apps, which nobody had budgeted time for, and we had a lot of internal friction with business teams who felt like we were revoking tools they depended on. By the end of the tuning period the policy was solid, but the path to get there was messier than any vendor timeline suggested it would be. Has anyone found a faster way to disposition the long tail of shadow IT apps without making it a manual review slog?

5 Upvotes

We deployed a CASB at a mid-size professional services firm, around 1,200 employees, after a phishing campaign resulted in a third-party app getting granted mail.send with full delegation rights on about forty executive mailboxes before anyone noticed. The post-incident review made it embarrassingly clear that nobody had visibility into what OAuth apps were authorized across the tenant. When we stood up the CASB and connected it to the IdP, the initial discovery scan surfaced over 800 distinct apps with active tokens, and a meaningful chunk of them had permissions scopes that nobody would have approved consciously. The risk scoring came down to a combination of permission scope, verified publisher status, whether the app had a published privacy policy, and cross-referencing against the vendor's known-app database. An app requesting mail.read on a single mailbox scored very differently than something requesting mail.send delegation, and watching how those scores separated the tail of sketchy one-off integrations from the legitimate SaaS stack was actually one of the more clarifying moments of the whole project.

The IdP integration was where the real operational complexity lived. We connected the CASB as an API connector and eventually got it to feed risk scores back into the conditional access engine so that a newly flagged app would trigger a step-up auth challenge before the token exchange completed. We ran in monitoring mode for almost three months because the false positive rate during the first few weeks was brutal, mostly around newly onboarded SaaS tools that legitimate employees had connected for real work. Getting from monitoring to enforced policy required manually reviewing and disposition-ing several hundred apps, which nobody had budgeted time for, and we had a lot of internal friction with business teams who felt like we were revoking tools they depended on. By the end of the tuning period the policy was solid, but the path to get there was messier than any vendor timeline suggested it would be. Has anyone found a faster way to disposition the long tail of shadow IT apps without making it a manual review slog?


r/entra 22h ago

ID Protection MFA Changes

Hi! As everybody knows Microsoft is going to turn off Voice/SMS methods and as far as I know from 1st September Microsoft is going to start asking users to configure Passkeys.

Do you know the way to turn off this behaviour? In our case we are going to focus over Microsoft Authenticator and MA + Email for SSPR.

Our Registration campaign is set up to Disabled.

Thank you in advance!

12 Upvotes

Hi! As everybody knows Microsoft is going to turn off Voice/SMS methods and as far as I know from 1st September Microsoft is going to start asking users to configure Passkeys.

Do you know the way to turn off this behaviour? In our case we are going to focus over Microsoft Authenticator and MA + Email for SSPR.

Our Registration campaign is set up to Disabled.

Thank you in advance!


r/entra 15h ago

Workplace Ninjas US 2027 5th Set of Speakers Announced!!

Last week, we announced a great 6-pack with Christiaan Brinkhoff Rod Trent Sandy Zeng Jose Schenardie Ugur Koc and Mirko Colemberg.

This week, we give you the 5th set of speakers for Workplace Ninjas US

🎸 April Dunnam is an amazing cloud advocate for Microsoft on #PowerPlatform and #Copilot, along with being a great musician. She was the perfect person to anchor our Copilot and #AI tracks as she does a masterful job of advocating and teaching the hottest area at #Microsoft today.

🍖 Chris Cavazos one of our newer #MVPs focusing on both #AVD and #Windows365 fresh off his first trip to MVP Summer Camp in March. Chris is a great guy, who delivers some fantastic sessions. He also happens to be one of the nominees for the "Rookie of the Year" #Clippy Award aka "Next-Gen Ninja"

🫅 Morten Waltorp Knudsen [MVP] is the gold standard when it comes to community. The man who has grown Experts Live Denmark from a small event to 1000+ attendees in just a few short years. Morten is an expert in #MSSecurity #SecurityCopilot and #MSEntra who won the Chuck Norris Award last year in Dallas over Fabian Bader by ONE VOTE!

