<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Entra.News - Your weekly dose of Microsoft Entra]]></title><description><![CDATA[Entra.News is the go-to newsletter for the latest updates & expert insights on Microsoft Entra. Curated from top sources like Microsoft & MVPs, it's trusted by IT Pros & enterprise security teams worldwide to stay ahead in identity & access management.]]></description><link>https://entra.news</link><image><url>https://substackcdn.com/image/fetch/$s_!4mCy!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png</url><title>Entra.News - Your weekly dose of Microsoft Entra</title><link>https://entra.news</link></image><generator>Substack</generator><lastBuildDate>Tue, 21 Apr 2026 10:56:32 GMT</lastBuildDate><atom:link href="https://entra.news/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Merill & Joshua Fernando]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[hey@entra.news]]></webMaster><itunes:owner><itunes:email><![CDATA[hey@entra.news]]></itunes:email><itunes:name><![CDATA[Merill Fernando]]></itunes:name></itunes:owner><itunes:author><![CDATA[Merill Fernando]]></itunes:author><googleplay:owner><![CDATA[hey@entra.news]]></googleplay:owner><googleplay:email><![CDATA[hey@entra.news]]></googleplay:email><googleplay:author><![CDATA[Merill Fernando]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Entra 🆔 News #145 → This week in Microsoft Entra]]></title><description><![CDATA[&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.]]></description><link>https://entra.news/p/entra-news-145-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-145-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 19 Apr 2026 12:30:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/jHGjv5_xIKg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>&#128075;</em> Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>There are some important updates in this week&#8217;s Message Center posts, so be sure to check them out and prepare for the changes.</p><p>Don&#8217;t forget to queue up this week&#8217;s Entra Chat featuring the legendary Sean Metcalf, and hear his top tips for hardening Entra ID in 2026.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b25c1138-79d2-45d7-b555-e861a8e7019d&quot;,&quot;caption&quot;:&quot;Microsoft Entra security is evolving and the way organizations think about identity protection needs to evolve with it. In this episode, I&#8217;m joined by Sean Metcalf, one of the foremost identity security experts in the industry, whose work has helped shape how many organizations approach securing both Active Directory and Microsoft Entra.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Stop Leaving the Door Open: The Entra ID Hardening Checklist Security Experts Actually Use&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-18T13:11:49.622Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/194593881/a70e3097-afe3-41b5-ba10-f20cd4ef3556/transcoded-1776515591.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/stop-leaving-the-door-open-the-entra&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194593881,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:13,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=4.19.26" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!de92!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!de92!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!de92!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!de92!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!de92!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:183110,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=4.19.26&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/194658228?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!de92!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!de92!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!de92!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!de92!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F072f5347-30d3-408f-ae76-9456839be7ee_1200x600.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Uncover Risky Entra ID Apps Faster</strong></p><p>Most Microsoft 365 tenants accumulate hundreds of enterprise applications, with OAuth permissions granted over time and ownership left undefined. Security teams often lack visibility into which apps access mailboxes, files, or user data, and which introduce risk.</p><p>Native tools provide pieces of this data, but not a unified view. That gap makes consistent application governance hard to maintain.</p><p><strong><a href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=4.19.26">AppGov Score</a></strong> assesses your Entra ID application landscape. Identify high-risk permissions, detect unused or overprivileged apps, and surface ownership gaps so you can prioritize remediation based on real exposure.</p><p>Attending the Microsoft 365 Community Conference in Orlando? <strong><a href="https://www.enowsoftware.com/microsoft-365-community-conference-2026?utm_campaign=39553032-ts-m365conf-2026&amp;utm_source=entranews&amp;utm_medium=email&amp;utm_content=4.19.26">Visit ENow at booth #617</a> </strong>to see how teams are strengthening application governance while enabling their users.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=4.19.26&quot;,&quot;text&quot;:&quot;Get Your App Risk Score&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=4.19.26"><span>Get Your App Risk Score</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access?tabs=azurecli">Authorize SFTP access to blobs using Microsoft Entra ID (preview) - Azure Storage</a> &#8226; <em>Microsoft Learn</em></p></li></ul><h2>&#128214; Read</h2><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/what%e2%80%99s-new-in-microsoft-entra-%e2%80%93-march-2026/4502150">What&#8217;s new in Microsoft Entra &#8211; March 2026</a> &#8226; <em>Shobhit Sahay</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1282568">MC1282568 - General Availability: Microsoft Entra passkeys on Windows</a></p></li><li><p><a href="https://mc.merill.net/message/MC1225192">MC1225192 - Microsoft Entra ID Governance: Azure subscription required to continue using guest governance features</a></p></li><li><p><a href="https://mc.merill.net/message/MC1221452">MC1221452 - (Updated 15 Apr) Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants</a></p></li><li><p><a href="https://mc.merill.net/message/MC1279092">MC1279092 - Microsoft Entra: Passkeys in registration campaigns update</a></p></li><li><p><a href="https://mc.merill.net/message/MC1255405">MC1255405 - Microsoft Edge for Business: Cross-tenant support using Intune Mobile Application Management (MAM)</a></p></li><li><p><a href="https://mc.merill.net/message/MC1223829">MC1223829 - Upcoming Conditional Access change: Improved enforcement for policies with resource exclusions</a> - The new Baseline scope configuration is now available to preview the enforcement behavior before it is enabled by default.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://aka.ms/BaselineScopesSettings" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hEW8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 424w, https://substackcdn.com/image/fetch/$s_!hEW8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 848w, https://substackcdn.com/image/fetch/$s_!hEW8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 1272w, https://substackcdn.com/image/fetch/$s_!hEW8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hEW8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png" width="1456" height="1228" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1228,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:389783,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://aka.ms/BaselineScopesSettings&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/194658228?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hEW8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 424w, https://substackcdn.com/image/fetch/$s_!hEW8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 848w, https://substackcdn.com/image/fetch/$s_!hEW8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 1272w, https://substackcdn.com/image/fetch/$s_!hEW8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c6a449-efbb-4061-be88-bb7e4be2376a_1674x1412.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://derkvanderwoude.medium.com/microsoft-security-copilot-for-m365-e5-e7-recommendations-from-the-field-ea32555180a5">Microsoft Security Copilot for M365 E5/E7 recommendations from the field</a> &#8226; <em>Derk van der Woude</em></p></li><li><p>&#129352;<a href="https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-3-weak-privileged-identity-management-configuration/">Common Entra ID Security Assessment Findings &#8211; Part 3: Weak Privileged Identity Management Configuration &#8211; Compass Security Blog</a> &#8226; <em>Christian Feuchter</em></p></li><li><p>&#129353;<a href="https://office365itpros.com/2026/04/06/microsoft-365-groups-change-report/">How to Track Changes in Microsoft 365 Groups</a> &#8226; <em>Tony Redmond</em></p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=19.4.26" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3VcT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 424w, https://substackcdn.com/image/fetch/$s_!3VcT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 848w, https://substackcdn.com/image/fetch/$s_!3VcT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 1272w, https://substackcdn.com/image/fetch/$s_!3VcT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3VcT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png" width="811" height="714" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:714,&quot;width&quot;:811,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:358966,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=19.4.26&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/194658228?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3VcT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 424w, https://substackcdn.com/image/fetch/$s_!3VcT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 848w, https://substackcdn.com/image/fetch/$s_!3VcT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 1272w, https://substackcdn.com/image/fetch/$s_!3VcT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e5550f0-9945-47dc-803b-cb1375880d7c_811x714.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Would you bet your reputation on your current Microsoft 365 security posture?</strong></p><p>Sure, you&#8217;ve checked Purview. Maybe tightened Conditional Access. We all do that.</p><p>But it&#8217;s usually the quiet stuff that bites... permissions that expanded, policies that drifted, exceptions nobody revisited.</p><p>You could assume it&#8217;s fine.</p><p>Or you could run the Microsoft 365 Security Posture Check.</p><p>It&#8217;s free.</p><p>It runs locally.</p><p>And no, it doesn&#8217;t send your tenant data back to us.</p><p>We&#8217;ll even help you set it up.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=19.4.26&quot;,&quot;text&quot;:&quot;Get yours here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=19.4.26"><span>Get yours here</span></a></p></blockquote><div><hr></div><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/jonaswatt_microsoft365-itadmin-powershell-activity-7448333334767628288--77q?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N4bw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 424w, https://substackcdn.com/image/fetch/$s_!N4bw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 848w, https://substackcdn.com/image/fetch/$s_!N4bw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 1272w, https://substackcdn.com/image/fetch/$s_!N4bw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N4bw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png" width="1116" height="1490" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1490,&quot;width&quot;:1116,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1713317,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/jonaswatt_microsoft365-itadmin-powershell-activity-7448333334767628288--77q?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/194658228?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N4bw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 424w, https://substackcdn.com/image/fetch/$s_!N4bw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 848w, https://substackcdn.com/image/fetch/$s_!N4bw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 1272w, https://substackcdn.com/image/fetch/$s_!N4bw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb17b0aed-6d03-412a-b2f1-f213ce64b983_1116x1490.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://derkvanderwoude.medium.com/a-deep-dive-into-entra-agent-id-authentication-07163f269de3?source=rss-108a26c58aec------2">A Deep-Dive into Entra Agent ID Authentication</a> &#8226; <em>Derk van der Woude</em></p></li></ul><h2>&#129520; Workload ID</h2><ul><li><p><a href="https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/">Block or limit multi-tenant and consumer applications in Entra ID</a> &#8226; <em>Jan Bakker</em></p></li><li><p><a href="https://www.shankuehn.io/post/who-created-that-service-principal-tracing-it-back-with-microsoft-graph">Who Created That Service Principal? Tracing It Back with Microsoft Graph</a> &#8226; <em>Shannon Kuehn</em></p></li></ul><h2>&#128110;&#8205;&#9794;&#65039; ID Governance</h2><ul><li><p><a href="https://medium.com/snowflake/beyond-basic-scim-custom-role-and-warehouse-mapping-with-microsoft-entra-id-and-snowflake-3bb16a68281b">Beyond Basic SCIM: Custom Role and Warehouse Mapping with Microsoft Entra ID and Snowflake</a> &#8226; <em>Parshu Anantharam</em></p></li><li><p><a href="https://idguys.tech/blog/making-lifecycle-workflows-state-aware-with-state-groups">Making Lifecycle Workflows State-Aware with State Groups</a> &#8226; <em>Patrik Jonsson</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p><a href="https://chris-brumm.com/2026/04/Why-you-should-enable-the-Microsoft-Traffic-Forwarding-Profile/">Why you should enable the Microsoft Traffic Forwarding Profile</a> &#8226; <em>Chris Brumm</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://blog.admindroid.com/block-multi-tenant-and-consumer-apps-in-entra-admin-center/">Block Multi-Tenant and Consumer Applications in Microsoft Entra</a> &#8226; <em>Shanchana</em></p></li><li><p><a href="https://medium.com/@brianveldman/getting-the-group-claims-when-authenticating-with-microsoft-graph-e8e22220b021?source=rss-4a3a93df846e------2">Getting the Group Claims when authenticating with Microsoft Graph</a> &#8226; <em>Brian Veldman</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=pzPqnTHxNPU">Entra ID Integrated SFTP</a> (16 min) &#8226; <em>John Savill</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=CWc0QGbCDHc&amp;t=285&amp;si=HhhP-NLrJ-J7CsGk">Device Authentication Flows in Microsoft Entra</a> (12 min) &#8226; <em>Colby Pryor</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://medium.com/@eminhuseynov_37266/any-user-can-disable-passkeys-in-windows-no-admin-rights-needed-bb0923fe35e2?source=rss-6acd8e7fc68a------2">Any user can disable passkeys in Windows. Completely. No admin rights needed.</a> &#8226; <em>Dr. Emin Huseynov</em></p></li><li><p><a href="https://f12.hu/2026/04/18/prevent-disabling-passkeys-on-windows/">Prevent disabling passkeys on Windows</a> &#8226; <em>D&#225;niel Kov&#225;cs</em></p></li><li><p><a href="https://ourcloudnetwork.com/microsoft-entra-passkeys-registration-campaign-delays-explained/">Microsoft Entra Passkeys: Registration Campaign Delays Explained</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://eskonr.com/2026/03/synchronizing-forced-password-changes-from-ad-to-entra-id-for-avd-and-cloud-pc-access/">Synchronizing Forced Password Changes from AD to Entra ID for AVD and Cloud PC Access &#8211; All about Endpoint Management</a> &#8226; <em>Eswar Koneti</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=DQ4dnXibaoM">Are passkeys as secure as you think?</a> (43 min) &#8226; <em>Fabian Bader</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=Ln8sdBMB5r0">How to Handle Upcoming Entra Passkey Changes [Defaults Fail]</a> (17 min) &#8226; <em>Ru Campbell</em></p></li><li><p>&#128250; <a href="https://m.youtube.com/watch?v=hVEvWZ6aVTo">Not Another Tech Podcast - Synced Passkeys</a> (38 min) &#8226; <em>Andy Kemp, Nate Hutchinson</em></p></li></ul><h2>&#128101; User &amp; Group Management</h2><ul><li><p><a href="https://www.thetechtrails.com/2026/04/m365-profile-card-division-role-employee-type-entra-graph.html">Customize Microsoft 365 Profile Cards with Division, Role &amp; Employee Type using Entra ID</a> &#8226; <em>Sreejith Reghunathan Pillai</em></p></li><li><p><a href="https://blog.hametbenoit.info/2026/04/16/entra-id-you-can-now-synchronize-groups-with-cross-tenant-capability/">Entra ID &#8211; You can now synchronize groups with cross-tenant capability</a> &#8226; <em>Benoit Hamet</em></p></li><li><p>&#128736;&#65039; <a href="https://aboutcloud.io/i-built-a-free-microsoft-entra-id-tool-that-finds-roles-microsoft-hasnt-documented-yet/?utm_source=linkedin&amp;utm_medium=social&amp;utm_campaign=entra-rolelens-launch">I built a free Microsoft Entra ID tool that finds roles Microsoft hasn&#8217;t documented yet</a> &#8226; <em>Antonio Russo</em></p></li></ul><h2>&#129302; DevOps &amp; PowerShell</h2><ul><li><p><a href="https://office365itpros.com/2026/04/13/eventually-consistent-entra-id/">Writing PowerShell for the Eventually Consistent Entra ID Database</a> &#8226; <em>Tony Redmond</em></p></li><li><p><a href="https://www.tiagoscarvalho.com/scripts-automation/install-m365-modules">Complete Microsoft 365 PowerShell Environment Setup</a> &#8226; <em>Tiago S. Carvalho</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-4-weak-conditional-access-policies/">Common Entra ID Security Assessment Findings &#8211; Part 4: Weak Conditional Access Policies</a> &#8226; <em>Christian Feuchter</em></p></li><li><p><a href="https://agderinthe.cloud/2026/04/13/conditional-access-or-how-to-stop-playing-security-whac-a-mole/">Conditional Access, or how to stop playing security Whac-A-Mole</a> &#8226; <em>&#197;sne Holtklimpen</em></p></li><li><p><a href="https://share.google/gwMXZw1XEIgT7yd3Y">Your Conditional Access Device Filters Are a Paper Wall</a> &#8226; <em>Rawson Wade</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p><a href="https://medium.com/@erik_lindeboom/manage-external-users-in-your-microsoft-365-tenant-315fe48d814e">Manage external users in your Microsoft 365 tenant</a> &#8226; <em>Erik Lindeboom</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p>&#128250; <a href="https://www.youtube.com/watch?v=tkSRPe0VrnU">Microsoft FINALLY Adds Entra Backup&#8230; But Wait</a> (8 min) &#8226; <em>Jonathan Edwards</em></p></li><li><p>&#128736;&#65039; <a href="https://www.linkedin.com/pulse/trustm365-baseline-detect-restore-m365-anthony-porter-jnt9c/?trackingId=TCtONKAtC0aUX9ndPXeloQ%3D%3D">TrustM365 - Baseline, Detect, Restore for M365</a> &#8226; <em>Anthony Porter</em></p></li></ul><div><hr></div><h2>&#128293; Maester</h2><div id="youtube2-jHGjv5_xIKg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jHGjv5_xIKg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jHGjv5_xIKg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://maester.dev/blog/multi-tenant-reports" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!maPn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 424w, https://substackcdn.com/image/fetch/$s_!maPn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 848w, https://substackcdn.com/image/fetch/$s_!maPn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 1272w, https://substackcdn.com/image/fetch/$s_!maPn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!maPn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png" width="1456" height="1311" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1311,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:303554,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://maester.dev/blog/multi-tenant-reports&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/194658228?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!maPn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 424w, https://substackcdn.com/image/fetch/$s_!maPn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 848w, https://substackcdn.com/image/fetch/$s_!maPn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 1272w, https://substackcdn.com/image/fetch/$s_!maPn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5dd2873-d85f-4626-9fd2-0b0b28ea5207_1548x1394.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><div id="youtube2-38GcO9I1Q6A" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;38GcO9I1Q6A&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/38GcO9I1Q6A?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_syncedpasskey-collaboration-engineeringexcellence-ugcPost-7450812643780558848-9yKb?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MGXd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 424w, https://substackcdn.com/image/fetch/$s_!MGXd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 848w, https://substackcdn.com/image/fetch/$s_!MGXd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 1272w, https://substackcdn.com/image/fetch/$s_!MGXd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MGXd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png" width="1114" height="1028" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1028,&quot;width&quot;:1114,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:435001,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_syncedpasskey-collaboration-engineeringexcellence-ugcPost-7450812643780558848-9yKb?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/194658228?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MGXd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 424w, https://substackcdn.com/image/fetch/$s_!MGXd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 848w, https://substackcdn.com/image/fetch/$s_!MGXd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 1272w, https://substackcdn.com/image/fetch/$s_!MGXd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11dc3b09-2c86-48c8-a98b-52e232e483bf_1114x1028.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div id="youtube2-PEQyqJgiLzc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;PEQyqJgiLzc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/PEQyqJgiLzc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p></p><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[Stop Leaving the Door Open: The Entra ID Hardening Checklist Security Experts Actually Use]]></title><description><![CDATA[10 Ways to Lock Down Entra ID Faster]]></description><link>https://entra.news/p/stop-leaving-the-door-open-the-entra</link><guid isPermaLink="false">https://entra.news/p/stop-leaving-the-door-open-the-entra</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 18 Apr 2026 13:11:49 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/194593881/65e0a03d3329ce6e0ead821d1802fd2c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Microsoft Entra security is evolving and the way organizations think about identity protection needs to evolve with it. In this episode, I&#8217;m joined by Sean Metcalf, one of the foremost identity security experts in the industry, whose work has helped shape how many organizations approach securing both Active Directory and Microsoft Entra.<br><br>Sean shares the hardening steps many teams still overlook, and why advances in AI are making it easier for both defenders and attackers to work faster than ever before. From MFA and application controls to protecting privileged accounts and reducing unnecessary exposure, this conversation offers a practical look at where strong identity security starts and why getting the fundamentals right matters more than ever.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nMof!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nMof!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!nMof!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!nMof!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!nMof!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nMof!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3014093,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/194593881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nMof!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!nMof!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!nMof!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!nMof!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F990ab89b-a8bb-491b-a504-c58091a65cac_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-O2usv4No_DI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;O2usv4No_DI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/O2usv4No_DI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About Sean Metcalf</h3><p>Sean Metcalf is the Identity Security Architect at TrustedSec and a renowned expert in Microsoft identity security. He holds the rare Certified Master in Active Directory certification and has spoken at major security conferences including Black Hat, DEF CON, and BlueHat on how to defend cloud and hybrid environments.</p><p>LinkedIn - <a href="https://www.linkedin.com/in/seanmmetcalf/">https://www.linkedin.com/in/seanmmetcalf/</a></p><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p>Securing Entra ID Administration: Tier 0 - <a href="https://trustedsec.com/blog/securing-entra-id-administration-tier-0">https://trustedsec.com/blog/securing-entra-id-administration-tier-0</a></p></li><li><p>Managing Privileged Roles in Microsoft Entra ID: A Pragmatic Approach - <a href="https://trustedsec.com/blog/managing-privileged-roles-in-microsoft-entra-id-a-pragmatic-approach">https://trustedsec.com/blog/managing-privileged-roles-in-microsoft-entra-id-a-pragmatic-approach</a></p></li><li><p>Improve Entra ID Security More Quickly - <a href="https://adsecurity.org/?p=4825">https://adsecurity.org/?p=4825</a></p></li><li><p>Microsoft Graph Skill - <a href="https://graph.pm">https://graph.pm</a></p></li></ul><div><hr></div><h3>&#128215; Chapters</h3><p>00:04:05 AI and the Evolution of Attacks</p><p>00:06:42 The Importance of Hardening Fundamentals</p><p>00:12:03 Securing Entra ID Quickly</p><p>00:16:24 Protecting Tokens with VBS and TPM</p><p>00:19:58 Restricting Consent and Guest Users</p><p>00:23:40 Managing Rogue Tenants</p><p>00:27:36 Cloud Admin Workstation Strategies</p><p>00:34:14 Delegated Admin Privileges</p><p>00:44:32 The Danger of Application Permissions</p><p>00:57:06 Artemis Mission Trivia</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #144 → This week in Microsoft Entra]]></title><description><![CDATA[&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.]]