Identity
Authentication, access, and tenant trust.
19 notes
-
Autopilot Hybrid Entra Join via Entra Kerberos (Preview): The Fix We've Been Waiting For?
A guide to Entra Kerberos based Hybrid Join. Is it enough to save Hybrid Autopilot, or should we just go Cloud Native?
-
Passkeys and the Personal Phone Problem – An MFA Update for 2026
MFA in 2026: Microsoft's mandatory enforcement, synced vs device-bound passkeys, and personal phone resistance.
-
ConsentFix - The Quickfix
Protect your tenant from the ConsentFix OAuth attack by locking down service principals for vulnerable Microsoft apps.
-
Unlocking Self-Service Account Recovery (SSAR) in Microsoft Entra
Configure Self-Service Account Recovery (SSAR) in Entra ID - regain access via government ID and biometric liveness checks.
-
2 for 1 - Mail Enable Unlicensed Admin Accounts - 2024 Edition
Save on Exchange Online licensing for admin accounts using plus addressing or a distribution list, no extra license needed.
-
Simplify Windows Hello for Business SSO with Cloud Kerberos Trust - Part 1
Part 1: Cloud Kerberos Trust for Windows Hello for Business - concepts, trust pain points, and the future of on-prem SSO.
-
Simplify Windows Hello for Business SSO with Cloud Kerberos Trust - Part 2
Part 2: step-by-step Cloud Kerberos Trust setup - Entra Kerberos PowerShell, Intune Settings Catalog, and verification.
-
Simplify Windows Hello for Business SSO with Cloud Kerberos Trust - Part 3
Part 3: Cloud Kerberos Trust mechanics - migration, NGC credentials, Wireshark captures, and klist troubleshooting.
-
2FA/MFA - Why Multi-Factor Authentication is Important
A high-level look at multi-factor authentication concepts, types (SMS, app, hardware), and why MFA matters in corporate IT.
-
Fix onmicrosoft.com Missing Default Domain
Fix the missing onmicrosoft.com default domain alias on synced identities in hybrid Exchange by changing the user's UPN.
-
How to remove credentials from a FIDO2 key like a boss
How to remove credentials from a FIDO2 key (Feitian specifically) and why housekeeping on your FIDO2 devices matters.
-
The Windows Hello Zone! - Part 2
Part 2 of the Windows Hello Zone - why PINs beat passwords and scenarios where Windows Hello for Business stops theft.
-
The Windows Hello Zone! - Part 1
Part 1 of the Windows Hello Zone - real scenarios showing why Windows Hello for Business biometrics matter for security.
-
Enable Microsoft Enterprise SSO plug-in for Apple Devices through Intune
How to enable the Microsoft Enterprise SSO plug-in for Apple iOS and macOS devices through Microsoft Intune.
-
Passwordless journey with FIDO2 - Part 3 - Engine troubles
Part 3 of the FIDO2 passwordless journey: key whitelisting, AAGUID discovery, and ThinC-AUTH, KEY-ID, OnlyKey reviews.
-
Conditional Access and the woes of being an external user
Conditional Access and MFA challenges for external/guest users in Entra ID, and practical fixes including FIDO2 keys.
-
Passwordless journey with FIDO2 - Part 2 - Usage experiences
Part 2 of the FIDO2 passwordless journey: hands-on with Solokeys, Yubico, and eWBM biometric security keys for Azure AD.
-
Passwordless journey with FIDO2 - Part 1 - Getting started with Security keys
Part 1 of the FIDO2 passwordless journey: requirements, setup hurdles, and security key vendors for Azure AD enterprise use.
-
2 Cool new password policy features in Microsoft Entra Connect Sync
Two Entra Connect Sync preview features: force password reset at logon and enforce cloud password policy for synced users.