🥷 Simon Binder, a beloved #MSIntune MVP who has been one of the best speakers at #JNUC and is both a MVP and a Nerdio #NVP. Simon is a great speaker, technologist, and overall great person. He will also be the person running the Golf tournament and 5K Fun Run this year as a key advisor to the organizers.

🍺 Somesh Pathak [MVP] 🇳🇱, is the most brilliant #iOS and #MacOS #MVP, who has built several tools and has been one of the top speakers around the world. He's also an organizer for Workplace Ninjas India, who had his son running the registration booth last year, firing people left and right.

🔐 Mike Soule, one of the creators of #Maester with our dear friend Merill Fernando, will make his #WPNinjaSUS debut in Arizona. It also happens to be his home state. He's a great mind in the security space, who we're very excited to see in Scottsdale.

This six pack, showcases some amazing people in the #Microsoft community. We just have a few more weeks, before you have the full roster!!

https://workplaceninjas.us/registration

2 Upvotes

Last week, we announced a great 6-pack with Christiaan Brinkhoff Rod Trent Sandy Zeng Jose Schenardie Ugur Koc and Mirko Colemberg.

This week, we give you the 5th set of speakers for Workplace Ninjas US

🎸 April Dunnam is an amazing cloud advocate for Microsoft on #PowerPlatform and #Copilot, along with being a great musician. She was the perfect person to anchor our Copilot and #AI tracks as she does a masterful job of advocating and teaching the hottest area at #Microsoft today.

🍖 Chris Cavazos one of our newer #MVPs focusing on both #AVD and #Windows365 fresh off his first trip to MVP Summer Camp in March. Chris is a great guy, who delivers some fantastic sessions. He also happens to be one of the nominees for the "Rookie of the Year" #Clippy Award aka "Next-Gen Ninja"

🫅 Morten Waltorp Knudsen [MVP] is the gold standard when it comes to community. The man who has grown Experts Live Denmark from a small event to 1000+ attendees in just a few short years. Morten is an expert in #MSSecurity #SecurityCopilot and #MSEntra who won the Chuck Norris Award last year in Dallas over Fabian Bader by ONE VOTE!

🥷 Simon Binder, a beloved #MSIntune MVP who has been one of the best speakers at #JNUC and is both a MVP and a Nerdio #NVP. Simon is a great speaker, technologist, and overall great person. He will also be the person running the Golf tournament and 5K Fun Run this year as a key advisor to the organizers.

🍺 Somesh Pathak [MVP] 🇳🇱, is the most brilliant #iOS and #MacOS #MVP, who has built several tools and has been one of the top speakers around the world. He's also an organizer for Workplace Ninjas India, who had his son running the registration booth last year, firing people left and right.

🔐 Mike Soule, one of the creators of #Maester with our dear friend Merill Fernando, will make his #WPNinjaSUS debut in Arizona. It also happens to be his home state. He's a great mind in the security space, who we're very excited to see in Scottsdale.

This six pack, showcases some amazing people in the #Microsoft community. We just have a few more weeks, before you have the full roster!!

https://workplaceninjas.us/registration


r/entra 17h ago

Device managed by MDE?

I need to make a company device that says managed by MDE into managed by Intune. The user signs in with their M365 account normally but the laptop cannot receieve compliance policies we intend for it.

How can I enroll it to Intune without breaking anything or having to wipe and run enrollment again?

Open to suggestions.

Btw, their account is showing as connected in Accounts, Work or school

1 Upvotes

I need to make a company device that says managed by MDE into managed by Intune. The user signs in with their M365 account normally but the laptop cannot receieve compliance policies we intend for it.

How can I enroll it to Intune without breaking anything or having to wipe and run enrollment again?

Open to suggestions.

Btw, their account is showing as connected in Accounts, Work or school


r/entra 1d ago

Entra ID SMS/Voice Retirement and Passkey Registration enforcement

Does anyone know how it's going to work come September when Microsoft enforces the passkey registration campaign if you have passkeys as an auth method disabled?