></description><link>https://entra.news/p/entra-news-144-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-144-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 12 Apr 2026 12:07:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qQyL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>&#128075;</em> Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>There&#8217;s quite a bit from the community this week, including a mix of agents, some solid deep dives into Conditional Access gaps and identity attack paths, and a few practical security findings from the field.</p><p>From Microsoft: the planned rollout for passkeys in Microsoft registration campaigns (MC1253746) has been paused for now. Read the post below for more info.</p><p>Also, this week&#8217;s Entra Chat podcast is with Per-Torben S&#248;rensen. We go deep on designing Conditional Access policies. You&#8217;ll likely come away with at least one new idea to apply. Worth adding to your podcast queue.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;2c19569c-24e4-46ef-938b-acd3427f9497&quot;,&quot;caption&quot;:&quot;If you can&#8217;t immediately name your break glass accounts and the last time you tested them &#8594; you&#8217;re already at risk.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;How to Design Bullet-Proof Conditional Access Policies in Microsoft Entra ID&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-11T14:36:17.036Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/193877841/91095f89-d8a3-4263-9ed8-0da824e29f0b/transcoded-1775946924.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/how-to-design-bullet-proof-conditional&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193877841,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:20,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gFOz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!gFOz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!gFOz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!gFOz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gFOz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gFOz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!gFOz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!gFOz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!gFOz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F071b53e2-77c0-4fc7-9314-47c508223b41_1200x600.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>User Lifecycle: Onboard and Offboard With a Single CmdLet</strong></p><p>Fact: Managing hybrid users across AD, Entra ID, and Exchange Online is a breeding ground for missed steps and security gaps - from day one to last day.</p><p>EasyEntra&#8217;s PowerShell-enabled workflows handle the entire lifecycle:</p><p>&#128640; Onboard a fully provisioned user in 30 seconds - UI or two-parameter CmdLet.<br>&#128640; Templates defined from existing users in seconds.<br>&#128640; Offboard completely in 10 seconds - UI or single CmdLet.<br>&#128640; Offboarding settings configured once, applied consistently every time.<br>&#128640; Delegate life-cycle management to first-line support - no senior PowerShell skills or tribal knowledge required.</p><p>Start your 30-day trial or book a demo - setup takes under a minute - free for tenants with fewer than 25 licensed users.</p><p><em><strong>&#8220;It feels almost like a revolution.&#8221;</strong></em><br>Head of IT, Arjeplog Municipality, Sweden</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle&quot;,&quot;text&quot;:&quot;Wait&#8230; One CmdLet?&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle"><span>Wait&#8230; One CmdLet?</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#127942; General Availability</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-ai-prompt-injection-protection">Protect enterprise generative AI applications with prompt injection protection</a></p></li></ul><h2>&#128214; Read</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#plan-for-change--agent-registry-consolidation-into-microsoft-agent-365">Plan for change &#8211; Agent Registry consolidation into Microsoft Agent 365</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/as-ai-adoption-scales-is-your-access-strategy-still-viable/4486060">As AI adoption scales, is your access strategy still viable?</a> &#8226; <em>Kaitlin Murphy</em></p></li><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/">Inside an AI&#8209;enabled device code phishing campaign</a> &#8226; <em>Microsoft Defender Security Research Team</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1253746">MC1253746 - Microsoft Entra: Passkeys in Microsoft registration campaigns</a> - <em>Updated April 9, 2026: After further review, we have decided not to move forward with this change at this time. We will communicate via a new Message center post when we are ready to proceed. We apologize for any inconvenience this may cause and appreciate your understanding.</em></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://www.linkedin.com/pulse/hidden-gem-microsoft-entra-conditional-access-context-henrik-piecha-qp2sc?utm_source=share&amp;utm_medium=member_android&amp;utm_campaign=share_via">Hidden Gem in Microsoft Entra Conditional Access: Authentication context</a> &#8226; <em>Henrik Piecha</em></p></li><li><p>&#129352;<a href="https://office365itpros.com/2026/03/30/conditional-access-weekend-block/">Conditional Access Policies are the Best Way to Block Weekend Access to Microsoft 365</a> &#8226; <em>Tony Redmond</em></p></li><li><p>&#129353;<a href="https://www.christianfrohn.dk/2026/03/30/managing-shared-mailbox-access-with-entra-id-governance/">Managing Shared Mailbox Access with Entra ID Governance</a> &#8226; <em>Christian Frohn</em></p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://info.cloudally.com/ppc" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wN16!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 424w, https://substackcdn.com/image/fetch/$s_!wN16!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 848w, https://substackcdn.com/image/fetch/$s_!wN16!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 1272w, https://substackcdn.com/image/fetch/$s_!wN16!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wN16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png" width="1456" height="697" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:697,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:172991,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://info.cloudally.com/ppc&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wN16!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 424w, https://substackcdn.com/image/fetch/$s_!wN16!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 848w, https://substackcdn.com/image/fetch/$s_!wN16!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 1272w, https://substackcdn.com/image/fetch/$s_!wN16!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d0c58d-c204-4771-8c37-34c4198d24fb_1563x748.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://info.cloudally.com/ppc&quot;,&quot;text&quot;:&quot;Book a demo&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://info.cloudally.com/ppc"><span>Book a demo</span></a></p><div><hr></div><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/jonaswatt_microsoft365-itadmin-powershell-activity-7448333334767628288--77q?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DdIo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 424w, https://substackcdn.com/image/fetch/$s_!DdIo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 848w, https://substackcdn.com/image/fetch/$s_!DdIo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 1272w, https://substackcdn.com/image/fetch/$s_!DdIo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DdIo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png" width="1110" height="1488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1488,&quot;width&quot;:1110,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1644063,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/jonaswatt_microsoft365-itadmin-powershell-activity-7448333334767628288--77q?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DdIo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 424w, https://substackcdn.com/image/fetch/$s_!DdIo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 848w, https://substackcdn.com/image/fetch/$s_!DdIo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 1272w, https://substackcdn.com/image/fetch/$s_!DdIo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd82c4173-532b-452c-90dc-4ea053747a14_1110x1488.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/jeevansd_github-jeevansdupdateapprolesappassignment-activity-7448065270687928320-r8Cq?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QtEj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 424w, https://substackcdn.com/image/fetch/$s_!QtEj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 848w, https://substackcdn.com/image/fetch/$s_!QtEj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 1272w, https://substackcdn.com/image/fetch/$s_!QtEj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QtEj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png" width="1086" height="680" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:680,&quot;width&quot;:1086,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:139951,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/jeevansd_github-jeevansdupdateapprolesappassignment-activity-7448065270687928320-r8Cq?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QtEj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 424w, https://substackcdn.com/image/fetch/$s_!QtEj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 848w, https://substackcdn.com/image/fetch/$s_!QtEj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 1272w, https://substackcdn.com/image/fetch/$s_!QtEj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2256b417-f2a8-437e-a192-95c6bd5dd242_1086x680.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/Jorge2990/status/2042610701257314328?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8J1y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 424w, https://substackcdn.com/image/fetch/$s_!8J1y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 848w, https://substackcdn.com/image/fetch/$s_!8J1y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 1272w, https://substackcdn.com/image/fetch/$s_!8J1y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8J1y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png" width="1276" height="1508" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1508,&quot;width&quot;:1276,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:609378,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/Jorge2990/status/2042610701257314328?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8J1y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 424w, https://substackcdn.com/image/fetch/$s_!8J1y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 848w, https://substackcdn.com/image/fetch/$s_!8J1y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 1272w, https://substackcdn.com/image/fetch/$s_!8J1y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd33cb6d-8631-483a-a14f-77719b4fbaaf_1276x1508.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://blog.skymadesimple.io/microsoft-entra-agent-id-blueprints-and-microsoft-foundry-a-security-guide/">Microsoft Entra Agent ID Blueprints and Microsoft Foundry: A Security Guide</a> &#8226; <em>Jonas B&#248;gvad</em></p></li><li><p><a href="https://derkvanderwoude.medium.com/microsoft-security-copilot-for-m365-e5-e7-recommendations-from-the-field-ea32555180a5">Microsoft Security Copilot for M365 E5/E7 recommendations from the field</a> &#8226; <em>Derk van der Woude</em></p></li><li><p><a href="https://office365itpros.com/2026/04/08/microsoft-365-connector-for-claude/">Using the Microsoft 365 Connector for Claude</a> &#8226; <em>Tony Redmond</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=dOcIowhliJ4">Introduction to Agent 365 SDK</a> - <em>Microsoft Community Learning </em>(9 min) &#8226; <em>MK Bajwa</em></p></li></ul><h2>&#128179; Verified ID</h2><ul><li><p><a href="https://mjendza.net/post/agent-authorization/">Cross-Device Identity Verification via Entra Verified ID in a Multi-Agent System</a> &#8226; <em>Mateusz Jendza</em></p></li><li><p><a href="https://blog.icewolf.ch/archive/2026/04/11/entra-verified-id-upgrade-signing-key-to-become-FIPS-compliant/">Entra Verified ID Upgrade signing key to become FIPS compliant</a> &#8226; <em>Andres Bohren</em></p></li></ul><h2>&#9937;&#65039; ID Protection</h2><ul><li><p><a href="https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-3-weak-privileged-identity-management-configuration/">Common Entra ID Security Assessment Findings &#8211; Part 3: Weak Privileged Identity Management Configuration &#8211; Compass Security Blog</a> &#8226; <em>Christian Feuchter</em></p></li><li><p><a href="https://www.linkedin.com/pulse/continuing-sentinel-mcp-series-hunting-identity-risk-david-4irsf/?trackingId=Q7jwjdD%2BSuGzqdKhM5G35A%3D%3D">Continuing the Sentinel &amp; MCP Series: Hunting Identity Risk and Password Sprays</a> &#8226; <em>David Alonso Dominguez</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p><a href="https://janbakker.tech/kb-entra-private-access-session-persistence/">KB &#8211; Entra Private Access Session persistence</a> &#8226; <em>Jan Bakker</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=rujGb8CEmN0">Network-layer data protection with Microsoft Entra GSA and Purview DLP</a> (18 min) &#8226; <em>Dominik Hoefling, Heike Ritter</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://ourcloudnetwork.com/how-to-assign-application-admin-to-specific-enterprise-apps/">How to Assign Application Admin to Specific Enterprise Apps</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://office365itpros.com/2026/04/10/user-and-group-assignments/">Leverage User and Group Assignments to Limit User Access to Apps</a> &#8226; <em>Tony Redmond</em></p></li><li><p>&#127897;&#65039; <a href="https://dirteam.com/sander/2026/03/31/sean-deuby-interviews-us-on-entra-app-sprawl-for-episode-91-of-the-hip-podcast/">Entra app sprawl - HIP Podcast </a> &#8226; <em>Sander Berkouwer, Sean Deuby, Raymond Comvalius</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://blog.admindroid.com/device-preferred-credential-logic-in-system-preferred-mfa/">Device-preferred Credential Logic in System-preferred MFA</a> &#8226; <em>Shanchana</em></p></li><li><p><a href="https://michaelsendpoint.com/entra/SystemAuth.html">System &amp; Device-preferred Authentication</a> &#8226; <em>Michael Frank</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=bYGbiYrXsrM">Your MFA Is Already Broken - Microsoft Just Didn&#8217;t Tell You</a> (2 min) &#8226; <em>Azure Academy</em></p></li></ul><h2>&#128101; User &amp; Group Management</h2><ul><li><p><a href="https://office365itpros.com/2026/04/06/microsoft-365-groups-change-report/">How to Track Changes in Microsoft 365 Groups</a> &#8226; <em>Tony Redmond</em></p></li><li><p><a href="https://o365reports.com/microsoft-365-group-management-using-powershell/">Manage Microsoft 365 Groups Using a PowerShell Script</a> &#8226; <em>Blesslin Rinu</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://www.chanceofsecurity.com/post/break-glass-accounts-done-right-securing-emergency-access-in-microsoft-entra">Break-Glass Accounts Done Right: Securing Emergency Access in Microsoft Entra</a> &#8226; <em>Sebastian Fl&#230;ng Markdanner</em></p></li><li><p><a href="https://medium.com/@jhope188/conditional-access-location-location-location-and-the-gaps-we-create-cae378cd10d4?postPublishedType=initial">Conditional Access: Location, Location, Location - and the Gaps We Create</a> &#8226; <em>Jon Hope</em></p></li><li><p><a href="https://moderncloud.ca/posts/2026/demonstrating-ca-policy-gaps-using-aadinternals/">Demonstrating CA Policy Gaps using AADInternals</a> &#8226; <em>Anton Willoughby</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p>&#128250; <a href="https://www.youtube.com/watch?v=rqYzKHK3fkg">Automate Entra ID Guest Audits (Azure Automation + Graph API)</a> (8 min) &#8226; <em>Azure Brother</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://www.linkedin.com/posts/jay-kerai-cyber_entra-conditionalacess-iam-activity-7447965808904908800-Lfva/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAACFJGnAB2usCCPn7mMr26lKmkzkrZ0XkiJ4">MyStaff - hidden admin portal ??</a> &#8226; <em>Jay Kerai</em></p></li><li><p><a href="https://trustedsec.com/blog/iam-the-captain-now-hijacking-azure-identity-access">IAM the Captain Now &#8211; Hijacking Azure Identity Access</a> &#8226; <em>Justin Mahon</em></p></li><li><p>&#128736;&#65039; <a href="https://www.linkedin.com/posts/gokselatakan_goxdr-kql-query-library-activity-7445383272341278720-iCpg/">GoXDR - KQL Query Library</a> &#8226; <em>G&#246;ksel Atakan</em></p></li></ul><h2>&#9851;&#65039; Sync</h2><ul><li><p><a href="https://blog.icewolf.ch/archive/2026/04/07/entra-connect-sync-2-6-3-released/">Entra Connect Sync 2.6.3 released</a> &#8226; <em>Andres Bohren</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://cloudbymoe.com/f/microsoft-finally-built-native-backup-into-entra-id">Microsoft Finally Built Native Backup into Entra ID</a> &#8226; <em>Moe Kinani</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=-oiK0_OkHbU">Entra Backup and Recovery in Preview: Don&#8217;t Miss This</a> (4 min) &#8226; <em>Peter Rising</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=DnArCZYZF08">Entra ID Backup. What you Need to Know!</a> (12 min) &#8226; <em>Andy Malone</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=paKsqZ06EF4">Entra ID Tenant Governance is Here!</a> (11 min) &#8226; <em>Colby Pryor</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=tiKZxqDC59w">How to Audit Microsoft Entra with CIS Benchmark v6.0.1</a> (58 min) &#8226; <em>Mario Bien-Aime</em></p></li></ul><h2>&#128717;&#65039; External ID - Customers</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/on-entra-external-id-eeid-federation-with-entra-id-200ea073aecb">On Entra External ID (EEID) federation with Entra ID</a> &#8226; <em>Rory Braybrook</em></p></li></ul><div><hr></div><h2>&#128293; Maester</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_maester-activity-7448510657022332929-DXCN?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gk5J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 424w, https://substackcdn.com/image/fetch/$s_!gk5J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 848w, https://substackcdn.com/image/fetch/$s_!gk5J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 1272w, https://substackcdn.com/image/fetch/$s_!gk5J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gk5J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png" width="1094" height="1378" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1378,&quot;width&quot;:1094,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:292736,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_maester-activity-7448510657022332929-DXCN?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gk5J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 424w, https://substackcdn.com/image/fetch/$s_!gk5J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 848w, https://substackcdn.com/image/fetch/$s_!gk5J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 1272w, https://substackcdn.com/image/fetch/$s_!gk5J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07dc1098-4256-4315-a72e-6ecca11d8453_1094x1378.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><p>In Melbourne this week? I&#8217;ll be presenting a short session on MCP auth at the Identity Management Day Summit. </p><p>Come say hi! Register <a href="https://www.accelevents.com/e/identity-management-day-2026">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/identityxp_want-to-hear-what-merill-fernando-has-to-activity-7447133499800838146-pgk9?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jvPG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 424w, https://substackcdn.com/image/fetch/$s_!jvPG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 848w, https://substackcdn.com/image/fetch/$s_!jvPG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 1272w, https://substackcdn.com/image/fetch/$s_!jvPG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jvPG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png" width="1186" height="1146" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1146,&quot;width&quot;:1186,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:451367,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/identityxp_want-to-hear-what-merill-fernando-has-to-activity-7447133499800838146-pgk9?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jvPG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 424w, https://substackcdn.com/image/fetch/$s_!jvPG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 848w, https://substackcdn.com/image/fetch/$s_!jvPG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 1272w, https://substackcdn.com/image/fetch/$s_!jvPG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4dabd0ab-402d-4107-9366-3cd613ed4ea5_1186x1146.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_microsoft365-azure-sysadmin-activity-7447239732100648960-np7e?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qQyL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 424w, https://substackcdn.com/image/fetch/$s_!qQyL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 848w, https://substackcdn.com/image/fetch/$s_!qQyL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 1272w, https://substackcdn.com/image/fetch/$s_!qQyL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qQyL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png" width="1110" height="1458" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1458,&quot;width&quot;:1110,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:653988,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_microsoft365-azure-sysadmin-activity-7447239732100648960-np7e?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193947779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qQyL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 424w, https://substackcdn.com/image/fetch/$s_!qQyL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 848w, https://substackcdn.com/image/fetch/$s_!qQyL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 1272w, https://substackcdn.com/image/fetch/$s_!qQyL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff0e71b4-8ee4-41ac-9758-364800d6f96a_1110x1458.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[How to Design Bullet-Proof Conditional Access Policies in Microsoft Entra ID]]></title><description><![CDATA[Before you enable &#8216;Block All&#8217; in Entra, watch/listen to this...]]></description><link>https://entra.news/p/how-to-design-bullet-proof-conditional</link><guid isPermaLink="false">https://entra.news/p/how-to-design-bullet-proof-conditional</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 11 Apr 2026 14:36:17 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/193877841/8c77fc0ffbce85cf7fe0841b4d02ce09.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>If you can&#8217;t immediately name your break glass accounts and the last time you tested them &#8594; you&#8217;re already at risk.</p><p>In this episode of Entra Chat, Microsoft MVP Per Torben walks through the conditional access mistakes he sees even large enterprises making, and the practical framework he actually uses with customers.</p><p>You&#8217;ll learn how to set up emergency access accounts the right way, why your CA policies should be built more like a firewall than a checklist, and the one naming convention that makes managing dozens of policies actually manageable.</p><p>&#127911; Hit play, your tenant will thank you.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VnyM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VnyM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 424w, https://substackcdn.com/image/fetch/$s_!VnyM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 848w, https://substackcdn.com/image/fetch/$s_!VnyM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 1272w, https://substackcdn.com/image/fetch/$s_!VnyM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VnyM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png" width="1456" height="844" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:844,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6356693,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193877841?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VnyM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 424w, https://substackcdn.com/image/fetch/$s_!VnyM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 848w, https://substackcdn.com/image/fetch/$s_!VnyM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 1272w, https://substackcdn.com/image/fetch/$s_!VnyM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdbc801c-01d2-471e-b374-6a2c864fb4ba_2894x1678.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=podcast&amp;utm_content=4.12.26" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9H4k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!9H4k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!9H4k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!9H4k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9H4k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:211829,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=podcast&amp;utm_content=4.12.26&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193877841?