Protected: No title

There is no excerpt because this is a protected post.

(Mis)understanding Software OATH token in Entra

Just me, overcomplicating something that is supposed to be easy: migrating to Authentication methods policy in Entra. Yes, I’m late to the party and I probably did not read all the documentation*, but wanted to share my journey with Software OATH tokens. * I indeed did not read enough documentation TL;DR So, the Automated migration […]

Prevent disabling passkeys on Windows

I recently read an article from Dr. Emin Huseynov about the toggle in Windows settings that disables passkeys for every user. While there can be specific circumstances where an organization may intentionally disable passkey usage, I – passkey fan – want to make sure it is enabled. I did not find any official solution to […]

Delegating LAPS password retrieval at device level

Poor man’s EPM – delegate access to the LAPS password on a device basis.
(this alternative title is inspired by Jan Bakker’s “Poor man’s IGA” blog series)

Entra App instance property lock vs SAML signing certificate – an uncommon way of self-sabotage

Recently I tried to set up ClaimXRay NG with the guidance of DSInternals, learned things, failed here and there and stumbled upon a totally-not-helpful error message: “There was an error in the uploading the private certificate and password. Please try again or contact support.” To cut to the chase: This message appeared when I was […]

Multitenant organization “cheat” to add group(s) to the default sync scope

Back in the days when M365 MTO was in preview, it was possible to add group(s) to the default sync scope – today, the documentation states that if you want to sync groups, “you must configure cross-tenant synchronization directly in Microsoft Entra ID”. It doesn’t say “it is impossible to add groups to the default […]

Find personal Microsoft accounts with corporate email address

Personal Microsoft accounts registered with corporate email address can cause end-user confusion and probably some headaches for IT admins. Let’s find these users before they find you.

Disabling Entra Seamless SSO – some extra notes

Disabling Entra Seamless SSO is simple – or you can get lost in the details.

Quicknote: Hybrid Exchange mailbox migration account vs. modern authentication policy

Recently, I came across an uncommon issue while disabling legacy authentication in a hybrid Exchange environment. Since I did not find any exact solutions, I thought I share my story about modern authentication in on-premises Exchange server and how it affects the mailbox migration account. Spoiler: it breaks the mailbox migration TL;DR– Exchange Online uses […]

Powershell with Entra CBA – unattended access to Defender portal when Graph API or Application permission does not fit

One of my previous posts covered a “basic” way to track secure score changes using Graph API with application permissions. While I still prefer application permissions (over service accounts) for unattended access to certain resources, sometimes it is not possible – for example when you want to access resources which are behind the Defender portal’s […]