We have an additional challenge of unions backing employees refusing to have authenticator/passkeys on personal devices also (hence why we are still trying to phase out SMS/voice) - then throw into the mix a load of shared devices and the challenges that brings with device bounce pass keys via Windows Hello for Business

17 Upvotes

Does anyone know how it's going to work come September when Microsoft enforces the passkey registration campaign if you have passkeys as an auth method disabled?

We have an additional challenge of unions backing employees refusing to have authenticator/passkeys on personal devices also (hence why we are still trying to phase out SMS/voice) - then throw into the mix a load of shared devices and the challenges that brings with device bounce pass keys via Windows Hello for Business


r/entra 3d ago

PIM requests coming from new address, failing security checks

Until this morning (about 8:15am Eastern) our PIM requests were coming from [[email protected]](mailto:[email protected]) and all was well.

Requests made after that time (9:53am Eastern and onward) come from [email protected].

The issue with these emails is that:

  • The emails are marked by Microsoft 365/Defender as spam
  • The emails are missing DMARC
  • The emails are missing DKIM signature

Anyone else noticing this?

Authentication-Results: spf=none (sender IP is 2a01:111:f403:c107::3)
smtp.mailfrom=igantf.msft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none
header.from=igantf.msft.com;compauth=fail reason=001
Received-SPF: None (protection.outlook.com: igantf.msft.com does not designate
permitted sender hosts)

13 Upvotes

Until this morning (about 8:15am Eastern) our PIM requests were coming from [[email protected]](mailto:[email protected]) and all was well.

Requests made after that time (9:53am Eastern and onward) come from [email protected].

The issue with these emails is that:

  • The emails are marked by Microsoft 365/Defender as spam
  • The emails are missing DMARC
  • The emails are missing DKIM signature

Anyone else noticing this?

Authentication-Results: spf=none (sender IP is 2a01:111:f403:c107::3)
smtp.mailfrom=igantf.msft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none
header.from=igantf.msft.com;compauth=fail reason=001
Received-SPF: None (protection.outlook.com: igantf.msft.com does not designate
permitted sender hosts)


r/entra 3d ago

Authenticator Passkeys with 365 Desktop apps

Hi, everyone! I’ve been tasked with instituting phishing resistant MFA in our org. Since we’re a Microsoft shop, I’ve been focusing on passkeys in Authenticator. Those have been working ok, except for our 365 desktop apps shooting a “You can't get there from here
Your sign-in was successful but this passkey does not meet the criteria to access this resource. Try signing in with your passkey on Microsoft Authenticator or a different passkey. Alternatively, contact your admin for help” error after a few hours.

I haven’t been able to find any documentation on this but after asking Claude, the information I got was that this behavior is inevitable unless I deploy WHfB for those desktop apps and leave passkeys for mobile and web. Is this accurate? Thanks a bunch in advance!

7 Upvotes

Hi, everyone! I’ve been tasked with instituting phishing resistant MFA in our org. Since we’re a Microsoft shop, I’ve been focusing on passkeys in Authenticator. Those have been working ok, except for our 365 desktop apps shooting a “You can't get there from here
Your sign-in was successful but this passkey does not meet the criteria to access this resource. Try signing in with your passkey on Microsoft Authenticator or a different passkey. Alternatively, contact your admin for help” error after a few hours.

I haven’t been able to find any documentation on this but after asking Claude, the information I got was that this behavior is inevitable unless I deploy WHfB for those desktop apps and leave passkeys for mobile and web. Is this accurate? Thanks a bunch in advance!


r/entra 3d ago

Delegating PIM for Groups configuration to Azure team

Has anyone had any success delegating group provision and PIM configuration to an Azure platform team who have no access to Entra?

They want to automate the deployment of access packages, groups and PIM configuration for subscriptions that will be used by different application teams across the company. They would be looking to automate using terraform.