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9H4k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!9H4k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!9H4k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!9H4k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6720c18e-1be1-4f11-accd-57c29d7a60ab_1200x600.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Entra ID Gaps That Cause Outages</strong></p><p>In Microsoft Entra ID, outages often start small: an expired client secret, a lapsed certificate, or a suddenly failing integration. Traditional controls don&#8217;t track credential expiry or enforce application ownership, so issues appear only after something breaks.</p><p>Teams are left asking:</p><ul><li><p>Which applications can access Microsoft 365 data?</p></li><li><p>Is that access still appropriate?</p></li><li><p>Who owns the app?</p></li></ul><p>Unclear answers stall reviews, weaken accountability, and slow delivery.</p><p>ENow App Governance Accelerator closes these gaps by highlighting expiring credentials, surfacing permission risks, and identifying ownership gaps before they disrupt operations. New Standard Tier pricing makes it accessible for organizations under 10,000 users, typically $3,500&#8211;$9,500 annually.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=podcast&amp;utm_content=4.12.26&quot;,&quot;text&quot;:&quot;Explore Entra ID Gaps&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=podcast&amp;utm_content=4.12.26"><span>Explore Entra ID Gaps</span></a></p></blockquote><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-QuNVyp9UMtI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;QuNVyp9UMtI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/QuNVyp9UMtI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About Per Torben</h3><p>Per Torben is a Senior Architect at Crayon and a Microsoft MVP for Identity and Access. Based in Norway, he frequently writes highly-read posts featured on Entra.News and runs the collaborative tech blog &#8220;Agder in the Cloud&#8221;.</p><p>LinkedIn - <a href="https://www.linkedin.com/in/pertorbensorensen/">https://www.linkedin.com/in/pertorbensorensen/</a></p><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p>Agder in the Cloud -  <a href="https://agderinthe.cloud">https://agderinthe.cloud</a></p></li><li><p>I.D.E.A. for creating/configuring break-glass accounts</p><ul><li><p>GitHub - <a href="https://github.com/Per-Torben/I.D.E.A.">https://github.com/Per-Torben/I.D.E.A.</a></p></li><li><p>Blog - <a href="https://agderinthe.cloud/2026/01/06/introducing-i-d-e-a-and-i-d-e-a-001/">https://agderinthe.cloud/2026/01/06/introducing-i-d-e-a-and-i-d-e-a-001/</a></p></li></ul></li><li><p>Protected actions: <a href="https://agderinthe.cloud/2025/02/12/protected-actions-adding-extra-guards-to-your-entra-id-gate/">https://agderinthe.cloud/2025/02/12/protected-actions-adding-extra-guards-to-your-entra-id-gate/</a></p></li><li><p>Conditional Access hardeing (series): <a href="https://agderinthe.cloud/2024/12/05/how-to-fix-the-fundamental-flaw-in-conditional-access-part-1-introduction-and-coverage-gaps">https://agderinthe.cloud/2024/12/05/how-to-fix-the-fundamental-flaw-in-conditional-access-part-1-introduction-and-coverage-gaps</a><br>CA geo filter (series): <a href="https://agderinthe.cloud/2025/11/06/diving-into-geo-filter-with-entra-conditional-access-part-1">https://agderinthe.cloud/2025/11/06/diving-into-geo-filter-with-entra-conditional-access-part-1</a></p></li><li><p>Entra Backup - <a href="https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/backup-restore">https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/backup-restore</a></p></li></ul><div><hr></div><h3>&#128215; Chapters</h3><p>06:22 The importance of Break Glass accounts</p><p>09:02 Securing emergency access with FIDO2 and RMAUs</p><p>18:10 Configuring Conditional Access: The &#8220;Block by Default&#8221; strategy</p><p>27:26 Managing scope and preventing accidental lockouts</p><p>29:31 Persona-based naming conventions for CA policies</p><p>35:38 Grouping settings and avoiding bloated policies</p><p>41:54 Handling exceptions and travel access with Access Packages</p><p>44:55 The flaw in Protected Actions for Conditional Access</p><p>53:38 Using the new Entra Backup feature for quick restores</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #143 → This week in Microsoft Entra]]></title><description><![CDATA[&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.]]></description><link>https://entra.news/p/entra-news-143-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-143-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 05 Apr 2026 12:29:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5kaY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>Well folks, there&#8217;s a lot happening in the Entra world, we have over seven features becoming GA, a bunch of new public preview features, and an upcoming change to enforce CA policies during WHfB registration. Check them all out below.</p><p>BTW, I caught up with some Microsoft Entra MVPs to get their take on the big updates&#8212;queue it up on Spotify, Apple Podcasts, or watch on YouTube &#128071;</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b51edfb1-81cc-4cc9-9354-4dc667e7d9c0&quot;,&quot;caption&quot;:&quot;Microsoft just dropped a massive wave of features for Entra, and the rules of Tenant Governance have officially changed.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;5 Entra ID Updates You Can&#8217;t Afford to Ignore in 2026 (Backup, Governance, CA Agent &amp; Risk Score Exposed)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-04-04T11:57:26.050Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/youtube/w_728,c_limit/2C6G9M1aOko&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/5-entra-id-updates-you-cant-afford&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193146126,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:13,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.alteredsecurity.com/azure-red-team-month?utm_source=Entra.News&amp;utm_medium=Post&amp;utm_campaign=MoART2026" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J8vh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!J8vh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!J8vh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!J8vh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J8vh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:660199,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.alteredsecurity.com/azure-red-team-month?utm_source=Entra.News&amp;utm_medium=Post&amp;utm_campaign=MoART2026&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193240079?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J8vh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!J8vh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!J8vh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!J8vh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc904baf3-317c-42e9-a660-a24e64ecf79c_2560x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Announcing the Month of Azure Red Teaming 2026</strong></p><p>Altered Security Month of Azure Red Teaming is an initiative to raise awareness and spark discussion around one of the most critical and in-demand skillsets: Azure Red Teaming. Throughout the month we want to keep the community engaged to help infosec professionals and students understand, practice and analyze attack vectors in Azure.</p><p>What to expect during the month:</p><p>- Four Free Azure Red Team Webinars with hands-on labs (April 10th, 17th, 24th and 30th).</p><p>- Flat 20% OFF on the accoladed Azure Red Team certifications: CARTP and CARTE.</p><p>- Free labs on Altered Security&#8217;s Red Labs Platform</p><p>Get ready for a month full of free labs, webinars, blog posts, giveaways and discounts!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.alteredsecurity.com/azure-red-team-month?utm_source=Entra.News&amp;utm_medium=Post&amp;utm_campaign=MoART2026&quot;,&quot;text&quot;:&quot;Know More&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.alteredsecurity.com/azure-red-team-month?utm_source=Entra.News&amp;utm_medium=Post&amp;utm_campaign=MoART2026"><span>Know More</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#127942; General Availability</h2><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/microsoft-entra-expands-scim-support-with-new-scim-2-0-apis-for-identity-lifecyc/4507465">Microsoft Entra expands SCIM support with new SCIM 2.0 APIs for identity lifecycle operations</a> &#8226; <em>Joseph Dadzie</em></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---microsoft-single-sign-on-for-linux-support-for-authenticating-with-phish-resistant-mfa-credentials">Microsoft Single Sign-On for Linux support for authenticating with Phish-Resistant MFA credentials</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---new-m365-group-creation-experience-in-my-groups">New M365 group creation experience in My Groups</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---microsoft-entra-connect-health-now-enforces-tls-12">Microsoft Entra Connect Health now enforces TLS 1.2</a></p></li><li><p><a href="https://devblogs.microsoft.com/identity/native-auth-social-idps-web-view-ga/">General Availability: Social Identity Providers for Native Authentication via Browser&#8209;Delegated Flows (web-view) in Microsoft Entra External ID</a> &#8226; <em>Sasha Mars</em></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---justintime-password-migration-in-microsoft-entra-external-id">Just&#8209;in&#8209;Time Password Migration in Microsoft Entra External ID</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---enabling-email-and-sms-otp-mfa-in-entra-external-id-native-authentication">Enabling Email and SMS OTP MFA in Entra External ID Native Authentication</a></p></li></ul><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/security-copilot/conditional-access-agent-optimization-phased-rollout">Phased Rollout with the Conditional Access Agent</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/security-copilot/conditional-access-agent-optimization-passkeys">Passkey Adoption Campaigns with the Conditional Access Optimization Agent</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join-using-microsoft-entra-kerberos">Microsoft Entra hybrid join using Microsoft Entra Kerberos</a></p></li></ul><h2>&#128214; Read</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/global-secure-access/troubleshoot-global-secure-access-mobile-client-health-check-utility">Troubleshoot the Global Secure Access mobile client with Health check utility</a> &#8226; <em>Microsoft Learn</em></p></li></ul><h2>&#128250; Watch</h2><ul><li><p><a href="https://www.youtube.com/watch?v=V6-k8Jev_tg">Developer Tools for Agent ID: SDKs, CLIs &amp; Samples</a> (37 min) &#8226; <em>Kyle Marsh</em></p></li><li><p><a href="https://www.youtube.com/watch?v=5ivST2bw7uQ">Self&#8209;Service Account Recovery with Microsoft Entra</a> (2 min) &#8226; <em>Microsoft Security</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1260708">MC1260708 - Microsoft Entra ID: Improved readability for Authentication Methods Policy Update audit logs</a></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://tech.nicolonsky.ch/entra-id-protection-stop-account-breach/">Don&#8217;t let Entra ID Protection miss your next breach!</a> &#8226; <em>Nicola Suter</em></p></li><li><p>&#129352;<a href="https://medium.com/@jhope188/conditional-access-ca-analyzer-product-updates-702f247b3d7f">Conditional Access: CA Analyzer Product Updates</a> &#8226; <em>Jon Hope</em></p></li><li><p>&#129353;<a href="https://blog.admindroid.com/remove-inactive-guest-users-using-power-automate-approval-workflow/">How to Automate Inactive Guest User Removal in Microsoft 365 Using Power Automate</a> &#8226; <em>Dhinesh</em></p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="http://Get Your App Risk Score" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S6za!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!S6za!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!S6za!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!S6za!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S6za!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:150689,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://Get Your App Risk Score&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193240079?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S6za!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!S6za!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!S6za!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!S6za!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e570ae8-d59f-4f7e-ae3d-7c14574914a7_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Uncover Entra App Risk in Minutes</strong></p><p>Most Entra ID tenants contain hundreds of applications with unclear ownership, excessive OAuth permissions, and long-lived secrets. These gaps are difficult to identify using native tools alone, especially at scale.</p><p>ENow&#8217;s<strong> <a href="https://www.appgovscore.com/">AppGov Score</a></strong> provides a read-only assessment of your Entra environment using 24 Microsoft-aligned checks. It surfaces risky consent grants, privileged service principals, expired credentials, and ownerless apps, then translates findings into a clear, defensible risk score.</p><p>Instead of manual reviews or scripting, administrators gain immediate visibility into application sprawl and permission exposure, making it easier to prioritize remediation and improve governance across Microsoft 365.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=4.5.26&quot;,&quot;text&quot;:&quot;Get Your App Risk Score&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=4.5.26"><span>Get Your App Risk Score</span></a></p></blockquote><div><hr></div><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/fabianbader_entraid-activity-7446181708883709952-ONXg?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5kaY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 424w, https://substackcdn.com/image/fetch/$s_!5kaY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 848w, https://substackcdn.com/image/fetch/$s_!5kaY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 1272w, https://substackcdn.com/image/fetch/$s_!5kaY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5kaY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png" width="1180" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1180,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:241099,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/fabianbader_entraid-activity-7446181708883709952-ONXg?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193240079?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5kaY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 424w, https://substackcdn.com/image/fetch/$s_!5kaY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 848w, https://substackcdn.com/image/fetch/$s_!5kaY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 1272w, https://substackcdn.com/image/fetch/$s_!5kaY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff1d41d0-f3b7-4b4e-9aa7-ca90cf53cd62_1180x760.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/activity-7445417161067737088-PlfR?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rnQD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 424w, https://substackcdn.com/image/fetch/$s_!rnQD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 848w, https://substackcdn.com/image/fetch/$s_!rnQD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 1272w, https://substackcdn.com/image/fetch/$s_!rnQD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rnQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png" width="1118" height="1672" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1672,&quot;width&quot;:1118,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:512146,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/activity-7445417161067737088-PlfR?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193240079?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rnQD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 424w, https://substackcdn.com/image/fetch/$s_!rnQD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 848w, https://substackcdn.com/image/fetch/$s_!rnQD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 1272w, https://substackcdn.com/image/fetch/$s_!rnQD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62378a6a-5744-490f-b2b2-01e19487944d_1118x1672.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://derkvanderwoude.medium.com/your-copilot-studio-agent-is-acting-as-someone-do-you-know-who-f9e5be1116b9?source=rss-108a26c58aec------2">Your Copilot Studio agent is acting as someone, do you know who?</a> &#8226; <em>Derk van der Woude</em></p></li><li><p>&#127897;&#65039; <a href="https://share.transistor.fm/s/0901950b">Governing the Ungoverned: Agent 365 and Entra Agent ID</a> &#8226; <em>Jussi Roine &amp; Tobias Zimmergren</em></p></li></ul><h2>&#129520; Workload ID</h2><ul><li><p><a href="https://sameerbhanushali.substack.com/p/spiffe-and-spire-the-workload-identity">&#128272; SPIFFE &amp; SPIRE: The Workload Identity Standard Quietly Powering Zero Trust</a> &#8226; <em>Sameer Bhanushali</em></p></li></ul><h2>&#128110;&#8205;&#9794;&#65039; ID Governance</h2><ul><li><p><a href="https://fromthecido.com/how-to-extend-entra-provisioning-to-apps-without-scim-or-api/">How to Extend Entra Provisioning to Apps Without SCIM or API</a> &#8226; <em>Nick Hunt</em></p></li><li><p><a href="https://www.christianfrohn.dk/2026/03/30/managing-shared-mailbox-access-with-entra-id-governance/">Managing Shared Mailbox Access with Entra ID Governance</a> &#8226; <em>Christian Frohn</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=wQkJDo3iJPM">Access Reviews Reimagined: What&#8217;s New in Microsoft Entra</a> (6 min) &#8226; <em>Peter Rising</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p>&#128736;&#65039; <a href="https://tdetzner.github.io/GSA-PrivateAccess-Connector-Planner/">GSA Private Access Sizing Planner</a> &#8226; <em>Thomas Detzner</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://securitywithtom.com/posts/A-Token-of-Appreciation/">A Token of Appreciation - JWTs &amp; Microsoft Authentication for Security Research</a> &#8226; <em>Tom Rolvers</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://www.nickydewestelinck.be/2026/03/31/seamless-access-using-qr-code-signin-on-android-enterprise-shared-devices-with-microsoft-entra/">Seamless Access: Using QR Code Sign&#8209;In on Android Enterprise Shared Devices with Microsoft Entra</a> &#8226; <em>Nicky De Westelinck</em></p></li></ul><h2>&#128101; User &amp; Group Management</h2><ul><li><p><a href="https://blog.admindroid.com/cross-tenant-group-synchronization-in-microsoft-entra-id/">How to Configure Cross-Tenant Group Synchronization in Microsoft Entra ID</a> &#8226; <em>Karthi</em></p></li><li><p><a href="https://michev.info/blog/post/7671/ownerless-group-policy-finally-supported-by-the-graph-api">Ownerless Group Policy finally supported by the Graph API</a> &#8226; <em>Vasil Michev</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://office365itpros.com/2026/03/30/conditional-access-weekend-block/">Conditional Access Policies are the Best Way to Block Weekend Access to Microsoft 365</a> &#8226; <em>Tony Redmond</em></p></li><li><p><a href="https://www.linkedin.com/pulse/hidden-gem-microsoft-entra-conditional-access-context-henrik-piecha-qp2sc?utm_source=share&amp;utm_medium=member_android&amp;utm_campaign=share_via">Hidden Gem in Microsoft Entra Conditional Access: Authentication context</a> &#8226; <em>Henrik Piecha</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p><a href="https://www.thetechtrails.com/2026/04/microsoft-entra-hybrid-join-using-entra-kerberos.html">Microsoft Entra Hybrid Join Using Entra Kerberos &#8211; Step-by-Step Guide Without Sync Dependency</a> &#8226; <em>Sreejith Reghunathan Pillai</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p>&#128250; <a href="https://www.youtube.com/watch?v=TY7oZ-EogoQ">Entra ID - Guest User Governance &#8211; Licensing Made Easy</a> (2 min) &#8226; <em>Julian Rasmussen MVP</em></p></li></ul><h2>&#128200; Reporting and Insights</h2><ul><li><p><a href="https://office365itpros.com/2026/03/31/entra-id-group-insights/">How to Report Entra ID Group Insights</a> &#8226; <em>Tony Redmond</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://xybytes.com/azure/Abusing-Overly-Permissive-Role-in-Azure-File-Sync/">Abusing Overly Permissive Roles in Azure File Sync</a> &#8226; <em>Christian Bortone</em></p></li><li><p><a href="https://blog.compass-security.com/2026/03/common-entra-id-security-assessment-findings-part-2-privileged-unprotected-groups/">Common Entra ID Security Assessment Findings &#8211; Part 2: Privileged Unprotected Groups</a> &#8226; <em>Christian Feuchter</em></p></li><li><p>&#128736;&#65039; <a href="https://goxdr.fyi/">GoXDR - KQL Query Library</a> &#8226; <em>G&#246;ksel Atakan</em></p></li></ul><h2>&#9851;&#65039; Sync</h2><ul><li><p><a href="https://cloudbymoe.com/f/hard-match-sync-hijacking-the-part-everyone-skips-over">Hard Match &amp; Sync Hijacking! The Part Everyone Skips Over</a> &#8226; <em>Moe Kinani</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://idefixwiki.no/post/Entra-ID-Backup-and-Recovery/">Entra ID Backup and Recovery</a> &#8226; <em>Julian Rasmussen</em></p></li><li><p><a href="https://michev.info/blog/post/7696/introduction-to-microsoft-tenant-governance-part-1-basics-and-establishing-relationships">Introduction to Microsoft Tenant Governance part 1: basics and establishing relationships</a> &#8226; <em>Vasil Michev</em></p></li><li><p><a href="https://michev.info/blog/post/7782/introduction-to-microsoft-tenant-governance-part-2-tenant-discovery-and-creation">Introduction to Microsoft Tenant Governance part 2: tenant discovery and creation</a> &#8226; <em>Vasil Michev</em></p></li><li><p><a href="https://www.cloudcoffee.ch/microsoft-azure/microsoft-entra-backup-and-recovery/">Microsoft Entra Backup and Recovery: Prerequisites, Backup, and Restore in Detail</a> &#8226; <em>Oliver M&#252;ller</em></p></li><li><p><a href="https://michaelsendpoint.com/entra/BackupAndRecovery.html">Tenant governance</a> &#8226; <em>Michael Frank</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=S5W-tYAYJFc">Entra ID Free vs Premium in 2026 - Is Premium Worth It?</a> (22 min) &#8226; <em>Andy Malone</em></p></li></ul><div><hr></div><h2>&#128293; Maester</h2><ul><li><p><a href="https://maester.dev/blog/azuredevops-tests-for-maester">Azure DevOps tests for Maester</a> &#8226; Sebastian Claesson</p></li></ul><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[5 Entra ID Updates You Can’t Afford to Ignore in 2026 (Backup, Governance, CA Agent & Risk Score Exposed)]]></title><description><![CDATA[Listen now | The Hidden Entra Diff Report That Catches Changes Even Microsoft Makes to Your Tenant]]></description><link>https://entra.news/p/5-entra-id-updates-you-cant-afford</link><guid isPermaLink="false">https://entra.news/p/5-entra-id-updates-you-cant-afford</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 04 Apr 2026 11:57:26 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/193146126/26e0ccd688e1a73fa0dd017ea8aca214.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Microsoft just dropped a massive wave of features for Entra, and the rules of Tenant Governance have officially changed. </p><p>Join us as we talk to three world-class MVPs about their hands-on experience with the new <strong>Entra Backup and Recovery</strong> and <strong>Tenant Governance</strong> features.</p><p>Our Microsoft MVP guests Nathan McNulty, Ru Campbell, and Thomas Naunheim break down the most exciting new features in Microsoft Entra.</p><p>In this episode, we explore:</p><ul><li><p><strong>The &#8220;Shadow Tenant&#8221; Problem:</strong> One org found 700+ Entra tenants they didn&#8217;t know they had.</p></li><li><p><strong>Version Control for Admins:</strong> Why &#8220;Difference Reports&#8221; are a total game-changer for troubleshooting.</p></li><li><p><strong>Recovery Safeguards:</strong> How to protect your tenant from accidental deletions and &#8220;sneaky&#8221; background changes.</p></li><li><p><strong>Backup &amp; Recovery:</strong> The truth about Entra Backup vs. Third-Party ISV tools.</p><p></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CPp2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CPp2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 424w, https://substackcdn.com/image/fetch/$s_!CPp2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 848w, https://substackcdn.com/image/fetch/$s_!CPp2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 1272w, https://substackcdn.com/image/fetch/$s_!CPp2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CPp2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png" width="1456" height="738" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:738,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6730406,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/193146126?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CPp2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 424w, https://substackcdn.com/image/fetch/$s_!CPp2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 848w, https://substackcdn.com/image/fetch/$s_!CPp2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 1272w, https://substackcdn.com/image/fetch/$s_!CPp2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cddbf8c-1ab4-4ff3-8ad2-bc9f2387bdb9_2804x1422.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-2C6G9M1aOko" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;2C6G9M1aOko&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/2C6G9M1aOko?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About The Guests</h3><p>Nathan, Ru, and Thomas are highly experienced MVPs specializing in identity security, governance, and Microsoft Entra.