Microsoft Entra ID Security Posts

Discover the latest insights, best practices, and security research related to Microsoft Entra ID (formerly Azure AD).

Search Entra ID Posts

Filter Posts

Posts

SignToolGUI 2.1.0.0 Released 🎉

by Michael Morten Sonne
azure azure-adentra-id c code-repository code-sign

Last Updated on December 16, 2025 by Michael Morten Sonne Introduction I’m happy to announce the release of… The post SignToolGUI 2.1.0.0 Rel...

Read Article →

Microsoft Baseline Security Mode Rolls Out

by Tony Redmond
compliance microsoft-365 baseline-security-mode entra-id exchange-online

Microsoft has released a set of security benchmark recommendations for Microsoft 365 tenants that it calls baseline security mode. The recommendati...

Read Article →

Checking Where Tenant Users Go as Guests

by Tony Redmond
entra-id microsoft-entra-id powershell entra-b2b-collaboration external-guest-activity

After all the fuss about Teams users inviting people to chat via email, tenant administrators realize that knowing where users are active as guest ...

Read Article →

Conditional Access bypasses

by Author
entra-id zero-trust conditional-access

In Microsoft Entra, Conditional Access is, after the Authentication itself, the most crucial part of defense against attackers. It’s referenced as ...

Read Article →

What is Microsoft Entra Agent ID?

by Daniel Bradley
ai-agents microsoft-entra

Learn about the new Agent ID (preview) functionality in Microsoft Entra as well as Agent Identities and Agent Blueprints. The post What is Microsof...

Read Article →

Microsoft-Managed Risk Remediation

by Derk van der Woude
entra-id security conditional-access mfa identity

Entra ID Identity Protection [Entra ID P2 license] is a Microsoft Security product to automatically protect Entra ID users (in-scope) and non-human...

Read Article →

A Brief History of Soft-Deleted Entra ID Groups

by Tony Redmond
entra-id entra-id recover-soft-deleted-group security-groups soft-deleted-groups

Entra ID has long supported soft-deleted Microsoft 365 Groups. Now support is available to list and restore soft-deleted security groups in both th...

Read Article →

Mastering Certificate Rotation in Entra ID

by Tim Groothuis
application-registration azure security entra-id devops

Recently I posted a blog about Entra ID Application Registration secret management, in which I explained how to rotate Application Registration sec...

Read Article →

Real-time protection for ‘AI Agents’

by Derk van der Woude
azure entra-id security defender identity

Microsoft Copilot Studio is a graphical, low-code/no‑code (LCNC) platform to build AI agents to support human tasks.Microsoft Copilot Studio — AI A...

Read Article →

What’s the Best Way to Manage Guest Accounts?

by Tony Redmond
entra-id microsoft-365 access-reviews guest-account-management id-governance

Guest account management should be a part of every Microsoft 365 tenant administrator’s checklist, unless the tenant has no guests. That’s possible...

Read Article →

Microsoft’s Effort to Develop a Broad People Platform

by Tony Redmond
microsoft-365 microsoft-graph copilot-connector get-mgbetauserprofileposition microsoft-365-profile-card

Microsoft 365 users see the profile card and might wonder where the information displayed on the card comes from. Entra ID is the obvious source, b...

Read Article →

People Settings Appear in the Microsoft 365 Admin Center

by Tony Redmond
entra-id microsoft-365 exchange-online-custom-properties microsoft-365-profile-card microsoft-365-user-profile-card

The Org Settings section of the Microsoft 365 admin center has a new People Settings section where you can choose properties for the Microsoft 365 ...

Read Article →

Entra Useless Insights Report

by Eric Woodruff
entra-id

Entra Useless Insights Report Overview Yes. The name is snarky on purpose. With the drive to using phishing-resistant MFA something on the mind of ...

Read Article →

What is Entra Docs Tracker?

by Daniel Bradley
entra-id

Effortlessly track and document all changes to public Microsoft Entra documentation and stay ahead of this rapidly changing product. The post What ...

Read Article →

Finding Seamless SSO usage

by Nathan McNulty
azure entra-id

A brief history Seamless Single Sign On was first introduced in late 2016 and provided a way for users to authenticate to Entra ID (Azure AD at the...

Read Article →

Entra ID Governance Deep dive

by jere.haavisto
entra-id identity

The time has come to write a blog about Entra ID Governance. There are a lot of cool functionality that can help managing Users and their permissio...

Read Article →

Announcing Office 365 for IT Pros (2026 Edition)

by Tony Redmond
book 2026-edition automating-microsoft-365-with-powershell office-365-for-it-pros tenant-management

Office 365 for IT Pros (2026 edition), the 12th in an eBook series going back to May 2015, is now available. Covering all the essential aspects of ...