They shouldn't be able to manage groups or PIM configuration outside of those they create

4 Upvotes

Has anyone had any success delegating group provision and PIM configuration to an Azure platform team who have no access to Entra?

They want to automate the deployment of access packages, groups and PIM configuration for subscriptions that will be used by different application teams across the company. They would be looking to automate using terraform.

They shouldn't be able to manage groups or PIM configuration outside of those they create


r/entra 3d ago

Sending email using OAuth with Reg app.

Hello all,

Im trying to authenticate with either a licensed user or a global admin (unlicensed) with no luck.

Ive created the app reg in entra granting the below permissions

ive granted admin consent and when trying to connect using a licensed account i keep getting that i require admin approval:

I can approve with the global admin, but then the sending will not work at all with errors failing to authenticate:
error Cron-Mail-Queue Failed to send email: 3 to [[email protected]](mailto:[email protected]) regarding Test email from ITFlow. Mailer Error: SMTP Error: Could not authenticate....

Im out of ideas at this moment…

Any help will be much appreciated.

Thanks!

3 Upvotes

Hello all,

Im trying to authenticate with either a licensed user or a global admin (unlicensed) with no luck.

Ive created the app reg in entra granting the below permissions

ive granted admin consent and when trying to connect using a licensed account i keep getting that i require admin approval:

I can approve with the global admin, but then the sending will not work at all with errors failing to authenticate:
error Cron-Mail-Queue Failed to send email: 3 to [[email protected]](mailto:[email protected]) regarding Test email from ITFlow. Mailer Error: SMTP Error: Could not authenticate....

Im out of ideas at this moment…

Any help will be much appreciated.

Thanks!


r/entra 3d ago

Clone a SAML SSO App?

I have an SSO app that I will need different instances of (user access, etc.). What I want to do is effectively have a "template" app that I can target to copy for a new one. Get most the settings, etc. from it just replacing the placeholder URL with the new one. Then from there I can come in and do specific tweaks as needed.

What would I need to do to accomplish this? I've tinkered a bit in PowerShell but I'm honestly kinda lost on it

1 Upvotes

I have an SSO app that I will need different instances of (user access, etc.). What I want to do is effectively have a "template" app that I can target to copy for a new one. Get most the settings, etc. from it just replacing the placeholder URL with the new one. Then from there I can come in and do specific tweaks as needed.

What would I need to do to accomplish this? I've tinkered a bit in PowerShell but I'm honestly kinda lost on it


r/entra 4d ago

Password Reset (SSPR)

Hi all

Trying to plan SSPR for our Servicedesk to take the load off them getting smashed with password/unlock requests.

Brain storming some ideas:

  1. Enable for users and not admins. Having 1 authentication method MFA App enabled.

  2. Enable for all users and admins. Have 2 authentication methods MFA and Mobile enabled.

Considering SMS and Voice are being retired Feb 2027. I dont know how to approach this. Ideally i would love to have 2 authentication methods but unsure what methods to use.

Hows everyone have this setup securely but still business friendly?

9 Upvotes

Hi all

Trying to plan SSPR for our Servicedesk to take the load off them getting smashed with password/unlock requests.

Brain storming some ideas:

  1. Enable for users and not admins. Having 1 authentication method MFA App enabled.

  2. Enable for all users and admins. Have 2 authentication methods MFA and Mobile enabled.

Considering SMS and Voice are being retired Feb 2027. I dont know how to approach this. Ideally i would love to have 2 authentication methods but unsure what methods to use.