</p><p>Nathan McNulty - LinkedIn - <a href="https://www.linkedin.com/in/nathanmcnulty/">https://www.linkedin.com/in/nathanmcnulty/</a></p><p>Ru Campbell - LinkedIn - <a href="https://www.linkedin.com/in/rlcam/">https://www.linkedin.com/in/rlcam/</a></p><p>Thomas Naunheim LinkedIn - <a href="https://www.linkedin.com/in/thomasnaunheim/">https://www.linkedin.com/in/thomasnaunheim/</a></p><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p>Microsoft Entra Backup and Recovery Documentation - https://learn.microsoft.com/en-us/entra/backup/overview</p></li><li><p>Microsoft Entra Tenant Governance - https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview</p></li><li><p>Synced Passkeys - https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-passkeys-fido2</p></li><li><p>Microsoft Work IQ CLI (Public Preview) - https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/workiq-overview</p></li><li><p>Playwright https://playwright.dev/</p></li><li><p>Entra Auth Tracer (Chrome Extension)  - https://github.com/darrenjrobinson/EntraAuthTracer</p></li><li><p>Unified Risk Score - https://learn.microsoft.com/en-us/defender-xdr/investigate-users#risk-score-tab-preview</p></li></ul><div><hr></div><h3>&#128215; Chapters</h3><p>00:00 Intro to New Entra Features</p><p>02:04 Entra Backup and Recovery Deep Dive</p><p>10:41 Difference Reports Explained</p><p>15:54 Intro to Tenant Governance</p><p>23:34 Managing Multi-Tenant Organizations</p><p>33:31 Conditional Access Optimization Agent</p><p>36:55 The Great Passkey Debate</p><p>47:22 Retirements: SP-less Auth &amp; ACS for SharePoint</p><p>48:46 Unified Risk Score in Defender</p><p>52:38 MVP Tips of the Week</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #142 → This week in Microsoft Entra]]></title><description><![CDATA[&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.]]></description><link>https://entra.news/p/entra-news-142-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-142-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 29 Mar 2026 12:15:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cgJj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>&#128075;</em> Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>The big news this week is the official launch of Entra Backup and Recovery and Entra Tenant Governance, along with new updates to the CA Optimization Agent.</p><p>There&#8217;s an upcoming change that may impact applications using Microsoft Graph app-only permissions. Check out the blog post <em>&#8220;<a href="https://devblogs.microsoft.com/identity/designing-for-eventual-consistency-for-microsoft-entra/">Designing for Eventual Consistency</a>&#8221;</em> for more details.</p><p>Don&#8217;t forget to catch up on this week&#8217;s Entra Chat podcast with Emilien Socchi, where we dig into two of his interesting projects.</p><p>Enjoy!</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;4c5c940f-5bf0-428e-9f4a-fc243c3719cc&quot;,&quot;caption&quot;:&quot;Emilien Socchi, Cloud Security Research Engineer at Storebrand, joins us to discuss CA Insight and AZTier.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Finding Every MFA Gap: Testing 250 Million Conditional Access Combinations in Under 20 Minutes&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-03-28T10:45:12.878Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/192389064/20f5cc31-7c3f-4425-863c-d46853d901b1/transcoded-1774694217.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/finding-every-mfa-gap-testing-250&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:192389064,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FYk_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!FYk_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!FYk_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!FYk_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FYk_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/192478304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FYk_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!FYk_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!FYk_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!FYk_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69ca3c1d-bd86-464a-bf8a-73dca8aee74d_1200x600.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>User Lifecycle: Onboard and Offboard With a Single CmdLet</strong></p><p>Fact: Managing hybrid users across AD, Entra ID, and Exchange Online is a breeding ground for missed steps and security gaps - from day one to last day.</p><p>EasyEntra&#8217;s PowerShell-enabled workflows handle the entire lifecycle:</p><p>&#128640; Onboard a fully provisioned user in 30 seconds - UI or two-parameter CmdLet.<br>&#128640; Templates defined from existing users in seconds.<br>&#128640; Offboard completely in 10 seconds - UI or single CmdLet.<br>&#128640; Offboarding settings configured once, applied consistently every time.<br>&#128640; Delegate life-cycle management to first-line support - no senior PowerShell skills or tribal knowledge required.</p><p>Start your 30-day trial or book a demo - setup takes under a minute - free for tenants with fewer than 25 licensed users.</p><p><em><strong>&#8220;It feels almost like a revolution.&#8221;</strong></em><br>Head of IT, Arjeplog Municipality, Sweden</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle&quot;,&quot;text&quot;:&quot;Wait&#8230; One CmdLet?&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle"><span>Wait&#8230; One CmdLet?</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#127942; General Availability</h2><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/external-mfa-in-microsoft-entra-id-is-now-generally-available/4488926">External MFA in Microsoft Entra ID is now Generally Available</a> &#8226; <em>Swaroop Krishnamurthy</em></p></li></ul><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac/4462426">Strengthen Identity Resilience: Recover with Confidence using Microsoft Entra Backup and Recovery</a> &#8226; <em>Joseph Dadzie</em></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/microsoft-entra-tenant-governance-secure-and-manage-multi-tenant-environments-at/4462427">Microsoft Entra Tenant Governance: Secure and Manage Multi-Tenant Environments at Scale</a> &#8226; <em>Joseph Dadzie</em></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/evolving-identity-security-how-the-conditional-access-optimization-agent-helps-y/4488927">Evolving Identity Security: How the Conditional Access Optimization Agent Helps You Adapt</a> &#8226; <em>Swaroop Krishnamurthy</em></p></li></ul><h2>&#128214; Read</h2><ul><li><p><a href="https://devblogs.microsoft.com/identity/designing-for-eventual-consistency-for-microsoft-entra/">Designing for Eventual Consistency for Microsoft Entra</a> &#8226; <em>Kyle Marsh</em></p></li><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/25/identity-security-is-the-new-pressure-point-for-modern-cyberattacks/">Identity security is the new pressure point for modern cyberattacks</a> &#8226; <em>Rob Lefferts, Nadim Abdo</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1262589">MC1262589 - New M365 group creation and editing in My Groups</a></p></li><li><p><a href="https://mc.merill.net/message/MC1261596">MC1261596 - Notice: Security Copilot will be included as part of your Microsoft 365 E5 plan soon</a></p></li><li><p><a href="https://mc.merill.net/message/MC1260708">MC1260708 - Microsoft Entra ID: Improved readability for Authentication Methods Policy Update audit logs</a></p></li><li><p><a href="https://mc.merill.net/message/MC1248389">MC1248389 - Retirement of -Credential parameter when connecting to Exchange Online PowerShell</a></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://ourcloudnetwork.com/microsoft-quietly-closes-another-loophole-for-tenant-domain-enumeration/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-quietly-closes-another-loophole-for-tenant-domain-enumeration">Microsoft Quietly Closes Another Loophole for Tenant Domain Enumeration</a> &#8226; <em>Daniel Bradley</em></p></li><li><p>&#129352;<a href="https://office365itpros.com/2026/03/18/microsoft-graph-issues/">The Sad State of Microsoft Graph and Other APIs</a> &#8226; <em>Tony Redmond</em></p></li><li><p>&#129353;<a href="https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/">Conditional Access Optimization Agent knowledge base</a> &#8226; <em>Jan Bakker</em></p></li></ul><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/IAMERICAbooted/status/2037910612139807141?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KEab!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 424w, https://substackcdn.com/image/fetch/$s_!KEab!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 848w, https://substackcdn.com/image/fetch/$s_!KEab!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 1272w, https://substackcdn.com/image/fetch/$s_!KEab!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KEab!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png" width="1254" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:230681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/IAMERICAbooted/status/2037910612139807141?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/192478304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KEab!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 424w, https://substackcdn.com/image/fetch/$s_!KEab!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 848w, https://substackcdn.com/image/fetch/$s_!KEab!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 1272w, https://substackcdn.com/image/fetch/$s_!KEab!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d549f8-9d6b-4ac9-baea-f784411a0167_1254x970.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://derkvanderwoude.medium.com/from-blueprint-to-token-how-entra-agent-identity-inheritance-really-works-fed114abe281?source=rss-108a26c58aec------2">From Blueprint to Token: How Entra Agent Identity Inheritance Really Works</a> &#8226; <em>Derk van der Woude</em></p></li><li><p><a href="https://blog.mindcore.dk/2026/03/microsoft-365-e7-the-frontier-suite-and-the-rise-of-ai-agents/">Microsoft 365 E7: The Frontier Suite and the Rise of AI Agents</a> &#8226; <em>Konstantin Slavin-Borovskij</em></p></li><li><p><a href="https://thalpius.com/2026/03/28/microsoft-entra-agent-id-a-practical-guide-to-blueprints-and-agent-identities/">Microsoft Entra Agent ID: A Practical Guide to Blueprints and Agent Identities</a> &#8226; <em>Raymond Roethof</em></p></li></ul><h2>&#128179; Verified ID</h2><ul><li><p><a href="https://www.youtube.com/watch?v=7l5vDNXPY1E">Build secure verification with Microsoft Entra Verified ID</a> (14 min) &#8226; <em>Yoel Horvitz</em></p></li></ul><h2>&#9937;&#65039; ID Protection</h2><ul><li><p><a href="https://tech.nicolonsky.ch/entra-id-protection-stop-account-breach/">Don&#8217;t let Entra ID Protection miss your next breach!</a> &#8226; <em>Nicola Suter</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=KLIJZhuiv9A&amp;si=O6ItZadSZ5x_BLN4">Sign-In Risk vs User Risk - Most Admins Don&#8217;t Know the Difference</a> (14 min) &#8226; <em>Jonathan Edwards</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://blog.compass-security.com/2026/03/common-entra-id-security-assessment-findings-part-1-foreign-enterprise-applications-with-privileged-api-permissions/">Common Entra ID Security Assessment Findings &#8211; Part 1: Foreign Enterprise Applications With Privileged API Permissions</a> &#8226; <em>Christian Feuchter</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p>&#128736;&#65039; <a href="https://blog.darrenjrobinson.com/entra-auth-tracer/">Entra Auth Tracer &#8211; A Browser Extension for Deep Inspection of Microsoft Entra Authentication Flows</a> &#8226; <em>Darren Robinson</em></p></li><li><p><a href="https://www.linkedin.com/posts/skrubbeltrang_the-exchange-attribute-soa-switch-works-like-activity-7443199142857703424-bDa9?utm_source=share&amp;utm_medium=member_android&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0">The Exchange attribute SOA switch and licencing woes</a> &#8226; <em>Morten Skrubbeltrang</em></p></li></ul><h2>&#129302; DevOps &amp; PowerShell</h2><ul><li><p><a href="https://devblogs.microsoft.com/devops/authentication-tokens-are-not-a-data-contract/">Authentication Tokens Are Not a Data Contract - Azure DevOps Blog</a> &#8226; <em>Angel Wong</em></p></li><li><p><a href="https://o365reports.com/convert-external-users-to-internal-users-in-bulk-using-powershell/">Bulk Convert External Users to Internal Users Using PowerShell</a> &#8226; <em>Kanaga</em></p></li><li><p><a href="https://blog.admindroid.com/remove-inactive-guest-users-using-power-automate-approval-workflow/">How to Automate Inactive Guest User Removal in Microsoft 365 Using Power Automate</a> &#8226; <em>Dhinesh</em></p></li><li><p><a href="https://office365itpros.com/2026/03/26/sensitive-message-properties-graph/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=sensitive-message-properties-graph">Microsoft Limits App Access to Sensitive Message Properties</a> &#8226; <em>Tony Redmond</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://www.prajwaldesai.com/block-microsoft-365-apps-using-conditional-access-policy/">Block Microsoft 365 Apps using Conditional Access Policy</a> &#8226; <em>Prajwal Desai</em></p></li><li><p><a href="https://medium.com/@jhope188/conditional-access-ca-analyzer-product-updates-702f247b3d7f">Conditional Access: CA Analyzer Product Updates</a> &#8226; <em>Jon Hope</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p><a href="https://www.prajwaldesai.com/kb5085516-oob-update-resolves-microsoft-account-sign-in-issues/">KB5085516 OOB Update Resolves Microsoft account sign in Issues</a> &#8226; <em>Prajwal Desai</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=wivHVp3lGqE&amp;si=raS80FaxaE-VFYof">Passwordless Windows for BYOD: Entra ID Passkeys Explained</a> (9 min) &#8226; <em>Azure Brother</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p><a href="https://www.cloud-architekt.net/tenant-governance-relationship-cross-tenant-delegation/">B2B or Not 2B? Cross-Tenant Delegated Administration with Microsoft Entra Tenant Governance</a> &#8226; <em>Thomas Naunheim</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://blog.admindroid.com/microsoft-adds-ai-pillar-to-zero-trust-workshop/">Microsoft Zero Trust Workshop Expands with a Dedicated AI Pillar</a> &#8226; <em>Praba</em></p></li></ul><h2>&#9851;&#65039; Sync</h2><ul><li><p><a href="https://identity-man.eu/2026/03/27/getting-started-with-entra-connect-cloud-sync/">Getting started with Entra Connect Cloud Sync</a> &#8226; <em>Pim Jacobs</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://office365itpros.com/2026/03/23/entra-id-backup-and-recovery/">Low-Key Debut for Entra ID Backup and Recovery</a> &#8226; <em>Tony Redmond</em></p></li><li><p><a href="https://lazyadmin.nl/office-365/microsoft-entra-backup-and-recovery/">Microsoft Entra Backup and Recovery</a> &#8226; <em>Rudy Mens</em></p></li><li><p><a href="https://medium.com/@jhope188/microsoft-entra-id-gets-native-backup-and-recovery-what-you-need-to-know-f9f4297e3c3e">Microsoft Entra ID Gets Native Backup and Recovery &#8212; What You Need to Know</a> &#8226; <em>Jon Hope</em></p></li><li><p><a href="https://michaelsendpoint.com/entra/Governance.html">Tenant governance | Entra ID</a> &#8226; <em>Michael Frank</em></p></li></ul><ul><li><p>&#127897;&#65039; <a href="https://runasradio.com/Shows/Show/1029">Unified Tenant Management with Nik Charlebois-Laprade</a> &#8226; <em>Nik Charlebois, Richard Campbell</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=72nowrDIlQU">Overview of Entra Backup and Recovery</a> (11 min) &#8226; <em>John Savill</em></p></li></ul><h2>&#128717;&#65039; External ID - Customers</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/connecting-entra-external-id-eeid-to-entra-id-as-an-external-provider-via-oidc-3fd62e2cba53?source=rss-6601e21c1210------2">Connecting Entra External ID (EEID) to Entra ID as an external provider via OIDC</a> &#8226; <em>Rory Braybrook</em></p></li></ul><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cgJj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 424w, https://substackcdn.com/image/fetch/$s_!cgJj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 848w, https://substackcdn.com/image/fetch/$s_!cgJj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 1272w, https://substackcdn.com/image/fetch/$s_!cgJj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cgJj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp" width="800" height="1000" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1000,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cgJj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 424w, https://substackcdn.com/image/fetch/$s_!cgJj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 848w, https://substackcdn.com/image/fetch/$s_!cgJj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 1272w, https://substackcdn.com/image/fetch/$s_!cgJj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff280b5d6-4645-4098-a0e0-ca46b0d1252b_800x1000.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7hp8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!7hp8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!7hp8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!7hp8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7hp8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp" width="1200" height="1500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1500,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7hp8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!7hp8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!7hp8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!7hp8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb0e2c0-34f5-4a1b-bf5e-ee65c1c33b1a_1200x1500.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZIuz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!ZIuz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!ZIuz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!ZIuz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZIuz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp" width="1200" height="1500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1500,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZIuz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!ZIuz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!ZIuz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!ZIuz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26cbfcbb-78d6-4151-8983-6a85fe5b61fa_1200x1500.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!osFU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!osFU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!osFU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!osFU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!osFU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp" width="1200" height="1500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1500,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!osFU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!osFU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!osFU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!osFU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5832a5fe-9213-4f12-ad87-c0d790fb80b6_1200x1500.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z4-h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!z4-h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!z4-h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!z4-h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z4-h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp" width="1200" height="1500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1500,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z4-h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!z4-h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!z4-h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!z4-h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c1f306d-142f-459b-94bf-0302040ff30b_1200x1500.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FvtN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!FvtN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!FvtN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!FvtN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FvtN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp" width="1200" height="1500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1500,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FvtN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!FvtN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!FvtN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!FvtN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F642eafb1-43c1-4dba-9e48-b9a1e6626187_1200x1500.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p8Ec!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!p8Ec!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!p8Ec!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!p8Ec!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p8Ec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp" width="1200" height="1500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1500,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_zero-trust-for-ai-ugcPost-7442915249172959233-zBV_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!p8Ec!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 424w, https://substackcdn.com/image/fetch/$s_!p8Ec!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 848w, https://substackcdn.com/image/fetch/$s_!p8Ec!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 1272w, https://substackcdn.com/image/fetch/$s_!p8Ec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccc66808-e211-4ff8-bf3c-2b2a82de0603_1200x1500.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[Finding Every MFA Gap: Testing 250 Million Conditional Access Combinations in Under 20 Minutes]]></title><description><![CDATA[The Offline CA Engine That Runs 24/7 on Autopilot. Offline. No Throttling. No Limits.]]></description><link>https://entra.news/p/finding-every-mfa-gap-testing-250</link><guid isPermaLink="false">https://entra.news/p/finding-every-mfa-gap-testing-250</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 28 Mar 2026 10:45:12 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/192389064/eaaa9a86ae99d9b58b87088e88404e1f.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Emilien Socchi, Cloud Security Research Engineer at Storebrand, joins us to discuss CA Insight and AZTier.</p><p>Two open-source tools Emilien built to find gaps in Conditional Access policies and categorize Azure/Entra roles based on attack paths. </p><p>Learn how <strong>CA Insight</strong> evaluates <strong>250 million sign-in combinations offline in minutes</strong> instead of days, why the What If API doesn't scale, and how AZTier helps defenders and pen testers understand privilege escalation risks across Entra ID, Azure, and Microsoft Graph.</p><p>Together, these projects help security teams move from reactive log monitoring to a proactive defense strategy.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S2e8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S2e8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 424w, https://substackcdn.com/image/fetch/$s_!S2e8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 848w, https://substackcdn.com/image/fetch/$s_!S2e8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 1272w, https://substackcdn.com/image/fetch/$s_!S2e8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S2e8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png" width="1456" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5592607,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/192389064?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S2e8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 424w, https://substackcdn.com/image/fetch/$s_!S2e8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 848w, https://substackcdn.com/image/fetch/$s_!S2e8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 1272w, https://substackcdn.com/image/fetch/$s_!S2e8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00e9add6-98d4-41ca-9be2-10dda78e0fb1_2804x1213.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AMSj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AMSj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!AMSj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!AMSj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!AMSj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AMSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df3e4844-7278-4350-a265-b36070cdb658_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:186930,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/192389064?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!AMSj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!AMSj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!AMSj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!AMSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3e4844-7278-4350-a265-b36070cdb658_1200x600.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>What&#8217;s Breaking and Slowing Your Entra ID Environment?</strong></p><p>In Microsoft Entra ID, the same visibility gaps cause two problems:</p><ul><li><p>Things break</p></li><li><p>Work slows down</p></li></ul><p>Expired client secrets disrupt integrations. Certificates lapse and authentication fails. New apps appear with excessive permissions and no clear ownership. At the same time, teams struggle to answer basic questions, which applications have access to Microsoft 365 data, whether that access is still required, and who is responsible for it.</p><p>When answers are not immediate, reviews stall and projects slow down.</p><p>ENow <a href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=podcast&amp;utm_content=3.29.26">App Governance Accelerator Credential Guard</a> helps identify expiring credentials and expose permission and ownership gaps.