Read Article →

How to Block Ad-Hoc Email-Based Subscriptions

by Tony Redmond
administration security copilot-studio email-based-subscriptions entra-id-authorization-policy

The old Set-MsolCompanySettings cmdlet is no more, so how can a Microsoft 365 tenant block email-based subscriptions? With the Graph, of course! Se...

Read Article →

Entra ID Admin Roles Report

by Roy Klooster
uncategorized

Table of Contents Introduction Requirements Features How does it work? Interactive Authentication Client Secret Authentication Certificate Authenti...

Read Article →

Maester Framework Continues to Prosper

by Tony Redmond
microsoft-365 entra-id-accounts finding-user-accounts get-user maester-custom-tests

The Maester project continues to prosper with a bunch of new features added, including several in the DevOps space. Maester usually tests tenant se...

Read Article →

Microsoft Introduces People Administrator Role

by Tony Redmond
administration entra-id entra-id people-administrator-role role-assignments

A new people administrator role is available in Entra ID. The new role allows holders to manage settings associated with people, like pronouns and ...

Read Article →

KQL Sources - 2025 Update

by Bert-Jan Pals
azure entra-id security intune sentinel

What started as a single blog is now becoming a yearly trend. More and more KQL related repositories are created, not only with a focus on security...

Read Article →

UAL = Unaligned Activity Logs

by Bert-Jan Pals
azure entra-id defender sentinel cloud

The unified audit log is a centralized repository for M365 user and admin activities. The activities originate from different applications, such as...

Read Article →

How to Force Users to Sign in Weekly

by Tony Redmond
administration entra-id revoke-access-to-user-account revoke-mgusersigninsession schedule-reauthentication-for-user-account

A recent question asked how to force users to reauthenticate at 7AM every Monday. The solution seems to revoke access for user accounts. This artic...

Read Article →

Hardening Entra ID

by Truls Dahlsveen
azure entra-id

This is an update to a previous article I wrote on hardening Azure Active Directory. The idea of this update is to provide a table of default setti...

Read Article →

Adding a Custom Test to the Maester Tool

by Tony Redmond
microsoft-365 entra-id custom-maester-tests entra-id-groups-policy microsoft-365-groups

The Maester tool is a great way to get a security assessment for a Microsoft 365 tenant. Being able to create custom Maester tests makes it even be...

Read Article →

Azug @ Noest

by Robbe Van den Daele
azure entra-id identity

At a recent community event, I presented a deep dive into various authentication flows in Entra Id, showcasing how to retrieve an ARC server from a...

Read Article →

Deep Dive SSO in Entra Private Access

by Christopher Brumm
entra-id security conditional-access

A few days ago, Microsoft announced that Global Secure Access is now generally available. Since I have been working with the product for some time ...

Read Article →

Speaking at the Workplace Ninja Summit 2024

by Kenneth Van Surksum
entra-id conditional-access entra-id identity-protection intune

Next week it’s time again for the annual Workplace Ninja Summit in Lucerne, Switzerland. The summit will start on Monday September 16th till ...

Read Article →

Deep Dive DNS in Entra Private Access

by Christopher Brumm
entra-id security conditional-access

A few days ago, Microsoft announced that Global Secure Access is now generally available. Since I have been working with the product for some time ...

Read Article →

Detect Impact MFA Enforcement

by Morten Knudsen
azure entra-id identity microsoft-graph microsoft-security

You may have noticed that Microsoft will enforce MFA requirement per October 15, 2024 for Azure/Entra/Intune. If this is new ... Read more

Read Article →

PnP PowerShell Changes Its Entra ID App

by Tony Redmond
powershell sharepoint-online change-in-pnp-powershell-app pnp-powershell

On August 21, 2024, news emerged that the PnP PowerShell module will transition from using a multi-tenant Entra ID app to a tenant-specific app. Th...

Read Article →

Finding Non-Compliant Shared Mailboxes

by Tony Redmond
exchange-online get-mgauditlogsignin licensing log-into-shared-mailbox shared-mailboxes

Shared mailboxes have Entra ID accounts. No one needs to sign into the accounts because Exchange Online manages connections using mailbox permissio...

Read Article →

Reporting Entra ID Administrative Role Assignments

by Tony Redmond
entra-id administrative-role-assignments get-mgbetarolemanagementdirectoryroleassignmentschedule get-mgbetarolemanagementdirectoryroleeligibilityschedule pim

A recent report highlighted the problem of on-premises accounts synchronized to Entra ID that receive administrative role assignments. This article...