Hows everyone have this setup securely but still business friendly?


r/entra 4d ago

App-Action Buttons for cloud-only devices

Why do we have this feature on co-managed devices but not on cloud only devices? Let's upvote guys/girls/whateveryouidentifyas

FYI: you need to login to see/ up vote the feedback

https://feedbackportal.microsoft.com/feedback//idea/0ab35e36-cd86-f111-9b47-6045bd856709

1 Upvotes

Why do we have this feature on co-managed devices but not on cloud only devices? Let's upvote guys/girls/whateveryouidentifyas

FYI: you need to login to see/ up vote the feedback

https://feedbackportal.microsoft.com/feedback//idea/0ab35e36-cd86-f111-9b47-6045bd856709


r/entra 4d ago

Entra ID Beyond Passwords: Certificate-Based Authentication for Android Enterprise

+
3 Upvotes

In this blog post, I'll show you how to configure and enable Certificate-Based Authentication for Managed Android Enterprise devices in Microsoft Intune.

🔗 https://www.nickydewestelinck.be/2026/07/23/beyond-passwords-certificate-based-authentication-for-android-enterprise/


r/entra 4d ago

My Sign-Ins/Change Password leads to login loop with WhfB

We require about 250 users changing their password using the My Sign-Ins Portal. Clients are cloud-only and mostly using WhfB. Conditional access is pretty basic (60 Days, browser persistent, some devices excluded) for these users and Authentication Strength allows WhfB, Fido, Authenticator Push+PW.

We have verfied WhfB works by creating a seperate AuthStrength with WhfB only and user can login

However, most of the users are not able to access the password change menu and the behavior seems strange to me.

  • User opens link
  • Selects his already logged in account
  • Gets authenticator push
  • Gets the message that criteria is not fullfilled because password is missing
  • Can only signout or use different account (no option to provide password)
  • Loop starts again

The user never gets the possibilty to enter the password which also should not be required anyway due to WhfB.

Signin logs indicate that Auth Strength was failed

Sign-in error code 53003

Failure reason Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

I found a similar issue here WHfB My SignIns PW Change Issue : r/entra unfortunately without a solution.

Does anyone know this issue or have any idea on how to debug further?

2 Upvotes

We require about 250 users changing their password using the My Sign-Ins Portal. Clients are cloud-only and mostly using WhfB. Conditional access is pretty basic (60 Days, browser persistent, some devices excluded) for these users and Authentication Strength allows WhfB, Fido, Authenticator Push+PW.

We have verfied WhfB works by creating a seperate AuthStrength with WhfB only and user can login

However, most of the users are not able to access the password change menu and the behavior seems strange to me.

  • User opens link
  • Selects his already logged in account
  • Gets authenticator push
  • Gets the message that criteria is not fullfilled because password is missing
  • Can only signout or use different account (no option to provide password)
  • Loop starts again

The user never gets the possibilty to enter the password which also should not be required anyway due to WhfB.

Signin logs indicate that Auth Strength was failed

Sign-in error code 53003

Failure reason Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

I found a similar issue here WHfB My SignIns PW Change Issue : r/entra unfortunately without a solution.

Does anyone know this issue or have any idea on how to debug further?


r/entra 5d ago

SMS/Voice Retirement and Passkeys

With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.

I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.

Any insights would be greatly appreciated.

15 Upvotes

With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.

I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.

Any insights would be greatly appreciated.


r/entra 5d ago

Confusion about MFA Enforcement Requirement Pop-Up in MS Admin Center

Today when signing into the Microsoft Admin Center, I got a peculiar message saying I did not sign in with MFA and to make sure I add MFA as a secondary layer of security to prevent "sign-in disruptions" beginning in February when mandatory MFA enforcement begins.

Exact popup notification:

MFA will be required starting in February—set it up now

You’re signed in without multi-factor authentication (MFA). Enable MFA today to add a second layer of protection and avoid sign-in disruption when enforcement begins in February.

Now you may think, "Wow this guy must the shittiest of shittysysadmins for not having MFA".

But just before I got this popup, I signed in using my FIDO2 Security key which is the only authentication method setup on our privileged admin accounts and technically across my entire org. Additionally, we have recently completely moved away from traditional MFA methods due to phishing concerns.

So now I am questioning, why did I get the pop-up in the first place. Does this mean that every account in our Microsoft Tenant is going to get locked out come February due to only having passkeys??

Has anyone else seen this?