</p><p>For organizations under 10,000 users, pricing ranges from $3,500 to $9,500 annually through March 31, 2026.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=podcast&amp;utm_content=3.29.26&quot;,&quot;text&quot;:&quot;Find App Access Gaps&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=podcast&amp;utm_content=3.29.26"><span>Find App Access Gaps</span></a></p></blockquote><div><hr></div><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-SmLprBx81KI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;SmLprBx81KI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/SmLprBx81KI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h3>About Emilien Socchi</h3><p>Emilien Socchi is a Cloud Security Research Engineer at Storebrand (Oslo, Norway) focusing on the proactive discovery of security issues. With an extensive background in application and cloud penetration testing, Emilien has published practical research and tooling used by defenders. He also maintains several open&#8209;source projects, including Azure administrative tiering models and Entra ID role&#8209;monitoring utilities.</p><p>LinkedIn - <a href="https://www.linkedin.com/in/emilien-socchi">https://www.linkedin.com/in/emilien-socchi</a></p><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p>CA Insight- <a href="https://github.com/emiliensocchi/entra-ca-insight">https://github.com/emiliensocchi/entra-ca-insight</a></p></li><li><p>Azure Administrative Tiering (AzTier) - <a href="https://aztier.com">https://aztier.com</a></p></li><li><p>AzTier Source: <a href="https://github.com/emiliensocchi/azure-tiering">https://github.com/emiliensocchi/azure-tiering</a></p></li><li><p>AzTier Deployer - <a href="https://github.com/emiliensocchi/aztier-deployer">https://github.com/emiliensocchi/aztier-deployer</a></p></li></ul><div><hr></div><h2>&#128215; Chapters</h2><p>00:00 The Story Behind CA Insights</p><p>16:52 Why the &#8216;What If&#8217; API Doesn&#8217;t Scale </p><p>21:09 Building an Offline Evaluation Engine </p><p>45:22 Deep Dive into AZTier: A Red Team Perspective </p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #141 → This week in Microsoft Entra]]></title><description><![CDATA[Learn about new Microsoft Entra features including Backup and Recovery, Tenant Governance and cross tenant group sync.]]></description><link>https://entra.news/p/entra-news-141-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-141-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 22 Mar 2026 13:08:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yFpO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>With the RSA Conference around the corner, we&#8217;ve had some major Entra-related announcements this week.</p><p>The biggest new features just announced are the Microsoft Entra Backup and Recovery service and the Entra Tenant Governance feature.</p><p>Microsoft also introduced a new AI pillar in their Zero Trust Workshop, along two new (Data and Networking) pillar additions to the Zero Trust Assessment. This now includes a range of automated tests to verify your Entra Private Access and Internet Access configurations.</p><p>Don&#8217;t forget to add this week&#8217;s Entra Chat podcast to your queue. Darren has plenty of tricks up his sleeve when it comes to Entra Provisioning Services, making this a great opportunity to learn from a true expert.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;38cd56b3-1bb2-45a8-9606-a176bb1dc9cb&quot;,&quot;caption&quot;:&quot;Darren Robinson, Identity and Zero Trust Strategy and Architecture Capability Lead at Increment, shares his extensive experience in identity governance and administration.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;From FIM/MIM to Cloud Sync: Complete Identity Journey with Australia&#8217;s Top Identity MVP Darren &#8220;Doc&#8221; Robinson&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-03-21T11:14:31.145Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/191641823/5694bb92-f07e-4b1f-afb5-3ab16246f014/transcoded-1774088356.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/from-fimmim-to-cloud-sync-complete&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:191641823,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/19/new-tools-and-guidance-announcing-zero-trust-for-ai/">New tools and guidance: Announcing Zero Trust for AI</a> &#8226; <em>Mike Adams</em></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/backup/">Microsoft Entra Backup and Recovery</a> &#8226; <em>Microsoft Learn</em></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/">Microsoft Entra Tenant Governance</a> &#8226; <em>Microsoft Learn</em></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/identity/multi-tenant-organizations/cross-tenant-synchronization-configure?pivots=same-cloud-synchronization#step-2-enable-user-and-group-synchronization-in-the-target-tenant">Microsoft Entra cross-tenant group synchronization</a> &#8226; <em>Microsoft Learn</em></p></li></ul><h2>&#128214; Read</h2><ul><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/19/when-tax-season-becomes-cyberattack-season-phishing-and-malware-campaigns-using-tax-related-lures/">When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures</a> &#8226; <em>Microsoft Threat Intelligence, Microsoft Defender Security Research Team</em></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/secure-access-in-the-age-of-ai-key-findings-from-our-2026-report/4486060">Secure access in the age of AI: Key findings from our 2026 Report</a> &#8226; <em>Kaitlin Murphy</em></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/microsoft-entra-innovations-announced-at-rsac-2026/4502146">Microsoft Entra innovations announced at RSAC 2026</a> &#8226; <em>Irina Nechaeva</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1223829">MC1223829 - Upcoming Conditional Access change: Improved enforcement for policies with resource exclusions</a> (Updated 18 Mar)</p></li><li><p><a href="https://mc.merill.net/message/MC1247893">MC1247893 - Microsoft Entra passkeys on Windows now support phishing-resistant sign-in</a> (Updated 18 Mar)</p></li><li><p><a href="https://mc.merill.net/message/MC1255405">MC1255405 - Microsoft Edge for Business: Cross-tenant support using Intune Mobile Application Management (MAM)</a></p></li><li><p><a href="https://mc.merill.net/message/MC1253746">MC1253746 - Microsoft Entra: Passkeys in Microsoft registration campaigns</a> (Updated 18 Mar)</p></li><li><p><a href="https://mc.merill.net/message/MC1246002">MC1246002 - Prevent/Fix: Microsoft Baseline Security Mode has automatically trigger Entra Conditional Access policy creation</a> (Updated 18 Mar)</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/tarekdawoud_i-am-so-excited-to-share-the-next-step-in-activity-7440490815040311297-OpHW?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yFpO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 424w, https://substackcdn.com/image/fetch/$s_!yFpO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 848w, https://substackcdn.com/image/fetch/$s_!yFpO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 1272w, https://substackcdn.com/image/fetch/$s_!yFpO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yFpO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png" width="1456" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1181799,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/tarekdawoud_i-am-so-excited-to-share-the-next-step-in-activity-7440490815040311297-OpHW?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191727403?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yFpO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 424w, https://substackcdn.com/image/fetch/$s_!yFpO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 848w, https://substackcdn.com/image/fetch/$s_!yFpO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 1272w, https://substackcdn.com/image/fetch/$s_!yFpO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e583840-899e-4bad-a397-7f1b7ab9204f_2330x1460.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://medium.com/@jhope188/conditional-access-finding-the-gaps-in-your-entra-ca-before-attackers-do-c15dc7c5c34f">Conditional Access: Finding the Gaps in Your Entra CA Before Attackers Do!</a> &#8226; <em>Jon Hope</em></p></li><li><p>&#129352;<a href="https://lazyadmin.nl/office-365/entra-passkeys-on-windows-now-support-phishing-resistant-sign-in/">Microsoft Entra Passkeys on Windows now Support Phishing-Resistant Sign-In</a> &#8226; <em>Rudy Mens</em></p></li><li><p>&#129353;<a href="https://ourcloudnetwork.com/new-microsoft-entra-passkeys-for-windows-hello-enter-public-preview/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=new-microsoft-entra-passkeys-for-windows-hello-enter-public-preview">New Microsoft Entra Passkeys for Windows Hello Enter Public Preview</a> &#8226; <em>Daniel Bradley</em></p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=newsletter&amp;utm_content=3.22.26" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qEuA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!qEuA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!qEuA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!qEuA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qEuA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:188974,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=newsletter&amp;utm_content=3.22.26&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191727403?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!qEuA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!qEuA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!qEuA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!qEuA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b64430-b9f2-457f-a2ce-a10ff775827d_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>What&#8217;s Slowing Decisions in Your Entra ID Tenant?</strong></p><p>In Microsoft Entra ID environments, application sprawl and uncertainty slow decisions, not just visibility. Hundreds of enterprise applications and service principals with persistent OAuth permissions and unclear ownership make it difficult to answer basic questions. Which apps have access to Microsoft 365 data? Is that access still justified? Who owns it?</p><p>When those answers are not immediate, reviews take longer, approvals stall, projects slow down, and your team is seen as a blocker rather than a technology enabler.</p><p>ENow&#8217;s <strong><a href="https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=newsletter&amp;utm_content=3.22.26">AppGov Score</a></strong> provides a clear view of permission risk, consent practices, and ownership gaps across your tenant. With that visibility, teams can make faster decisions, reduce unnecessary access, and keep work moving without added risk.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=newsletter&amp;utm_content=3.22.26&quot;,&quot;text&quot;:&quot;Find App Access Blockers&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=newsletter&amp;utm_content=3.22.26"><span>Find App Access Blockers</span></a></p></blockquote><div><hr></div><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/jan-bakker_important-update-for-tenants-with-system-preferred-activity-7439209088787374080-qoRw?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RGZ2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 424w, https://substackcdn.com/image/fetch/$s_!RGZ2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 848w, https://substackcdn.com/image/fetch/$s_!RGZ2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 1272w, https://substackcdn.com/image/fetch/$s_!RGZ2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RGZ2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png" width="1106" height="1314" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1314,&quot;width&quot;:1106,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:626074,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/jan-bakker_important-update-for-tenants-with-system-preferred-activity-7439209088787374080-qoRw?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191727403?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RGZ2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 424w, https://substackcdn.com/image/fetch/$s_!RGZ2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 848w, https://substackcdn.com/image/fetch/$s_!RGZ2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 1272w, https://substackcdn.com/image/fetch/$s_!RGZ2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34eeccbe-139d-45bc-9831-80dcf32b1a82_1106x1314.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/alitajran_entraid-microsoft365-microsoft-activity-7440389148173160450-hZOS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-S0o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 424w, https://substackcdn.com/image/fetch/$s_!-S0o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 848w, https://substackcdn.com/image/fetch/$s_!-S0o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 1272w, https://substackcdn.com/image/fetch/$s_!-S0o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-S0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png" width="1124" height="1106" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1106,&quot;width&quot;:1124,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:453004,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/alitajran_entraid-microsoft365-microsoft-activity-7440389148173160450-hZOS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191727403?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-S0o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 424w, https://substackcdn.com/image/fetch/$s_!-S0o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 848w, https://substackcdn.com/image/fetch/$s_!-S0o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 1272w, https://substackcdn.com/image/fetch/$s_!-S0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F881a70bf-03d4-4343-a331-0c9a7a06317c_1124x1106.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://office365itpros.com/2026/03/17/is-the-new-agent-365-worth-99/">Is the New Agent 365 Worth $99?</a> &#8226; <em>Paul Robichaux</em></p></li><li><p><a href="https://thalpius.com/2026/03/17/microsoft-orphaned-agents-identities-the-hidden-identity-debt-in-your-entra-tenant/">Microsoft Orphaned Agents Identities: The hidden identity debt in your Entra tenant</a> &#8226; <em>Raymond Roethof</em></p></li><li><p><a href="https://www.youtube.com/watch?v=9-nLpD0EMBI">Secure access for AI agents, the new frontier of identity</a> (25 min) &#8226; <em>Leandro Iwase, Nick Wryter</em></p></li></ul><h2>&#129520; Workload ID</h2><ul><li><p><a href="https://www.linkedin.com/pulse/securing-unseen-why-non-human-identities-deserve-ciso-david-ssqfe?utm_source=share&amp;utm_medium=member_android&amp;utm_campaign=share_via">Securing the Unseen: Why Non-Human Identities Deserve CISO Attention</a> &#8226; <em>David Alonso Dominguez</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=C_sfyrK-1_I&amp;si=5uwqkhjRKIUiGBqv">Overview of Entra Workload Identities</a> (3 min) &#8226; <em>Orin</em></p></li></ul><h2>&#128110;&#8205;&#9794;&#65039; ID Governance</h2><ul><li><p><a href="https://www.thetechtrails.com/2026/03/multi-stage-approval-entra-roles.html">How to Implement Multi-Stage Approval for High-Privileged Entra Roles Using Entitlement Management and PIM</a> &#8226; <em>Sreejith Reghunathan Pillai</em></p></li><li><p><a href="https://mobile-jon.com/2026/03/16/how-to-secure-access-to-entra-roles-with-conditional-access-and-privileged-identity-management/">How to Secure Access to Entra Roles with Conditional Access and Privileged Identity Management</a> &#8226; <em>Jon Towles</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=KLIJZhuiv9A">Sign-In Risk vs User Risk - Most Admins Don&#8217;t Know the Difference</a> (14 min) &#8226; <em>Jonathan Edwards</em></p></li><li><p>&#128736;&#65039; <a href="https://www.christianfrohn.dk/2026/03/16/access-package-documentor-a-reporting-tool-for-entra-id-governance/">Access Package Documentor &#8211; A Reporting Tool for Entra ID Governance</a> &#8226; <em>Christian Frohn</em></p></li><li><p>&#128736;&#65039; <a href="https://blog.darrenjrobinson.com/entra-provision-on-demand-powershell-module/">Entra Provision On Demand PowerShell Module</a> &#8226; <em>Darren Robinson</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p><a href="https://directaccess.richardhicks.com/2026/03/17/entra-private-access-and-vpn-migration-strategies-on-entra-news/">Entra Private Access and VPN Migration Strategies on Entra.News</a> &#8226; <em>Richard M. Hicks</em></p></li><li><p><a href="https://zerototrust.tech/your-data-has-a-back-door-gsa-and-purview-are-the-deadbolt/">Your Data Has a Back Door. GSA and Purview Are the Deadbolt</a> &#8226; <em>Dustin Gullett</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p>&#128736;&#65039; <a href="https://github.com/nicolasblank/privileged-app-path-auditor">Privileged App Path Auditor</a> - Audit Entra ID for privilege escalation paths through application permissions, role assignments, and app ownership &#8226; <em>Nicolas Blank</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://emsroute.com/2026/03/19/passkeys-beginners-101/">A Beginner&#8217;s Deep Dive Guide to Entra Passkeys</a> &#8226; <em>Shehan Perera</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=TO1x3U-1WNo&amp;si=eGxKs8CbinufkPnY">Adding Allowed FIDO Keys and Registering in Microsoft Entra</a> (4 min) &#8226; <em>Mobile Jon</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=Z9BQY-PeoVc">From Lockouts to Logins: Modern Account Recovery and Passkeys</a> (59 min) &#8226; <em>Hana Kim, Jai Maharaj</em></p></li></ul><h2>&#129302; DevOps &amp; PowerShell</h2><ul><li><p><a href="https://office365itpros.com/2026/03/18/microsoft-graph-issues/">The Sad State of Microsoft Graph and Other APIs</a> &#8226; <em>Tony Redmond</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/">Conditional Access Optimization Agent knowledge base</a> &#8226; <em>Jan Bakker</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p>&#128250; <a href="https://www.youtube.com/shorts/A6IhBYNPlVY">Azure Bastion Enter ID Authentication: Full Requirements Guide #shorts</a> &#8226; <em>Travis Roberts</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=DA_M3X1KQbM&amp;si=MywUNKUs-nPaq_0v">Samba 4.24 Brings Entra ID Password Reset Support and Kerberos Hardening</a> (2 min) &#8226; <em>DistroTester</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=DxEHyDqiwEQ&amp;si=whvkELHJ0WNDDGNw">Setting up Conditional Access for Entra Privileged Identity Management</a> (4 min) &#8226; <em>Mobile Jon</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p><a href="https://idefixwiki.no/post/entra-id-guest-governance/">Guest Identity Governance in Microsoft Entra ID - IdefixWiki</a> &#8226; <em>Julian Rasmussen</em></p></li></ul><h2>&#128200; Reporting and Insights</h2><ul><li><p><a href="https://www.chanceofsecurity.com/post/introducing-m365identityposture-community-driven-identity-reporting-for-microsoft-365">Introducing M365IdentityPosture: Community-Driven Identity Reporting for Microsoft 365</a> &#8226; <em>Sebastian Fl&#230;ng Markdanner</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://trustedsec.com/blog/full-disclosure-a-third-and-fourth-azure-sign-in-log-bypass-found">Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found</a> &#8226; <em>Nyxgeek</em></p></li><li><p>&#127897;&#65039; <a href="https://rss.com/podcasts/azsecpodcast/2646282/">Episode 126: Microsoft Baseline Security Mode</a> &#8226; <em>Michael Howard, Sarah Young</em></p></li><li><p><a href="https://ourcloudnetwork.com/microsoft-quietly-closes-another-loophole-for-tenant-domain-enumeration/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-quietly-closes-another-loophole-for-tenant-domain-enumeration">Microsoft Quietly Closes Another Loophole for Tenant Domain Enumeration</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://www.matej.guru/p/when-oauth-redirects-become-a-phishing">When OAuth Redirects Become a Phishing Tool</a> &#8226; <em>Matej Klemen&#269;i&#269;</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/playlist?list=PLahhVEj9XNTc3cKjd28NUDFPrV4QcfxH5">SC-900: Microsoft Security, Compliance, and Identity Fundamentals</a> &#8226; <em>Microsoft Learn Course Video Series</em></p></li><li><p>&#128736;&#65039; <a href="https://www.linkedin.com/redir/redirect/?url=https%3A%2F%2Fgithub%2Ecom%2Ftemp43487580%2FBAADTokenBroker&amp;urlhash=rRdi&amp;mt=64SPrB1QAXy9s8wUI91kKNqbaPmYUXlNStMXTjOSfMfA-sbPi-U2i4vQU4L4Qr1zMPcmL-B12aWKrTttab_NlETNMdC1pXHtqD_fP9FJvEFOFWvuBzMrfcT5&amp;isSdui=true">BAADTokenBroker: BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.</a></p></li><li><p>&#128736;&#65039; <a href="https://blog.compass-security.com/2026/03/from-enumeration-to-findings-the-security-findings-report-in-entrafalcon/">From Enumeration to Findings: The Security Findings Report in EntraFalcon &#8211; Compass Security Blog</a> &#8226; <em>Christian Feuchter</em></p></li></ul><h2>&#9851;&#65039; Sync</h2><ul><li><p>&#128250; <a href="https://youtube.com/watch?v=kojBFJf6AM8&amp;si=1GTJVRPFORH0w6rT">Architecture Explained: Integrating On Prem AD with Microsoft Entra ID</a> (9 min) &#8226; <em>Thomas Mitchell</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://medium.com/@brianveldman/backup-and-recovery-for-microsoft-entra-d4035d812a4c?source=rss-4a3a93df846e------2">Backup and Recovery for Microsoft Entra</a> &#8226; <em>Brian Veldman</em></p></li><li><p><a href="https://www.modern42.com/post/native-microsoft-entra-id-backup-and-recovery-overview">Microsoft Entra ID Backup and Recovery: Native Tenant Backup Is Finally Here</a> &#8226; <em>Rawson Wade</em></p></li><li><p><a href="https://medium.com/@jhope188/microsoft-licensing-the-bs-in-business-standard-e8d457e24d20">Microsoft Licensing: The BS in Business Standard</a> &#8226; <em>Jon Hope</em> </p></li><li><p><a href="https://ourcloudnetwork.com/microsoft-updates-the-entra-license-usage-insights-blade/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-updates-the-entra-license-usage-insights-blade">Microsoft updates the Entra license usage insights blade</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://ourcloudnetwork.com/use-entra-tenant-governance-for-native-multi-tenant-drift-detection/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=use-entra-tenant-governance-for-native-multi-tenant-drift-detection">Use Entra Tenant Governance for Native Multi-Tenant Drift Detection</a> &#8226; <em>Daniel Bradley</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=ehKz2waXwDM">Entra Backup &amp; Recovery (Public Preview)</a> (9 min) &#8226; <em>RioCloudSync</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=MwgS_ZBFF0Y">Tenant Configuration Management Creating a Snapshot</a> (7 min) &#8226; <em>TechNik</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=o03NJtuXe8k">What&#8217;s NEW in Microsoft 365 &amp; Entra ID March 2026</a> (16 min) &#8226; <em>Andy Malone</em></p></li></ul><h2>&#128717;&#65039; External ID - Customers</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/creating-a-feature-flag-in-azure-ad-b2c-6ba01cb57ac8?source=rss-6601e21c1210------2">Creating a feature flag in Azure AD B2C</a> &#8226; <em>Rory Braybrook</em></p></li><li><p><a href="https://medium.com/the-new-control-plane/entra-external-id-eeid-aadsts1100001-error-with-token-issuance-custom-authentication-extensions-faf55d97cea5?source=rss-6601e21c1210------2">Entra External ID (EEID) AADSTS1100001 error with token issuance custom authentication extensions</a> &#8226; <em>Rory Braybrook</em></p></li></ul><div><hr></div><h2>&#9874;&#65039; Toolkit</h2><ul><li><p><a href="https://github.com/Noble-Effeciency13/M365IdentityPosture">M365IdentityPosture: PowerShell security reporting framework for Microsoft 365 identity posture assessment. Analyzes Authentication Context, PIM, Conditional Access &amp; more.</a> &#8226; <em>Sebastian F. Markdanner</em></p></li></ul><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_microsoftentra-ai-identity-activity-7439824525212512256--joi?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TKJu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 424w, https://substackcdn.com/image/fetch/$s_!TKJu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 848w, https://substackcdn.com/image/fetch/$s_!TKJu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 1272w, https://substackcdn.com/image/fetch/$s_!TKJu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TKJu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png" width="1110" height="976" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:976,&quot;width&quot;:1110,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:722255,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_microsoftentra-ai-identity-activity-7439824525212512256--joi?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191727403?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TKJu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 424w, https://substackcdn.com/image/fetch/$s_!TKJu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 848w, https://substackcdn.com/image/fetch/$s_!TKJu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 1272w, https://substackcdn.com/image/fetch/$s_!TKJu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32129574-7efa-4e22-b5fa-6fadf333b487_1110x976.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_richard-m-hicks-shared-some-awesome-tips-ugcPost-7440338118110580739-qe2r?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FNij!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 424w, https://substackcdn.com/image/fetch/$s_!FNij!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 848w, https://substackcdn.com/image/fetch/$s_!FNij!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 1272w, https://substackcdn.com/image/fetch/$s_!FNij!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FNij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png" width="1456" height="1169" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1169,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1484840,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_richard-m-hicks-shared-some-awesome-tips-ugcPost-7440338118110580739-qe2r?