Read Article →

Overview to Global Secure Access

by Christopher Brumm
entra-id security conditional-access

A few days ago, Microsoft announced that Global Secure Access is now generally available. Since I have been working with the product for some time ...

Read Article →

Phishing-resistant MFA basics

by Derk van der Woude
entra-id security conditional-access mfa identity

This blog explains the basics of phishing-resistant MFA (Multi Factor Authentication) and the single- and/or multi-tenant support options (which qu...

Read Article →

All About Microsoft 365 Tenant Identifiers

by Tony Redmond
administration microsoft-365 microsoft-365-tenant-identifier tenant-identifier

Every Microsoft 365 tenant has a tenant identifier, a unique GUID that's used within the Entra ecosystem to identify a tenant and its objects. Much...

Read Article →

Reporting Soft-Deleted Entra ID Objects

by Tony Redmond
entra-id report-soft-deleted-entra-id-objects

A Microsoft Technical Community article gave some interesting information about how to report soft-deleted Entra ID objects. We think we can improv...

Read Article →

Checking Out Entra Identity Secure Score

by Tony Redmond
entra-id entra-identity-secure-score expiring-app-credentials

If your Microsoft 365 tenant has Entra P2 licenses, you can use the Entra Identity Secure Score feature to measure your tenant against Microsoft be...

Read Article →

How to Report Expiring Credentials for Entra ID Apps

by Tony Redmond
entra-id microsoft-graph app-certificate-expiration app-credential-expiration app-secret-expiration

Entra ID registered apps can authenticate using app secrets and certificates. These credentials expire over time, so it’s good to review app creden...

Read Article →

Mastering Microsoft Graph PowerShell SDK Foibles

by Tony Redmond
entra-id microsoft-graph powershell get-graphscriptpermission group-extension-attributes

Entra ID supports user extension attributes but the same facility is unavailable for group objects. That seems strange, but it might be due to the ...

Read Article →

Reporting Entra ID Admin Consent Requests

by Tony Redmond
entra-id powershell admin-consent-request entra-id get-mgidentitygovernanceappconsentrequest

A question came in about how to report admin consent requests as viewed through the Entra ID admin center. PowerShell does the trick, once you know...

Read Article →

Entra ID Improves Registered App Security

by Tony Redmond
entra-id powershell app-instance-property-lock entra-id-registrered-app get-mgapplication

The preview app instance property lock feature designed to improve the security of Entra ID registered apps is becoming the default for new apps. I...

Read Article →

What problem do passkeys solve?

by Kenneth Van Surksum
entra-id security fido2 passkeys

Sometimes unlearning things is harder than learning As you might have read somewhere Microsoft is busy implementing support for passkeys in their p...

Read Article →

Dude, Where's My Audit Logs?

by Eric Woodruff
entra-id

Dude, Where's My Audit Logs? Audit logs can provide all sorts of wonderful points of data. In the interest of identity security, we have historical...

Read Article →

Secure your Azure Management portal

by Michael Morten Sonne
entra-id identity security

Last Updated on June 25, 2023 by Michael Morten Sonne How secure your Azure Management Portal?. By default,… The post Secure your Azure Manag...

Read Article →

Running Evilginx 3.0 on Windows

by Jan Bakker
entra-id security

Check out this article via web browser: Running Evilginx 3.0 on Windows In case you missed it: Evilginx 3 was recently launched to the public. This...

Read Article →

The TenantID from Toronto

by rudyooms
entra-id intune uncategorized

After reading a question on Reddit about how Intune knows which device belongs to which organization, I decided to write a dedicated blog post abou...

Read Article →

Night of the Autopilot of the Dawn of the Temporary Access Pass of the MFA of the Return of the RebootRequired of the WUFB of the Attack of the Evil, Mutant, Hellbound, Flesh-Eating SSO Zombified Living Conditional Access, Part 2: In Azure 2-D

by rudyooms
autopilot entra-id intune privileged-access-workstation uncategorized

After a nice talk with Yannick Van Landeghem, who made me aware of a “possible” security gap when using a Temporary Access Pass (TAP), I decided to...

Read Article →

Self Service in Microsoft 365

by Jan Bakker
entra-id delegation groups it-staff microsoft-365

Check out this article via web browser: Self Service in Microsoft 365 One of the great things about Azure Active Directory is the capability of sel...

Read Article →

Azure AD Identity Protection deep dive

by Kenneth Van Surksum
entra-id conditional-access identity-protection security identity

One of the advantages of Microsoft having many customers using its services is that Microsoft can leverage data from those customers and apply some...

Read Article →