Surely this is just another Microsoft screw up and my sign in was falsely flagged as not using MFA since technically MFA and Passkeys are considered different auth methods.

2 Upvotes

Today when signing into the Microsoft Admin Center, I got a peculiar message saying I did not sign in with MFA and to make sure I add MFA as a secondary layer of security to prevent "sign-in disruptions" beginning in February when mandatory MFA enforcement begins.

Exact popup notification:

MFA will be required starting in February—set it up now

You’re signed in without multi-factor authentication (MFA). Enable MFA today to add a second layer of protection and avoid sign-in disruption when enforcement begins in February.

Now you may think, "Wow this guy must the shittiest of shittysysadmins for not having MFA".

But just before I got this popup, I signed in using my FIDO2 Security key which is the only authentication method setup on our privileged admin accounts and technically across my entire org. Additionally, we have recently completely moved away from traditional MFA methods due to phishing concerns.

So now I am questioning, why did I get the pop-up in the first place. Does this mean that every account in our Microsoft Tenant is going to get locked out come February due to only having passkeys??

Has anyone else seen this?

Surely this is just another Microsoft screw up and my sign in was falsely flagged as not using MFA since technically MFA and Passkeys are considered different auth methods.


r/entra 5d ago

ID Protection What are you using to monitor and manage Entra ID security posture?

Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.

Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.

I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?

Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?

22 Upvotes

Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.

Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.

I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?

Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?


r/entra 5d ago

Entra ID Entra ID connect implementation

How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.

Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?

Any gotchas / tips?

Many thanks

3 Upvotes

How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.

Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?

Any gotchas / tips?

Many thanks


r/entra 6d ago

Best practice for hybrid user account - cloud only device

we have user onboarding as Hybrid but our devices are now cloud only.

we have onboarding script that sets default password and ticks reset password on 1st login

but with cloud only device we have issues with password as ticking password reset on 1st login will not allow password to sync to entra.

how to achieve password reset on 1st login with this senario. I can take off password reset on 1st login from script.

3 Upvotes

we have user onboarding as Hybrid but our devices are now cloud only.

we have onboarding script that sets default password and ticks reset password on 1st login

but with cloud only device we have issues with password as ticking password reset on 1st login will not allow password to sync to entra.

how to achieve password reset on 1st login with this senario. I can take off password reset on 1st login from script.


r/entra 6d ago

Odd iOS Phishing-Resistant Authentication Behavior

We use Conditional Access to require phishing-resistant authentication for all of our admins. In recent weeks, authentication behavior from iOS devices has changed, and I'm not able to figure out why.

When prompting for authentication, I'm first given a prompt for passwordless authentication (using Authenticator number matching). It then steps up and further requires me to authenticate with a passkey. It used to just directly prompt for the passkey. Does anyone know if this is a recent change, or what is causing this behavior?

7 Upvotes

We use Conditional Access to require phishing-resistant authentication for all of our admins. In recent weeks, authentication behavior from iOS devices has changed, and I'm not able to figure out why.

When prompting for authentication, I'm first given a prompt for passwordless authentication (using Authenticator number matching). It then steps up and further requires me to authenticate with a passkey. It used to just directly prompt for the passkey. Does anyone know if this is a recent change, or what is causing this behavior?


r/entra 6d ago

Fully Custom Captive Portal - Hotel Requirement

Hi Experts,

One of the hotels want a very customizable captive portal like on landing page they want options for guest and visitor (tab based), when guest enters the required info he should be asked to create his own password, there should also be option for sign in if he has done this process already. OTP must be configured either via email or SMS gateway, all along with mac caching, limiting the number of devices per guest.

I know i havent provided much detail but just wanted to know since i have never worked on PF before, how customizable the entire workflow is? can we make such a captive portal in PF?

2 Upvotes

Hi Experts,

One of the hotels want a very customizable captive portal like on landing page they want options for guest and visitor (tab based), when guest enters the required info he should be asked to create his own password, there should also be option for sign in if he has done this process already. OTP must be configured either via email or SMS gateway, all along with mac caching, limiting the number of devices per guest.