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191727403?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FNij!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 424w, https://substackcdn.com/image/fetch/$s_!FNij!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 848w, https://substackcdn.com/image/fetch/$s_!FNij!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 1272w, https://substackcdn.com/image/fetch/$s_!FNij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f912aa2-8555-4f98-90af-552519470fa2_1622x1302.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://entra.news/p/entra-news-141-this-week-in-microsoft?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Entra.News - Your weekly dose of Microsoft Entra! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://entra.news/p/entra-news-141-this-week-in-microsoft?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://entra.news/p/entra-news-141-this-week-in-microsoft?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[From FIM/MIM to Cloud Sync: Complete Identity Journey with Australia’s Top Identity MVP Darren “Doc” Robinson]]></title><description><![CDATA[Legacy Identity to Cloud with Entra ID]]></description><link>https://entra.news/p/from-fimmim-to-cloud-sync-complete</link><guid isPermaLink="false">https://entra.news/p/from-fimmim-to-cloud-sync-complete</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 21 Mar 2026 11:14:31 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/191641823/eb878c75bb3c1f015bbca7cb054369ef.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Darren Robinson, Identity and Zero Trust Strategy and Architecture Capability Lead at Increment, shares his extensive experience in identity governance and administration.</p><p>In this episode Merill sits down with Darren &#8220;Doc&#8221; Robinson &#8211; Microsoft MVP since 2017, former SailPoint Ambassador and one of Australia&#8217;s most experienced identity architects.</p><p>Darren takes us on a 25+ year journey from Novell networks to modern Microsoft Entra ID, reveals why he&#8217;s building custom ECMA2 connectors, and shares the exact PowerShell tools he just open-sourced (Granfeldt uplift, ECMA2 Host Tools, Provision On-Demand module).</p><p>We also compare Entra ID Governance vs SailPoint and dive into his latest obsession: MCPs for Entra News and personal AI agents.</p><p>Whether you&#8217;re migrating legacy apps or levelling up your IGA strategy, this episode is pure gold.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jzGq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jzGq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 424w, https://substackcdn.com/image/fetch/$s_!jzGq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 848w, https://substackcdn.com/image/fetch/$s_!jzGq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 1272w, https://substackcdn.com/image/fetch/$s_!jzGq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jzGq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png" width="1456" height="825" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:825,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6955850,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191641823?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jzGq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 424w, https://substackcdn.com/image/fetch/$s_!jzGq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 848w, https://substackcdn.com/image/fetch/$s_!jzGq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 1272w, https://substackcdn.com/image/fetch/$s_!jzGq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11eb24a4-2949-44a0-9891-f33544d174bf_2804x1588.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong>Sponsored by <a href="https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=21.3.26">CoreView</a>:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=21.3.26" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JFiV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 424w, https://substackcdn.com/image/fetch/$s_!JFiV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 848w, https://substackcdn.com/image/fetch/$s_!JFiV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 1272w, https://substackcdn.com/image/fetch/$s_!JFiV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JFiV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png" width="298" height="262" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:262,&quot;width&quot;:298,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70922,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=21.3.26&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/191641823?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JFiV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 424w, https://substackcdn.com/image/fetch/$s_!JFiV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 848w, https://substackcdn.com/image/fetch/$s_!JFiV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 1272w, https://substackcdn.com/image/fetch/$s_!JFiV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc73f7669-803b-4519-b478-e9d141d9bf2d_298x262.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong><br>Would you bet your reputation on your current Microsoft 365 security posture?</strong></p><p>Sure, you&#8217;ve checked Purview. Maybe tightened Conditional Access. We all do that.</p><p>But it&#8217;s usually the quiet stuff that bites... permissions that expanded, policies that drifted, exceptions nobody revisited.</p><p>You could assume it&#8217;s fine.</p><p>Or you could run the Microsoft 365 Security Posture Check.</p><p>It&#8217;s free.</p><p>It runs locally.</p><p>And no, it doesn&#8217;t send your tenant data back to us.</p><p>We&#8217;ll even help you set it up.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=21.3.26&quot;,&quot;text&quot;:&quot;Get yours here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.coreview.com/free-tool/tenant-security-scanner?&amp;utm_medium=entra.chat&amp;utm_source=MVP&amp;utm_content=21.3.26"><span>Get yours here</span></a></p></blockquote><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-i7YBPBFy2E4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;i7YBPBFy2E4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/i7YBPBFy2E4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About Darren Robinson</h3><p>Darren is highly accomplished in digital identity and cybersecurity specialising in Identity &amp; Access Management for over three decades. Darren is renowned for driving Digital Identity innovation, building global offerings, and leading high-impact teams to deliver cutting-edge solutions that enhance security posture, operational efficiency, and business value.</p><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p>Blog: <a href="https://blog.darrenjrobinson.com">https://blog.darrenjrobinson.com</a></p></li><li><p>GitHub: <a href="https://github.com/darrenjrobinson">https://github.com/darrenjrobinson</a></p></li><li><p>LinkedIn: <a href="https://www.linkedin.com/in/darrenjrobinson/">https://www.linkedin.com/in/darrenjrobinson/</a></p></li></ul><div><hr></div><h2>In this episode&#8230;</h2><h4>1. Understanding the &#8220;Metaverse&#8221;</h4><p>The foundation of Microsoft&#8217;s identity strategy dates back to the acquisition of Zoomit in 2000. This introduced the <strong>Metaverse</strong>&#8212;not a VR world, but a &#8220;hologram&#8221; or central representation of a user that exists across multiple systems like SQL databases and LDAP directories. By correlating these identities into one object, organizations can maintain consistency across a fragmented environment.</p><h4>2. The Modern Bridge: ECMA and SCIM</h4><p>As organizations move to the cloud, the &#8220;heavy&#8221; sync engines like MIM (Microsoft Identity Manager) are being replaced by <strong>Entra Cloud Sync</strong>. The modern approach uses:</p><ul><li><p><strong>A Light Shim:</strong> A small on-premises component that acts as a member of the domain.</p></li><li><p><strong>SCIM Instructions:</strong> The Entra provisioning service sends instructions via the SCIM protocol to this shim.</p></li><li><p><strong>ECMA Connectors:</strong> The <strong>Extensible Connector Management Agent (ECMA)</strong> translates these cloud instructions into a language legacy on-prem apps can understand, such as SQL or Oracle updates.</p></li></ul><h4>3. Scaling with PowerShell 7</h4><p>One of the biggest hurdles in legacy identity management was performance. Darren Robinson recently uplifted the popular <strong>Granfeldt PowerShell Management Agent</strong> to support <strong>PowerShell 7</strong>. This update allows for:</p><ul><li><p><strong>64-bit Processing:</strong> Handling larger datasets with ease.</p></li><li><p><strong>Parallelism:</strong> Sending multiple identity updates in parallel rather than waiting for individual &#8220;gets,&#8221; significantly speeding up sync times.</p></li></ul><h4>4. Managing the &#8220;Cache&#8221;</h4><p>A common pain point for administrators is the lack of visibility into the <strong>ECMA host cache</strong>. To solve this, Darren developed a new module that allows practitioners to programmatically query the cache, back up configurations, and document every connector and parameter in the system.</p><p><strong>Key Takeaway:</strong> Whether you are migrating from legacy solutions like Novell or managing a complex hybrid Entra environment, the goal remains the same: automated, secure, and visible identity lifecycles.</p><div><hr></div><h3>&#128215; Chapters</h3><p>00:00 Intro</p><p>02:22 The Evolution of Directory Services and Synchronization</p><p>08:05 Understanding Sync Engines and the Metaverse</p><p>14:45 Modern Identity Provisioning with Entra</p><p>17:39 Developing Custom PowerShell ECMA Connectors</p><p>20:53 Automating Provisioning with New PowerShell Modules</p><p>28:53 The Current Landscape of Identity Governance</p><p>31:37 Solving the Disconnected Apps Challenge</p><p>35:46 Exploring Model Context Protocol (MCP)</p><p>45:34 Leveraging Local AI and LLMs for Identity Tasks</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #140 → This week in Microsoft Entra]]></title><description><![CDATA[&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.]]></description><link>https://entra.news/p/entra-news-140-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-140-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 15 Mar 2026 10:26:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lJ66!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>This week brings another step forward in the journey toward phishing-resistant identity. Make sure to check the latest Message Center update on passkey profiles and registration, which includes new details about upcoming changes to passkey registration. There&#8217;s also big news around the new Microsoft 365 E7 license, which now includes the Entra Suite.</p><p>There&#8217;s plenty from the community as well. One highlight is the <a href="https://blog.darrenjrobinson.com/entra-news-mcp-server/">Entra News MCP Server</a> created by fellow Aussie Darren &#8216;Doc&#8217; Robinson, an incredibly useful way to tap into the collective knowledge of the Microsoft Entra community.</p><p>Finally, I caught up with Richard Hicks for the Entra Chat podcast. Having worked through every major era of remote access, from DirectAccess and Always On VPN to Microsoft Entra Private Access, Richard shares the hard-earned lessons he&#8217;s learned helping enterprises modernize their VPN strategy. Definitely one to add to your podcast listening queue! &#127911;</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;cf83ea9d-5a02-46b2-a724-592224d58247&quot;,&quot;caption&quot;:&quot;Richard Hicks wrote the book on DirectAccess. Then he wrote the one on Always On VPN. Now he&#8217;s here to tell you it&#8217;s time to move on from both (and other legacy VPNs). Over the last two years, Richard has helped numerous enterprise customers navigate the shift from legacy VPN to Microsoft Entra Private Access, and he&#8217;s collected some hard-learnt lessons&#8230;&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;How to Migrate from Legacy VPNs to Entra Private Access (Real Strategies from a Veteran)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-03-14T07:45:29.713Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/190904045/907cd676-2543-4113-9851-f2ba36fd8577/transcoded-1773473316.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/how-to-migrate-from-legacy-vpns-to&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190904045,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190987530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!Y4Jg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9978534d-3224-4fec-82de-2a6f73896d09_1200x600.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>User Lifecycle: Onboard and Offboard With a Single CmdLet</strong></p><p>Fact: Managing hybrid users across AD, Entra ID, and Exchange Online is a breeding ground for missed steps and security gaps - from day one to last day.</p><p>EasyEntra&#8217;s PowerShell-enabled workflows handle the entire lifecycle:</p><p>&#128640; Onboard a fully provisioned user in 30 seconds - UI or two-parameter CmdLet.<br>&#128640; Templates defined from existing users in seconds.<br>&#128640; Offboard completely in 10 seconds - UI or single CmdLet.<br>&#128640; Offboarding settings configured once, applied consistently every time.<br>&#128640; Delegate life-cycle management to first-line support - no senior PowerShell skills or tribal knowledge required.</p><p>Start your 30-day trial or book a demo - setup takes under a minute - free for tenants with fewer than 25 licensed users.</p><p><em><strong>&#8220;It feels almost like a revolution.&#8221;</strong></em><br>Head of IT, Arjeplog Municipality, Sweden</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle&quot;,&quot;text&quot;:&quot;Wait&#8230; One CmdLet?&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=userlifecycle"><span>Wait&#8230; One CmdLet?</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#127942; General Availability</h2><ul><li><p><a href="https://devblogs.microsoft.com/identity/native-auth-mfa-ga/">Email and SMS OTP as Second&#8209;Factor MFA for Native Authentication in Entra External ID</a> &#8226; <em>Sasha Mars</em></p></li></ul><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://www.linkedin.com/posts/merill_microsoft-just-made-a-big-improvement-to-activity-7437742266338885634-cmjS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0">New </a><strong><a href="https://www.linkedin.com/posts/merill_microsoft-just-made-a-big-improvement-to-activity-7437742266338885634-cmjS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0">myacount.microsoft.com</a></strong><a href="https://www.linkedin.com/posts/merill_microsoft-just-made-a-big-improvement-to-activity-7437742266338885634-cmjS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0"> home page</a></p></li></ul><h2>&#128214; Read</h2><ul><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/">Secure agentic AI for your Frontier Transformation</a> &#8226; <em>Vasu Jakkal</em></p></li></ul><h2>&#128250; Watch</h2><ul><li><p><a href="https://www.youtube.com/watch?v=ElzHUfNkFjQ">QR code authentication: Fast, simple sign&#8209;in designed for Frontline Workers</a> (46 min) &#8226; <em>Akshat Goel</em></p></li><li><p><a href="https://www.youtube.com/watch?v=ZDlP1sFKMJo">Building MCP on Entra: Design Choices for Enterprise Agents</a> (61 min) &#8226; <em>Merill Fernando</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1221452">MC1221452 - (Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants</a></p></li><li><p><a href="https://mc.merill.net/message/MC1247893">MC1247893 - Microsoft Entra passkeys on Windows now support phishing-resistant sign-in</a></p></li></ul><h2>&#128198; Upcoming Events</h2><p><strong>Microsoft Security Webinars</strong></p><ul><li><p><a href="https://forms.office.com/pages/responsepage.aspx?id=v4j5cvGGr0GRqy180BHbR9d1XvZDzJ1FhndX_eCRr0xUMlpIQTFOVTk5QkpDQ0VPTk1CRlJQVlNNNy4u&amp;route=shorturl">18 March - Microsoft Entra | From Lockouts to Logins: Modern Account Recovery and Passkeys</a></p></li><li><p><a href="https://forms.office.com/pages/responsepage.aspx?id=v4j5cvGGr0GRqy180BHbR9d1XvZDzJ1FhndX_eCRr0xUMlpIQTFOVTk5QkpDQ0VPTk1CRlJQVlNNNy4u&amp;route=shorturl">31 March - Microsoft Entra | Developer Tools for Agent ID: SDKs, CLIs &amp; Samples</a></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://www.cloudidentity.se/blog/making-global-administrators-safer/">Making Global Administrators Safer</a> &#8226; <em>Dennis J.</em></p></li><li><p>&#129352;<a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/rethinking-%E2%80%9Callow-my-organization-to-manage-my-device%E2%80%9D-why-opt%E2%80%91in-enrollment-wor/4499766">Rethinking &#8220;Allow my organization to manage my device&#8221; Why opt&#8209;in enrollment works better for Intune</a> &#8226; <em>Ramya Sharma</em></p></li><li><p>&#129353;<a href="https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/">Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale</a> &#8226; <em>Microsoft Threat Intelligence, Microsoft Defender Security Research Team</em></p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.15.26" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6SQd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!6SQd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!6SQd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!6SQd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6SQd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8792776-4a5e-4810-896d-af8551487a22_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:767607,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.15.26&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190987530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6SQd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!6SQd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!6SQd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!6SQd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8792776-4a5e-4810-896d-af8551487a22_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Benchmark Your Entra App Governance</strong></p><p>Enterprise applications and service principals accumulate rapidly in Microsoft Entra ID. Over time, many retain OAuth permissions and access to corporate data without clear ownership or regular review.</p><p>This creates a growing governance gap. Administrators often lack visibility into which applications hold high-risk permissions and whether those permissions are still justified.</p><p>ENow <a href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=Entra.news&amp;utm_medium=email&amp;utm_content=3.15.26">AppGov Score</a> evaluates your Entra ID application environment against 24 governance checks and benchmarks your governance posture. Identify risky permissions, orphaned apps, role assignments, and credential risks that require review. Get your AppGov Score to see where your environment stands and access free community resources for practical guidance. &#128737;&#65039;&#128269;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.15.26&quot;,&quot;text&quot;:&quot;Access Your Score&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.15.26"><span>Access Your Score</span></a></p></blockquote><div><hr></div><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/darrenjrobinson_entra-news-mcp-server-darrenjrobinson-activity-7436924281848201216-4E-D?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XMhH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 424w, https://substackcdn.com/image/fetch/$s_!XMhH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 848w, https://substackcdn.com/image/fetch/$s_!XMhH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 1272w, https://substackcdn.com/image/fetch/$s_!XMhH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XMhH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png" width="618" height="605.6847826086956" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1082,&quot;width&quot;:1104,&quot;resizeWidth&quot;:618,&quot;bytes&quot;:209808,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/darrenjrobinson_entra-news-mcp-server-darrenjrobinson-activity-7436924281848201216-4E-D?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190987530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XMhH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 424w, https://substackcdn.com/image/fetch/$s_!XMhH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 848w, https://substackcdn.com/image/fetch/$s_!XMhH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 1272w, https://substackcdn.com/image/fetch/$s_!XMhH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b73362b-32da-438c-ae26-1662b3ccbd47_1104x1082.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://thalpius.com/2026/03/14/microsoft-ownerless-agents-the-silent-risk-in-your-entra-tenant/">Microsoft Ownerless Agents: The silent risk in your Entra tenant</a> &#8226; <em>Raymond Roethof</em></p></li><li><p><a href="https://ourcloudnetwork.com/microsoft-releases-new-ai-self-service-support-experience-in-entra/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-releases-new-ai-self-service-support-experience-in-entra">Microsoft releases new AI self service support experience in Entra</a> &#8226; <em>Daniel Bradley</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=GEWNLjreG2Q&amp;si=rZ3i6R5eHt7Nqf4_">How to Enable Entra ID Agent Identity for Copilot Studio Agents</a> (4 min) &#8226; <em>Wario W. Wario</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p><a href="https://petervanderwoude.nl/post/blocking-the-microsoft-store-web-installer-using-entra-internet-access/">Blocking the Microsoft Store Web Installer using Entra Internet Access</a> &#8226; <em>Peter van der Woude</em></p></li><li><p><a href="https://www.julianjakob.com/windows-cloud-pushing-private-access-to-the-limit/">Windows Cloud &#8211; Pushing Private Access to the Limit</a> &#8226; <em>Julian Jakob</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/tutorial-manage-certificates-for-federated-single-sign-on#guidance-and-best-practices-for-isvs-on-rotating-certificates">Guidance and best practices for ISVs on rotating certificates</a> &#8226; <em>Microsoft Learn</em></p></li><li><p><a href="https://o365reports.com/limit-multi-tenant-app-access-to-specific-tenants-in-entra-id/">How to Limit Multi-Tenant Applications to Specific Tenants in Entra ID</a> &#8226; <em>Thiraviam</em></p></li><li><p><a href="https://ourcloudnetwork.com/how-to-restrict-multi-tenant-entra-apps-to-specific-tenants/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=how-to-restrict-multi-tenant-entra-apps-to-specific-tenants">How to Restrict Multi-Tenant Entra Apps to Specific Tenants</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://agderinthe.cloud/2026/03/12/rethinking-application-access-entra-id/">Rethinking application access in Microsoft Entra ID</a> &#8226; <em>Sandra Saluti</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://lazyadmin.nl/office-365/entra-passkeys-on-windows-now-support-phishing-resistant-sign-in/">Microsoft Entra Passkeys on Windows now Support Phishing-Resistant Sign-In</a> &#8226; <em>Rudy Mens</em></p></li><li><p><a href="https://ourcloudnetwork.com/new-microsoft-entra-passkeys-for-windows-hello-enter-public-preview/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=new-microsoft-entra-passkeys-for-windows-hello-enter-public-preview">New Microsoft Entra Passkeys for Windows Hello Enter Public Preview</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://www.michaelvink.com/l/passkeysandwindowshellosign-ins/">Passkeys, Windows Hello And Phishing-Resistant Sign-Ins</a> &#8226; <em>Michael Vink</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=DQ4dnXibaoM&amp;si=E-vXyhF12wrLorvm">[D26] Are passkeys as secure as you think?</a> (43 min) &#8226; <em>Fabian Bader</em></p></li></ul><h2>&#128101; User &amp; Group Management</h2><ul><li><p><a href="https://mattchatt.co.za/new-switching-user-source-of-authority-soa-in-entra-id/">New! Switching User Source of Authority (SOA) in Entra ID</a> &#8226; <em>Matthew Levy</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=HmaOrLcCdqg&amp;si=wUVV3q4MHgEvB8j8">Break the Chain: Convert Synced Distribution Lists to Cloud-Only!</a> (7 min) &#8226; <em>Azure Brother</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://www.modern42.com/post/microsoft-entra-id-conditional-access-resource-exclusions">Conditional Access Exclusion: What&#8217;s Actually Changing on March 27th and Should You Care?</a> &#8226; <em>Rory Wade</em></p></li><li><p><a href="https://medium.com/@jhope188/conditional-access-finding-the-gaps-in-your-entra-ca-before-attackers-do-c15dc7c5c34f">Conditional Access: Finding the Gaps in Your Entra CA Before Attackers Do!</a> &#8226; <em>Jon Hope</em></p></li><li><p><a href="https://c7solutions.com/2026/03/device-code-flow-and-authentication-transfer-in-conditional-access-rules-one-or-two-rules-required">Device Code Flow and Authentication Transfer in Conditional Access Rules &#8211; One or two rules required?