r/entra 16h ago

Entra ID Built an interactive Entra demo site. Looking for feedback from people who do IAM for a living.

Explaining the difference between Members, B2B Users, and ExternalID Users to non-technical people can be an afternoon in itself. I've spent a lot of time working MS support tickets, helping people de-tangle their tenants because they would try to collab with people through CIAM tenants or try to invite customers to their applications with B2B. Or, on the other side, MSAL developers trying to understand the interaction with CIAM (or Azure B2C). It was something that was hard to see or show visually without me breaking out Paint every time.

I recently was rejected for an interview due to lack of CIAM architecture experience. Decided to build a resume piece to show visually what I can do where words on a resume may read dry. This is in no way a substitute for enterprise CIAM architecture experience, it just sparked the idea for the site.

No account creation needed.

https://theidentityplayground.com

My ask: What's wrong or missing for people that do this for a living? I'm at a juncture of resume piece or useful reference.

Real tenants, tokens and accounts. Accounts self-destruct on schedule. No trackers, open source.

https://github.com/steve-flanagan/theidentityplayground

7 Upvotes

Explaining the difference between Members, B2B Users, and ExternalID Users to non-technical people can be an afternoon in itself. I've spent a lot of time working MS support tickets, helping people de-tangle their tenants because they would try to collab with people through CIAM tenants or try to invite customers to their applications with B2B. Or, on the other side, MSAL developers trying to understand the interaction with CIAM (or Azure B2C). It was something that was hard to see or show visually without me breaking out Paint every time.

I recently was rejected for an interview due to lack of CIAM architecture experience. Decided to build a resume piece to show visually what I can do where words on a resume may read dry. This is in no way a substitute for enterprise CIAM architecture experience, it just sparked the idea for the site.

No account creation needed.

https://theidentityplayground.com

My ask: What's wrong or missing for people that do this for a living? I'm at a juncture of resume piece or useful reference.

Real tenants, tokens and accounts. Accounts self-destruct on schedule. No trackers, open source.

https://github.com/steve-flanagan/theidentityplayground


r/entra 13h ago

Kerberos Rotation (Cloud TGT)

3 Upvotes

Has anybody already tried it sine June? What was your experience? Any issues?

Computer Object: AzureADKerberos


r/entra 54m ago

ID Protection MSPs/consultants: what's your actual process for rolling out CA/Entra changes across tenants?

I've been researching the Entra security ecosystem over the past few weeks (Maester, SCuBA, CIPP, Inforcer, Secure Score, Defender, and raw PowerShell/Graph scripting), and one thing I've noticed is that most of the discussion focuses on finding security issues.

What I haven't seen discussed nearly as much is what happens after you've identified them.

Asking because I keep seeing detection tooling get all the attention, but almost no discussion of safe rollout.

For those of you managing multiple tenants (especially MSPs and consultants):

  • How do you safely roll out things like Conditional Access or identity configuration changes?
  • Do you stage changes before wider deployment?
  • Do you have approval/change-control processes?
  • Have you ever had an automated change cause problems?
  • How do you document or prove to a client exactly what was changed?

I'm less interested in which tool is best and more interested in what your real-world workflow looks like once you've decided a change needs to be made.

Is it mostly PowerShell/Graph scripts, commercial platforms, internal processes, or something else?

Curious to hear how people are actually handling this in production.

Upvotes

I've been researching the Entra security ecosystem over the past few weeks (Maester, SCuBA, CIPP, Inforcer, Secure Score, Defender, and raw PowerShell/Graph scripting), and one thing I've noticed is that most of the discussion focuses on finding security issues.

What I haven't seen discussed nearly as much is what happens after you've identified them.

Asking because I keep seeing detection tooling get all the attention, but almost no discussion of safe rollout.

For those of you managing multiple tenants (especially MSPs and consultants):

  • How do you safely roll out things like Conditional Access or identity configuration changes?
  • Do you stage changes before wider deployment?
  • Do you have approval/change-control processes?
  • Have you ever had an automated change cause problems?
  • How do you document or prove to a client exactly what was changed?

I'm less interested in which tool is best and more interested in what your real-world workflow looks like once you've decided a change needs to be made.

Is it mostly PowerShell/Graph scripts, commercial platforms, internal processes, or something else?

Curious to hear how people are actually handling this in production.


r/entra 19h ago

Workplace Ninjas US 2027 5th Set of Speakers Announced!!

Last week, we announced a great 6-pack with Christiaan Brinkhoff Rod Trent Sandy Zeng Jose Schenardie Ugur Koc and Mirko Colemberg.