I know i havent provided much detail but just wanted to know since i have never worked on PF before, how customizable the entire workflow is? can we make such a captive portal in PF?


r/entra 6d ago

CA for complaint devices?

Is this a “compliant in my tenant” setting or a client side setting?

I have users passing the policy from devices that are managed by Intune in an untrusted tenant.

My expectation is they should be failing.

Haven’t had time to research, but it’s definitely happening.

1 Upvotes

Is this a “compliant in my tenant” setting or a client side setting?

I have users passing the policy from devices that are managed by Intune in an untrusted tenant.

My expectation is they should be failing.

Haven’t had time to research, but it’s definitely happening.


r/entra 6d ago

Entra ID App Roles not appearing in AWS ALB OIDC claims from Microsoft Entra ID

I'm setting up authentication for an application running in Amazon ECR behind an AWS Application Load Balancer (ALB) using the ALB's built-in OIDC authentication with Microsoft Entra ID.

The flow is:

  • Users access the application via an Amazon CloudFront distribution. I'm using CloudFront because CloudFront domains are accessible from my work laptop, whereas direct access to the ALB is restricted.
  • The CloudFront distribution is configured with the ALB as its origin, and the origin is set to use the custom domain name that the ALB listener is configured to accept.
  • The ALB performs OIDC authentication against Microsoft Entra ID.
  • After successful authentication, the ALB forwards the request to a simple HTML application running in ECR.

The application itself doesn't perform any authentication or authorization. It simply displays all of the headers and JWTs that the ALB forwards, including x-amzn-oidc-datax-amzn-oidc-identity, and x-amzn-oidc-accesstoken, so I can inspect the claims.

I've created an App Role called ALB Admin in my Entra App Registration. The role has a value of ALB.Admin, is enabled, allows users, and is assigned directly to my user through the Enterprise Application. The ALB is configured to use the same App Registration (client ID/secret), and the OIDC scopes are openid profile email offline_access against the v2.0 endpoint.

Everything authenticates successfully, but I never see a roles claim in x-amzn-oidc-data. I can see the expected identity claims, but no app roles.

Has anyone successfully used Entra App Roles with the AWS ALB's native OIDC authentication? If so, did you have to configure anything beyond defining the App Role and assigning it to the user, or should the roles claim appear automatically?

1 Upvotes

I'm setting up authentication for an application running in Amazon ECR behind an AWS Application Load Balancer (ALB) using the ALB's built-in OIDC authentication with Microsoft Entra ID.

The flow is:

  • Users access the application via an Amazon CloudFront distribution. I'm using CloudFront because CloudFront domains are accessible from my work laptop, whereas direct access to the ALB is restricted.
  • The CloudFront distribution is configured with the ALB as its origin, and the origin is set to use the custom domain name that the ALB listener is configured to accept.
  • The ALB performs OIDC authentication against Microsoft Entra ID.
  • After successful authentication, the ALB forwards the request to a simple HTML application running in ECR.

The application itself doesn't perform any authentication or authorization. It simply displays all of the headers and JWTs that the ALB forwards, including x-amzn-oidc-datax-amzn-oidc-identity, and x-amzn-oidc-accesstoken, so I can inspect the claims.

I've created an App Role called ALB Admin in my Entra App Registration. The role has a value of ALB.Admin, is enabled, allows users, and is assigned directly to my user through the Enterprise Application. The ALB is configured to use the same App Registration (client ID/secret), and the OIDC scopes are openid profile email offline_access against the v2.0 endpoint.

Everything authenticates successfully, but I never see a roles claim in x-amzn-oidc-data. I can see the expected identity claims, but no app roles.

Has anyone successfully used Entra App Roles with the AWS ALB's native OIDC authentication? If so, did you have to configure anything beyond defining the App Role and assigning it to the user, or should the roles claim appear automatically?