</a> &#8226; <em>Brian Reid</em></p></li><li><p><a href="https://martin.rublik.eu/2026/03/12/overview-of-oatuh-scopes-in-signin-logs.html">Tracking OAuth scopes in sign&#8209;in logs and upcoming change in conditional access</a> &#8226; <em>Martin Rublik</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p><a href="https://joostgelijsteen.com/why-edge-mam-ios-keeps-removing-work-account/">Edge (MAM) on iOS Keeps removing the Work Account after Sign-in!: Why one Broken identity breaks it All - Just about the Modern Workplace</a> &#8226; <em>Joost Gelijsteen</em></p></li><li><p><a href="https://zerototrust.tech/happy-little-edge-securing-windows-byod-with-edge-for-business/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=happy-little-edge-securing-windows-byod-with-edge-for-business">Happy Little Edge. Securing Windows BYOD with Edge for Business</a> &#8226; <em>Dustin Gullett</em></p></li><li><p><a href="https://blog.hametbenoit.info/2026/03/09/intune-block-automatic-mobile-device-management-enrollment-preview/">Intune &#8211; Block automatic mobile device management enrollment (preview)</a> &#8226; <em>Benoit Hamet</em></p></li><li><p><a href="https://michaelsendpoint.com/intune/MAMContractor.html">MAM for Contractors</a> &#8226; <em>Michael Frank</em></p></li><li><p><a href="https://modern-workplace.uk/?p=3142">Microsoft Entra: Hybrid Join Without ADFS</a> &#8226; <em>Fabrizio Volpe</em></p></li><li><p><a href="https://michev.info/blog/post/7641/more-secure-version-of-the-bitlocker-recovery-keys-export-script">More secure version of the Bitlocker recovery keys export script</a> &#8226; <em>Vasil Michev</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=fiPqKI16XiA">Ditch Public RDP Before It&#8217;s Too Late | Entra ID Bastion Setup</a> (8 min) &#8226; <em>Travis Roberts</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=AWDEsbwWGlg&amp;si=PbiutVGeo0kRMGr9">Entra ID support for Azure Bastion</a> (4 min) &#8226; <em>Brian Veldman</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p><a href="https://damienbod.com/2026/03/09/invite-guest-users-in-a-entra-id-multi-tenant-setup/">Invite Guest users in a Entra ID Multi-tenant setup</a> &#8226; <em>Damien Bowden</em></p></li></ul><h2>&#128200; Reporting and Insights</h2><ul><li><p><a href="https://controlaltdeletetechbits.co.uk/entra-sign-in-diagnostic/">Microsoft Entra Sign-in Diagnostic tool</a> &#8226; <em>Mark Oldham</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://patrickbinder.medium.com/entra-id-password-spraying-using-apim-as-ip-rotating-mechanism-3620861dd66a">Entra ID Password Spraying using APIM as IP-Rotating Mechanism</a> &#8226; <em>Patrick Binder</em></p></li><li><p><a href="https://securitylabs.datadoghq.com/articles/copilot-studio-logging-gaps/">Uncovering agent logging gaps in Copilot Studio</a> &#8226; <em>Katie Knowles</em></p></li></ul><h2>&#9851;&#65039; Sync</h2><ul><li><p><a href="https://blog.hametbenoit.info/2026/03/10/entra-id-entra-id-connect-cloud-sync-going-to-block-hard-match-for-privileged-roles/">Entra ID &#8211; Entra ID Connect/Cloud Sync going to block hard match for privileged roles</a> &#8226; <em>Benoit Hamet</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://blog.darrenjrobinson.com/entra-news-mcp-server/">Entra News MCP Server</a> &#8226; <em>Darren Robinson</em></p></li><li><p><a href="https://secureazcloud.com/microsoft-security/f/microsoft365e7hasarrived">Microsoft 365 E7 Has Arrived</a> &#8226; <em>Ankit Gupta</em></p></li><li><p><a href="https://ourcloudnetwork.com/microsoft-entra-to-receive-native-backup-capabilities/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-entra-to-receive-native-backup-capabilities">Microsoft Entra to Receive Native Backup Capabilities</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://lazyadmin.nl/office-365/new-microsoft-365-e7-plan-explained/">New Microsoft 365 E7 Plan Explained</a> &#8226; <em>Rudy Mens</em></p></li><li><p><a href="https://c7solutions.com/2026/03/tenant-switching-from-bookmarks">Tenant Switching From Bookmarks</a> &#8226; <em>Brian Reid</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=HkmdjJZpu-s">Microsoft Just Launched E7 - Here&#8217;s the Truth</a> (7 min) &#8226; <em>Jonathan Edwards</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=K2oiI2ZMFSk">Why Your Entra ID Still Depends on AD [Fix This]</a> (34 min) &#8226; <em>Ru Campbell</em></p></li></ul><h2>&#128717;&#65039; External ID - Customers</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/getting-the-sign-up-attributes-via-native-authentication-in-entra-external-id-eeid-6d195a9af340?source=rss-6601e21c1210------2">Getting the sign-up attributes via native authentication in Entra External ID (EEID)</a> &#8226; <em>Rory Braybrook</em></p></li></ul><div><hr></div><h2>&#9874;&#65039; Toolkit</h2><ul><li><p><a href="https://m365analyzer.com/">M365 Tenant Analyzer</a> &#8226; <a href="https://easyentra.com/">EasyEntra</a></p></li><li><p><a href="https://github.com/Cloud-Architekt/EntraOps">EntraOps v0.6 - AgentID Support, Advanced API Permission Classification &amp; Performance Improvements</a> &#8226; <em>Thomas Naunheim</em></p></li></ul><div><hr></div><h2>&#127897;&#65039; Podcasts</h2><ul><li><p>&#128250; <a href="https://www.youtube.com/watch?v=rLN7WoDLT4U">Episode 423 &#8211; Non-Human Identities in Microsoft Entra with Eric Woodruff and Chris Brumm</a> (39 min) &#8226; <em>Microsoft Cloud IT Pro Podcast</em></p></li></ul><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_quick-tip-for-microsoft-entra-admins-activity-7438351900502245376-QKpZ?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LrBJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 424w, https://substackcdn.com/image/fetch/$s_!LrBJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 848w, https://substackcdn.com/image/fetch/$s_!LrBJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 1272w, https://substackcdn.com/image/fetch/$s_!LrBJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LrBJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png" width="643" height="846.0526315789474" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1450,&quot;width&quot;:1102,&quot;resizeWidth&quot;:643,&quot;bytes&quot;:676872,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_quick-tip-for-microsoft-entra-admins-activity-7438351900502245376-QKpZ?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190987530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LrBJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 424w, https://substackcdn.com/image/fetch/$s_!LrBJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 848w, https://substackcdn.com/image/fetch/$s_!LrBJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 1272w, https://substackcdn.com/image/fetch/$s_!LrBJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f7d9d1b-6931-4b91-ba16-75617200630c_1102x1450.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>New homepage in the unified portal for myaccount.microsoft.com</strong></p><p>Microsoft just made a big improvement to the end-user identity experience.<br><br>The new homepage in the unified portal for <strong><a href="http://myaccount.microsoft.com/">myaccount.microsoft.com</a></strong> is now in public preview.<br><br>For the first time, users have a single front door for identity tasks.<br><br>Instead of navigating multiple pages, the homepage brings everything together</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_microsoft-just-made-a-big-improvement-to-activity-7437742266338885634-cmjS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hipj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 424w, https://substackcdn.com/image/fetch/$s_!Hipj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 848w, https://substackcdn.com/image/fetch/$s_!Hipj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 1272w, https://substackcdn.com/image/fetch/$s_!Hipj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hipj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png" width="1456" height="1253" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1253,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1627457,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_microsoft-just-made-a-big-improvement-to-activity-7437742266338885634-cmjS?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190987530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hipj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 424w, https://substackcdn.com/image/fetch/$s_!Hipj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 848w, https://substackcdn.com/image/fetch/$s_!Hipj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 1272w, https://substackcdn.com/image/fetch/$s_!Hipj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb1c23-6da7-4b2c-b8c4-e5afc8493d7e_2834x2438.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_one-of-the-most-underrated-tools-for-anyone-activity-7437282470569496576-uRrU?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aj1E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 424w, https://substackcdn.com/image/fetch/$s_!aj1E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 848w, https://substackcdn.com/image/fetch/$s_!aj1E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!aj1E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aj1E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png" width="1456" height="924" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:924,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2500073,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_one-of-the-most-underrated-tools-for-anyone-activity-7437282470569496576-uRrU?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190987530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aj1E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 424w, https://substackcdn.com/image/fetch/$s_!aj1E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 848w, https://substackcdn.com/image/fetch/$s_!aj1E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!aj1E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c35b7-1f97-421f-a40e-9c61c07a69e5_2322x1474.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_have-an-entra-question-and-want-to-tap-into-activity-7437250976903999488-HJlE?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fqHA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 424w, https://substackcdn.com/image/fetch/$s_!fqHA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 848w, https://substackcdn.com/image/fetch/$s_!fqHA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!fqHA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fqHA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png" width="566" height="757.0635208711434" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1474,&quot;width&quot;:1102,&quot;resizeWidth&quot;:566,&quot;bytes&quot;:723649,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_have-an-entra-question-and-want-to-tap-into-activity-7437250976903999488-HJlE?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190987530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fqHA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 424w, https://substackcdn.com/image/fetch/$s_!fqHA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 848w, https://substackcdn.com/image/fetch/$s_!fqHA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!fqHA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44696d7d-59b1-4d4c-9a36-b2fcde434fac_1102x1474.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_cybersecurity-microsoftauthenticator-zerotrust-activity-7437013897284595712-tOkl?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lJ66!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lJ66!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lJ66!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lJ66!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lJ66!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;graphical user interface, text, email&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_cybersecurity-microsoftauthenticator-zerotrust-activity-7437013897284595712-tOkl?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="graphical user interface, text, email" title="graphical user interface, text, email" srcset="https://substackcdn.com/image/fetch/$s_!lJ66!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lJ66!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lJ66!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lJ66!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc345681-507a-49d6-a26c-c6565d2eec3b_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[How to Migrate from Legacy VPNs to Entra Private Access (Real Strategies from a Veteran)]]></title><description><![CDATA[VPN &#8594; Entra]]></description><link>https://entra.news/p/how-to-migrate-from-legacy-vpns-to</link><guid isPermaLink="false">https://entra.news/p/how-to-migrate-from-legacy-vpns-to</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 14 Mar 2026 07:45:29 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/190904045/54761e0dd8808fc63632a9f18f61e8d4.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Richard Hicks wrote the book on DirectAccess. Then he wrote the one on Always On VPN. Now he&#8217;s here to tell you it&#8217;s time to move on from both (and other legacy VPNs). Over the last two years, Richard has helped numerous enterprise customers navigate the shift from legacy VPN to Microsoft Entra Private Access, and he&#8217;s collected some hard-learnt lessons along the way that most migration guides won&#8217;t tell you.</p><p>In this episode, Richard - enterprise security consultant and early Entra Private Access insider - breaks down why traditional VPN is fundamentally broken for today&#8217;s threat landscape, how Entra Private Access works under the hood, and the exact crawl-walk-run playbook he uses to migrate enterprise customers without disruption. Plus: his hot take on the Microsoft E7 announcement and why it just changed the pricing conversation forever.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AmgX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AmgX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 424w, https://substackcdn.com/image/fetch/$s_!AmgX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 848w, https://substackcdn.com/image/fetch/$s_!AmgX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!AmgX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AmgX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png" width="1200" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1944682,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190904045?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AmgX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 424w, https://substackcdn.com/image/fetch/$s_!AmgX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 848w, https://substackcdn.com/image/fetch/$s_!AmgX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!AmgX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684af5a1-1c2a-4fd7-b056-b55e3abc0d82_1200x1200.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>In this episode you&#8217;ll learn:</strong></p><ul><li><p>Why your VPN tunnel is a security liability &#8212; and how a single compromised device can expose your entire corporate network</p></li><li><p>How Entra Private Access works differently to traditional VPN, and why that architectural shift matters for security</p></li><li><p>The &#8220;Quick Access&#8221; migration strategy that lets you get off legacy VPN fast, without locking everything down on day one</p></li><li><p>How to deploy the Global Secure Access client alongside your existing VPN &#8212; so you can migrate field-based workers without a single disconnection</p></li><li><p>What most teams get wrong about the Entra Private Network Connector &#8212; and the scaling pitfalls that catch enterprises off guard</p></li><li><p>Why Conditional Access knowledge, not connectivity, is the real key to a successful zero trust migration</p></li><li><p>The current limitations of Entra Private Access and how to plan around them</p></li><li><p>We also discuss the new &#8216;E7&#8217; which includes Entra Private Access</p></li></ul><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-sFAlJxCfZzU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;sFAlJxCfZzU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/sFAlJxCfZzU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About Richard Hicks</h3><p>Richard Hicks is the founder and principal consultant at Richard M. Hicks Consulting, Inc. A Microsoft Most Valuable Professional (MVP) with more than 30 years of experience implementing secure remote access and public key infrastructure (PKI) solutions, he is a widely recognized enterprise mobility and security infrastructure expert sought after by organizations worldwide. His mission is to help companies provide visibility, control, and assurance for their field-based users and devices, ensuring the highest level of security and productivity for today&#8217;s highly mobile workforce.</p><p>LinkedIn - <a href="https://www.linkedin.com/in/richardhicks/">https://www.linkedin.com/in/richardhicks/</a></p><div><hr></div><p>&#128279; Related Links</p><ul><li><p>Richard&#8217;s Blog - <a href="https://directaccess.richardhicks.com/">https://directaccess.richardhicks.com/</a></p></li></ul><ul><li><p>Richard M. Hicks Consulting, Inc - <a href="https://www.richardhicks.com/">https://www.richardhicks.com/</a></p></li><li><p><a href="https://directaccess.richardhicks.com/always-on-vpn-vs-entra-private-access/">https://directaccess.richardhicks.com/always-on-vpn-vs-entra-private-access/</a></p></li></ul><div><hr></div><p><strong>&#128215; Chapters</strong></p><p>00:00 Intro </p><p>01:10 The History of Direct Access and Always On VPN </p><p>05:59 Transitioning to Zero Trust and Entra Private Access </p><p>11:34 Seamless Side-by-Side VPN Migration </p><p>17:37 Using Quick Access to Kickstart Zero Trust </p><p>23:43 Changing Mindsets: Identity over IP Addresses </p><p>27:55 The New Zero Trust Network Assessment Tool </p><p>29:17 Avoiding Pitfalls with the Entra Private Network Connector </p><p>33:11 Feature Wishlist: IPv6 and Process Binding </p><p>38:46 Hot Takes on the New Entra E7 Suite</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #139 → This week in Microsoft Entra]]></title><description><![CDATA[Learn about External auth methods going GA, SharePoint OTP retirement and more!]]></description><link>https://entra.news/p/entra-news-139-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-139-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 08 Mar 2026 13:53:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!eS-Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>&#128075;</em> Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>It&#8217;s been a busy week in the Entra community &#8212; with new GA and Public Preview features, a flurry of Message Center updates, handy community tools, and much more.</p><p>Below is a visual snapshot of this week&#8217;s highlights.</p><p>&#127897;&#65039; Also, don&#8217;t miss this week&#8217;s podcast episode with Nathan McNulty and Daniel Bradley, where we dive into the latest features and upcoming changes.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eS-Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eS-Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 424w, https://substackcdn.com/image/fetch/$s_!eS-Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 848w, https://substackcdn.com/image/fetch/$s_!eS-Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 1272w, https://substackcdn.com/image/fetch/$s_!eS-Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eS-Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png" width="1456" height="837" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:837,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5072160,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eS-Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 424w, https://substackcdn.com/image/fetch/$s_!eS-Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 848w, https://substackcdn.com/image/fetch/$s_!eS-Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 1272w, https://substackcdn.com/image/fetch/$s_!eS-Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb23e62bc-b72a-4046-9d64-6318fd2dee6a_2358x1356.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;5ecaad39-89ee-4430-a13d-7b1f7a57f9ba&quot;,&quot;caption&quot;:&quot;I am back home in Melbourne today, and joining me are Nathan McNulty from Alaska and Daniel Bradley from the UK as we dive into all the massive Entra updates that dropped last month. We are breaking down the controversial shift to syncable passkeys , why your Conditional Access policies might suddenly start blocking apps , and the absolute necessity of &#8230;&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Passkeys, Conditional Access, Hard-match updates, GSA BYOD: What Entra Admins Need To Know&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-03-07T13:38:51.701Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/190192220/55fc4ef9-2d71-4e8f-9346-4e7b5386e007/transcoded-1772889653.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/passkeys-conditional-access-hard&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:190192220,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.coreview.com/free-tool/teams-access-reviews?utm_medium=Entra_News&amp;utm_source=MVP&amp;utm_campaign=Security%20Scanner" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NyVX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 424w, https://substackcdn.com/image/fetch/$s_!NyVX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 848w, https://substackcdn.com/image/fetch/$s_!NyVX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 1272w, https://substackcdn.com/image/fetch/$s_!NyVX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NyVX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png" width="589" height="518.5524044389642" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:714,&quot;width&quot;:811,&quot;resizeWidth&quot;:589,&quot;bytes&quot;:358966,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.coreview.com/free-tool/teams-access-reviews?utm_medium=Entra_News&amp;utm_source=MVP&amp;utm_campaign=Security%20Scanner&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NyVX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 424w, https://substackcdn.com/image/fetch/$s_!NyVX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 848w, https://substackcdn.com/image/fetch/$s_!NyVX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 1272w, https://substackcdn.com/image/fetch/$s_!NyVX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F753f806a-ddcb-49cb-a111-4463c57adefc_811x714.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Would you bet your reputation on your current Microsoft 365 security posture?</strong></p><p>Sure, you&#8217;ve checked Purview. Maybe tightened Conditional Access. We all do that.</p><p>But it&#8217;s usually the quiet stuff that bites... permissions that expanded, policies that drifted, exceptions nobody revisited.</p><p>You could assume it&#8217;s fine.</p><p>Or you could run the Microsoft 365 Security Posture Check.</p><p>It&#8217;s free.</p><p>It runs locally.</p><p>And no, it doesn&#8217;t send your tenant data back to us.</p><p>We&#8217;ll even help you set it up.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.coreview.com/free-tool/teams-access-reviews?utm_medium=Entra_News&amp;utm_source=MVP&amp;utm_campaign=Security%20Scanner&quot;,&quot;text&quot;:&quot;Get yours here:&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.coreview.com/free-tool/teams-access-reviews?utm_medium=Entra_News&amp;utm_source=MVP&amp;utm_campaign=Security%20Scanner"><span>Get yours here:</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#127942; General Availability</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---external-auth-methods-is-generally-available">External Auth Methods is Generally Available</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---expanded-attribute-support-in-lifecycle-workflows-attribute-changes-trigger">Expanded attribute support in Lifecycle Workflows attribute changes trigger</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---delegated-workflow-management-in-lifecycle-workflows">Delegated Workflow Management in Lifecycle Workflows</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#upcoming-change--microsoft-entra-connect-security-update-to-block-hard-match-for-privileged-roles">Upcoming change &#8211; Microsoft Entra Connect security update to block hard match for privileged roles</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#upcoming-changes---jailbreak-detection-in-authenticator-app">Jailbreak Detection in Authenticator App</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---microsoft-entra-connect-sync-now-supports-windows-server-2025">Microsoft Entra Connect Sync now supports Windows Server 2025</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---revoke-previously-approved-access-package-assignments-in-my-access">Revoke previously approved access package assignments in My Access</a></p></li></ul><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/rethinking-%E2%80%9Callow-my-organization-to-manage-my-device%E2%80%9D-why-opt%E2%80%91in-enrollment-wor/4499766">Rethinking &#8220;Allow my organization to manage my device&#8221; Why opt&#8209;in enrollment works better for Intune</a> &#8226; <em>Ramya Sharma</em></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-bring-your-own-device">GSA: BYOD support for Windows client using Microsoft Entra registration</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---custom-block-pages">GSA: Custom Block pages</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#public-preview---new-end-user-homepage-in-my-account">New end user homepage in My Account</a></p></li></ul><h2>&#128214; Read</h2><ul><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/">OAuth redirection abuse enables phishing and malware delivery</a> &#8226; <em>Microsoft Defender Security Research Team</em></p></li><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/">Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale</a> &#8226; <em>Microsoft Threat Intelligence, Microsoft Defender Security Research Team</em></p></li></ul><h2>&#128250; Watch</h2><ul><li><p><a href="https://www.youtube.com/watch?v=w7t-Of8jBv4">Conditional Access Optimization Agent: What It Is &amp; Why It Matters</a> (39 min) &#8226; <em>Microsoft Security Community</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1221452">MC1221452 - Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants</a></p></li><li><p><a href="https://mc.merill.net/message/MC1243549">MC1243549 - Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B</a></p></li><li><p><a href="https://mc.merill.net/message/MC1246002">MC1246002 - Prevent/Fix: Microsoft Baseline Security Mode has automatically trigger Entra Conditional Access policy creation</a></p></li></ul><h2>&#128198; Upcoming Events</h2><ul><li><p><a href="https://www.meetup.com/nl-nl/dmecnl/events/313395022/">Join us for the upcoming Dutch Microsoft Entra Community Meetup</a> &#8226; <em>Jan Bakker</em></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/activity-7435521375882207232-zbV4?