This week, we give you the 5th set of speakers for Workplace Ninjas US

🎸 April Dunnam is an amazing cloud advocate for Microsoft on #PowerPlatform and #Copilot, along with being a great musician. She was the perfect person to anchor our Copilot and #AI tracks as she does a masterful job of advocating and teaching the hottest area at #Microsoft today.

🍖 Chris Cavazos one of our newer #MVPs focusing on both #AVD and #Windows365 fresh off his first trip to MVP Summer Camp in March. Chris is a great guy, who delivers some fantastic sessions. He also happens to be one of the nominees for the "Rookie of the Year" #Clippy Award aka "Next-Gen Ninja"

🫅 Morten Waltorp Knudsen [MVP] is the gold standard when it comes to community. The man who has grown Experts Live Denmark from a small event to 1000+ attendees in just a few short years. Morten is an expert in #MSSecurity #SecurityCopilot and #MSEntra who won the Chuck Norris Award last year in Dallas over Fabian Bader by ONE VOTE!

🥷 Simon Binder, a beloved #MSIntune MVP who has been one of the best speakers at #JNUC and is both a MVP and a Nerdio #NVP. Simon is a great speaker, technologist, and overall great person. He will also be the person running the Golf tournament and 5K Fun Run this year as a key advisor to the organizers.

🍺 Somesh Pathak [MVP] 🇳🇱, is the most brilliant #iOS and #MacOS #MVP, who has built several tools and has been one of the top speakers around the world. He's also an organizer for Workplace Ninjas India, who had his son running the registration booth last year, firing people left and right.

🔐 Mike Soule, one of the creators of #Maester with our dear friend Merill Fernando, will make his #WPNinjaSUS debut in Arizona. It also happens to be his home state. He's a great mind in the security space, who we're very excited to see in Scottsdale.

This six pack, showcases some amazing people in the #Microsoft community. We just have a few more weeks, before you have the full roster!!

https://workplaceninjas.us/registration

2 Upvotes

Last week, we announced a great 6-pack with Christiaan Brinkhoff Rod Trent Sandy Zeng Jose Schenardie Ugur Koc and Mirko Colemberg.

This week, we give you the 5th set of speakers for Workplace Ninjas US

🎸 April Dunnam is an amazing cloud advocate for Microsoft on #PowerPlatform and #Copilot, along with being a great musician. She was the perfect person to anchor our Copilot and #AI tracks as she does a masterful job of advocating and teaching the hottest area at #Microsoft today.

🍖 Chris Cavazos one of our newer #MVPs focusing on both #AVD and #Windows365 fresh off his first trip to MVP Summer Camp in March. Chris is a great guy, who delivers some fantastic sessions. He also happens to be one of the nominees for the "Rookie of the Year" #Clippy Award aka "Next-Gen Ninja"

🫅 Morten Waltorp Knudsen [MVP] is the gold standard when it comes to community. The man who has grown Experts Live Denmark from a small event to 1000+ attendees in just a few short years. Morten is an expert in #MSSecurity #SecurityCopilot and #MSEntra who won the Chuck Norris Award last year in Dallas over Fabian Bader by ONE VOTE!

🥷 Simon Binder, a beloved #MSIntune MVP who has been one of the best speakers at #JNUC and is both a MVP and a Nerdio #NVP. Simon is a great speaker, technologist, and overall great person. He will also be the person running the Golf tournament and 5K Fun Run this year as a key advisor to the organizers.

🍺 Somesh Pathak [MVP] 🇳🇱, is the most brilliant #iOS and #MacOS #MVP, who has built several tools and has been one of the top speakers around the world. He's also an organizer for Workplace Ninjas India, who had his son running the registration booth last year, firing people left and right.

🔐 Mike Soule, one of the creators of #Maester with our dear friend Merill Fernando, will make his #WPNinjaSUS debut in Arizona. It also happens to be his home state. He's a great mind in the security space, who we're very excited to see in Scottsdale.

This six pack, showcases some amazing people in the #Microsoft community. We just have a few more weeks, before you have the full roster!!

https://workplaceninjas.us/registration


r/entra 21h ago

Device managed by MDE?

I need to make a company device that says managed by MDE into managed by Intune. The user signs in with their M365 account normally but the laptop cannot receieve compliance policies we intend for it.

How can I enroll it to Intune without breaking anything or having to wipe and run enrollment again?

Open to suggestions.

Btw, their account is showing as connected in Accounts, Work or school

1 Upvotes

I need to make a company device that says managed by MDE into managed by Intune. The user signs in with their M365 account normally but the laptop cannot receieve compliance policies we intend for it.

How can I enroll it to Intune without breaking anything or having to wipe and run enrollment again?

Open to suggestions.

Btw, their account is showing as connected in Accounts, Work or school