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fs3Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 424w, https://substackcdn.com/image/fetch/$s_!fs3Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 848w, https://substackcdn.com/image/fetch/$s_!fs3Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 1272w, https://substackcdn.com/image/fetch/$s_!fs3Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fs3Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png" width="1456" height="1296" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1296,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:903121,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/activity-7435521375882207232-zbV4?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fs3Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 424w, https://substackcdn.com/image/fetch/$s_!fs3Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 848w, https://substackcdn.com/image/fetch/$s_!fs3Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 1272w, https://substackcdn.com/image/fetch/$s_!fs3Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6c1be3-3d3c-4da6-8b88-fa537a2b09b5_1854x1650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/SamErde/status/2028984827433701478?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DvGP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 424w, https://substackcdn.com/image/fetch/$s_!DvGP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 848w, https://substackcdn.com/image/fetch/$s_!DvGP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 1272w, https://substackcdn.com/image/fetch/$s_!DvGP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DvGP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png" width="1276" height="1354" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1354,&quot;width&quot;:1276,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:816272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/SamErde/status/2028984827433701478?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DvGP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 424w, https://substackcdn.com/image/fetch/$s_!DvGP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 848w, https://substackcdn.com/image/fetch/$s_!DvGP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 1272w, https://substackcdn.com/image/fetch/$s_!DvGP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bc641d2-243b-4224-bb70-8978fb9809b2_1276x1354.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://skiptotheendpoint.co.uk/intune-administrator-is-the-new-domain-admin/">Intune Administrator Is the New Domain Admin</a> &#8226; <em>James Robinson</em></p></li><li><p>&#129352;<a href="https://o365reports.com/difference-between-app-registrations-and-enterprise-apps/">Difference Between App Registrations and Enterprise Apps</a> &#8226; <em>Dhinesh</em></p></li><li><p>&#129353;<a href="https://agderinthe.cloud/2026/02/26/passkey-onboarding-in-entra-what-microsoft-doesnt-tell-you/">Passkey onboarding in Entra: What Microsoft doesn&#8217;t tell you!</a> &#8226; <em>Per-Torben S&#248;rensen</em></p></li></ul><h1>&#9728;&#65039; Learn</h1><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://irwins.github.io/blog/posts/testing-msgraph-agent-skill/">Testing the msgraph Copilot Skill: Giving AI Agents a Local Graph API Brain</a> &#8226; <em>Irwin Strachan</em></p></li></ul><h2>&#129520; Workload ID</h2><ul><li><p><a href="https://www.hipconf.com/resources/become-a-wizard-of-entra-workload-identities/">Become a Wizard of Entra Workload Identities</a> &#8226; <em>Eric Woodruff, Thomas Naunheim</em></p></li><li><p><a href="https://www.cloudidentity.se/blog/managed-identities-and-how-i-use-them/">Managed Identities and How I Use Them</a> &#8226; <em>Dennis J.</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p><a href="https://www.cloudcoffee.ch/microsoft-azure/microsoft-entra-private-access-external-users/">Microsoft Entra Private Access: Secure Access for External Users to Internal Resources</a> &#8226; <em>Oliver M&#252;ller</em></p></li><li><p><a href="https://medium.com/@kmuitspice/update-global-secure-access-client-with-intune-smb-it-spice-83630fb2bda8">Update Global Secure Access Client With Intune</a> &#8226; <em>Marco Wohler</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://blog.pryrotech.com/2026/02/how-to-use-app-registration-deactivation.html">How To Use App Registration Deactivation</a> &#8226; <em>Colby Pryor</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://www.matej.guru/p/march-2026-is-here-synced-passkeys">March 2026 is here! Synced Passkeys and Passkey Profiles rollout?</a> &#8226; <em>Matej Klemen&#269;i&#269;</em></p></li><li><p><a href="https://medium.com/@eminhuseynov_37266/microsoft-documentation-says-passkeys-in-authenticator-cant-log-into-or-unlock-windows-088e83a5e6ee?source=rss-6acd8e7fc68a------2">Microsoft Documentation Says Passkeys in Authenticator Can&#8217;t Log Into or Unlock Windows workstations ; But They Can</a> &#8226; <em>Dr. Emin Huseynov</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/shorts/A9WstmrTJFY">How To Enable Synced Passkeys In Entra ID</a> &#8226; <em>Azure Academy</em></p></li></ul><h2>&#128101; User &amp; Group Management</h2><ul><li><p><a href="https://www.cloudidentity.se/blog/creating-new-entra-id-users-the-powershell-way/">Creating New Entra ID Users the PowerShell Way</a> &#8226; <em>Dennis J.</em></p></li><li><p><a href="https://o365reports.com/group-insights-in-microsoft-entra-id/">Microsoft Introduces Group Insights in Entra ID (Preview)</a> &#8226; <em>Praba</em></p></li></ul><h2>&#129302; DevOps &amp; PowerShell</h2><ul><li><p><a href="https://janbakker.tech/how-to-get-better-with-graph-api-part-one/">How to get better with Graph API &#8211; Part one</a> &#8226; <em>Jan Bakker</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://controlaltdeletetechbits.co.uk/conditional-access-session-controls/">Conditional Access Session Controls Sessions Running Forever</a> &#8226; <em>Control Alt Delete Tech Bits</em></p></li></ul><h2>&#128272; Credential Management</h2><ul><li><p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/the-future-of-identity-self-service-account-recovery-preview-in-microsoft-entra/4499749">The Future of Identity: Self-Service Account Recovery (Preview) in Microsoft Entra</a> &#8226; <em>Farooque</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p><a href="https://joostgelijsteen.com/designing-app-protection-policy/">Designing an App Protection Policy that don&#8217;t backfire on your unmanaged devices - Just about the Modern Workplace</a> &#8226; <em>Joost Gelijsteen</em></p></li><li><p><a href="https://emsroute.com/2026/03/04/disable-user-enrolling-personal-windows-devices-in-intune/">Disable User Enrolling Personal Windows Devices in Intune</a> &#8226; <em>Shehan Perera</em></p></li><li><p><a href="https://petervanderwoude.nl/post/disabling-mdm-enrollment-when-adding-work-or-school-account/">Disabling MDM enrollment when adding work or school account</a> &#8226; <em>Peter van der Woude</em></p></li><li><p><a href="https://medium.com/@brianveldman/entra-id-support-for-azure-bastion-32b2bb16b8d6?source=rss-4a3a93df846e------2">Entra ID support for Azure Bastion</a> &#8226; Brian Veldman</p></li><li><p><a href="https://intuneirl.com/under-the-hood-how-brokered-authentication-works-on-ios-android/">Under the Hood: How Brokered Authentication Works on iOS &amp; Android - Intune - In Real Life</a> &#8226; <em>Somesh Pathak</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=DmcKYPQlsdU">App Protection Policies: BYOD Done Right in Microsoft 365</a> (15 min) &#8226; <em>Jonathan Edwards</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p><a href="https://office365itpros.com/2026/03/06/guest-accounts-spo/">SharePoint Online Drops One Time Passcodes for External Access</a> &#8226; <em>Tony Redmond</em></p></li><li><p><a href="https://blog.admindroid.com/entra-b2b-replaces-sharepoint-one-time-passcode-for-external-sharing/">Entra B2B Replaces SharePoint One-Time Passcode for External Sharing</a> &#8226; <em>Admin Droid</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://medium.com/@Big_Bad_Jon/theres-a-cable-guy-in-your-tenant-f26eeb5c10d2">There&#8217;s a Cable Guy in Your Tenant</a> &#8226; Jon Haas</p></li><li><p><a href="https://www.linkedin.com/pulse/signinlogs-threat-hunting-workbook-your-frontline-alonso-dominguez-uwkae?utm_source=share&amp;utm_medium=member_android&amp;utm_campaign=share_via">&#127919; SigninLogs Threat Hunting Workbook Your frontline defense against identity-based attacks in Microsoft Sentinel</a> &#8226; <em>David Alonso Dominguez</em></p></li><li><p><a href="https://www.cloudidentity.se/blog/making-global-administrators-safer/">Making Global Administrators Safer</a> &#8226; <em>Dennis J.</em></p></li><li><p><a href="https://blog.admindroid.com/how-to-mitigate-consentfix-oauth-attacks-in-microsoft365/">What is ConsentFix Attack and How to Mitigate it in Microsoft 365</a> &#8226; <em>Kanaga</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://michev.info/blog/post/7624/new-ui-to-manage-allowed-tenants-for-entra-id-integrated-applications">New UI to manage allowed tenants for Entra ID integrated applications</a> &#8226; <em>Vasil Michev</em></p></li></ul><div><hr></div><h2>&#9874;&#65039; Toolkit</h2><ul><li><p><a href="https://github.com/SamErde/DLLPickle">SamErde/DLLPickle: A PowerShell module that helps you get un-stuck from dependency version conflicts that can occur when connecting to multiple Microsoft services in the same session.</a> &#8226; <em>Sam Erde</em></p></li><li><p><a href="https://github.com/codeandersen/Group-SOA-Conversion-Tool">codeandersen/Group-SOA-Conversion-Tool</a> &#8226; <em>Hans Christian Andersen</em></p></li></ul><div><hr></div><h2>&#128293; Maester</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/nathanmcnulty_fully-automated-deployment-of-maester-for-activity-7434842324188217344-2350?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8mQg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 424w, https://substackcdn.com/image/fetch/$s_!8mQg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 848w, https://substackcdn.com/image/fetch/$s_!8mQg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 1272w, https://substackcdn.com/image/fetch/$s_!8mQg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8mQg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png" width="1120" height="974" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:974,&quot;width&quot;:1120,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:333304,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/nathanmcnulty_fully-automated-deployment-of-maester-for-activity-7434842324188217344-2350?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8mQg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 424w, https://substackcdn.com/image/fetch/$s_!8mQg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 848w, https://substackcdn.com/image/fetch/$s_!8mQg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 1272w, https://substackcdn.com/image/fetch/$s_!8mQg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e3bef-61d1-4018-b066-38dbc21e320b_1120x974.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_yup-apparently-they-let-anyone-go-to-rsac-activity-7435837347272986624-PBCs?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wfFz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 424w, https://substackcdn.com/image/fetch/$s_!wfFz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 848w, https://substackcdn.com/image/fetch/$s_!wfFz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 1272w, https://substackcdn.com/image/fetch/$s_!wfFz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wfFz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png" width="1102" height="1216" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1216,&quot;width&quot;:1102,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:624171,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_yup-apparently-they-let-anyone-go-to-rsac-activity-7435837347272986624-PBCs?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wfFz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 424w, https://substackcdn.com/image/fetch/$s_!wfFz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 848w, https://substackcdn.com/image/fetch/$s_!wfFz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 1272w, https://substackcdn.com/image/fetch/$s_!wfFz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c7a6b74-f133-461b-b68f-6c22f3bb53b0_1102x1216.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_hey-folks-i-published-a-new-ai-skill-activity-7435329642485673984-Lypr?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iFYE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 424w, https://substackcdn.com/image/fetch/$s_!iFYE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 848w, https://substackcdn.com/image/fetch/$s_!iFYE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!iFYE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iFYE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png" width="1112" height="1474" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1474,&quot;width&quot;:1112,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:711840,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_hey-folks-i-published-a-new-ai-skill-activity-7435329642485673984-Lypr?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iFYE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 424w, https://substackcdn.com/image/fetch/$s_!iFYE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 848w, https://substackcdn.com/image/fetch/$s_!iFYE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 1272w, https://substackcdn.com/image/fetch/$s_!iFYE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77dfd704-75d3-4bb1-8537-0b277033d745_1112x1474.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_wow-this-is-so-cool-jukka-niiranen-activity-7434588067371499520-Tp-G?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EOCh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 424w, https://substackcdn.com/image/fetch/$s_!EOCh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 848w, https://substackcdn.com/image/fetch/$s_!EOCh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 1272w, https://substackcdn.com/image/fetch/$s_!EOCh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EOCh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png" width="1456" height="1452" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/adce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1452,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2444681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_wow-this-is-so-cool-jukka-niiranen-activity-7434588067371499520-Tp-G?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190245565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EOCh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 424w, https://substackcdn.com/image/fetch/$s_!EOCh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 848w, https://substackcdn.com/image/fetch/$s_!EOCh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 1272w, https://substackcdn.com/image/fetch/$s_!EOCh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadce82ae-570f-4e17-9d92-cce1b2e60d23_1602x1598.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[Passkeys, Conditional Access, Hard-match updates, GSA BYOD: What Entra Admins Need To Know]]></title><description><![CDATA[Top 5 February Microsoft Entra Updates & Announcements Full Deep Dive!]]></description><link>https://entra.news/p/passkeys-conditional-access-hard</link><guid isPermaLink="false">https://entra.news/p/passkeys-conditional-access-hard</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 07 Mar 2026 13:38:51 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/190192220/25eb6df3f1c45d6ed71dd2d0bbd985f2.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>I am back home in Melbourne today, and joining me are Nathan McNulty from Alaska and Daniel Bradley from the UK as we dive into all the massive Entra updates that dropped last month. We are breaking down the controversial shift to syncable passkeys , why your Conditional Access policies might suddenly start blocking apps , and the absolute necessity of moving privileged accounts away from on-prem AD. We&#8217;re also geeking out over some incredible new Global Secure Access (GSA) features and how AI is completely transforming the way we work with Graph API. You won&#8217;t want to miss the under-the-radar changes that could impact your tenant&#8217;s security architecture overnight.</p><p>Here&#8217;s a quick overview of all the topics we covered in this episode (links below).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XY6W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XY6W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!XY6W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!XY6W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!XY6W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XY6W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3197681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190192220?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XY6W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!XY6W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!XY6W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!XY6W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faecb3d2a-7105-4e60-a89e-6245acf10817_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XG0w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XG0w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!XG0w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!XG0w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!XG0w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XG0w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:324851,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/190192220?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!XG0w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!XG0w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!XG0w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!XG0w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F086a9518-019d-43a6-b3d7-86728001fa7e_1200x600.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Scan, Score, and Secure Your Applications in Entra</strong></p><p>Application identities represent one of the largest attack surfaces in Entra and are often among the least consistently governed.<strong> </strong><a href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=Entra.chat&amp;utm_medium=podcast&amp;utm_content=3.8.26">AppGov Score</a> helps IT and Security teams understand where risk exists. The 24-check assessment evaluates Entra ID application integrations against Microsoft-recommended governance practices, analyzing:</p><ul><li><p>App registrations and enterprise apps for excessive permissions</p></li><li><p>Expired or unmanaged secrets</p></li><li><p>Ownerless apps</p></li><li><p>Risky consent grants, and</p></li><li><p>Privileged service principals</p></li></ul><p>Results are delivered as a clear, defensible risk score with actionable findings. No scripts. No manual inventory. Just a fast, read-only scan that reveals app sprawl, identity misconfigurations, and blast radius so you can prioritize remediation and strengthen your security posture with confidence.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=Entra.chat&amp;utm_medium=podcast&amp;utm_content=3.8.26&quot;,&quot;text&quot;:&quot;Scan Your Tenant &#8211; No Cost&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=Entra.chat&amp;utm_medium=podcast&amp;utm_content=3.8.26"><span>Scan Your Tenant &#8211; No Cost</span></a></p></blockquote><div><hr></div><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-vQv3l3_Mhrw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;vQv3l3_Mhrw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/vQv3l3_Mhrw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About Nathan McNulty</h3><p>Senior Security Solutions Architect at Patriot Consulting and Microsoft MVP in security. Nathan is the practice lead for identity and has extensive experience with endpoint deployments and everything Entra.</p><p>LinkedIn -<a href="https://www.linkedin.com/in/nathanmcnulty/"> https://www.linkedin.com/in/nathanmcnulty/</a></p><h3>About Daniel Bradley</h3><p>Senior Solution Architect for CDW down in the UK and an MVP in Identity Security and M365 for Graph API. Daniel specializes in pre-sales, mergers, acquisitions, and the highly technical migration space.</p><p>LinkedIn - <a href="https://www.linkedin.com/in/danielbradley2/">https://www.linkedin.com/in/danielbradley2/</a></p><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p> Entra What's New - <a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new">https://learn.microsoft.com/en-us/entra/fundamentals/whats-new</a></p></li><li><p>Upcoming Conditional Access change: Improved enforcement for policies with resource exclusions - <a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/upcoming-conditional-access-change-improved-enforcement-for-policies-with-resour/4488925">https://techcommunity.microsoft.com/blog/microsoft-entra-blog/upcoming-conditional-access-change-improved-enforcement-for-policies-with-resour/4488925</a></p></li><li><p>XDRInternals - <a href="https://github.com/MSCloudInternals/XDRInternals">https://github.com/MSCloudInternals/XDRInternals</a></p></li><li><p>Passkey Login - <a href="https://github.com/nathanmcnulty/nathanmcnulty/blob/main/Entra/passkeys/PasskeyLogin.ps1">https://github.com/nathanmcnulty/nathanmcnulty/blob/main/Entra/passkeys/PasskeyLogin.ps1</a></p></li><li><p>Graph PM - <a href="https://graph.pm">https://graph.pm</a></p></li></ul><div><hr></div><h3>&#128215; Chapters</h3><p>03:01 Syncable Passkeys &amp; Registration Changes</p><p>18:10 Conditional Access Policy Updates</p><p>26:35 Blocking Hard Match for Privileged Roles</p><p>35:42 External Authentication Methods GA</p><p>43:04 Lifecycle Workflows &amp; Admin Units</p><p>48:01 Global Secure Access (GSA) BYOD Preview</p><p>53:06 New My Account Portal &amp; Authenticator Updates</p><p>58:43 AI Skills &amp; Automating Graph API</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #138 → This week in Microsoft Entra]]></title><description><![CDATA[&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.]]></description><link>https://entra.news/p/entra-news-138-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-138-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 01 Mar 2026 11:28:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KTmN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>&#128075;</em> Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p>I&#8217;m finally back in Melbourne after an incredible week at <a href="https://eldk26.expertslive.dk/">Experts Live Denmark</a> in Copenhagen. As Rod Trent beautifully put it in his <a href="https://rodtrent.substack.com/p/reflections-on-experts-live-denmark">latest post</a>, it truly felt like a &#8220;Tech Family Reunion Like No Other.&#8221;</p><p>The highlight for me wasn&#8217;t just the tech, it was the people. There is something so special about finally shaking hands with folks I&#8217;ve only ever known through LinkedIn, Twitter/X, and blog posts. Turning those digital handles into real-world friendships is what makes this community so vibrant.</p><p>A massive shoutout to Morten Knudsen and his entire team for organizing such a seamless and high-energy event.</p><p><strong>The Gift for You: Open-Source Labs &#128275;</strong> </p><p>I had the honor of hosting a one-day Identity Masterclass with MVPs Thomas, Jan, Klaus, and Pim. We didn&#8217;t want the learning to stay in the room, so we&#8217;ve open-sourced our labs! You can find the links and hear the behind-the-scenes stories in this week&#8217;s Entra Chat podcast.</p><p>Let&#8217;s get into it &#9889;&#65039;</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e340e3ce-3f35-478f-8d30-fd6003f5c617&quot;,&quot;caption&quot;:&quot;Hey folks, I have to start with a massive shout-out to Morten Knudsen and his entire team at Experts Live Denmark where I&#8217;m just returning from.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;We Gave Away Our Microsoft Entra Masterclass Labs &#8594; Full Governance, Privileged Access &amp; Agent ID Labs Walkthrough&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-02-28T12:41:05.342Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/189421747/b0522b78-2f64-424c-922a-28a9fff0f2c1/transcoded-1772281383.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/we-gave-away-our-microsoft-entra&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:189421747,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:8,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tQDo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!tQDo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!tQDo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!tQDo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tQDo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:286752,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189526732?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tQDo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!tQDo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!tQDo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!tQDo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fc47ec-d102-4787-bed0-2e31bbf4fbb6_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Hybrid User Onboarding: One CmdLet &#8211; Two Parameters</strong></p><p>Fact: Hybrid user onboarding across AD, Entra ID, and Exchange Online is time-consuming and error-prone.</p><p><strong>EasyEntra&#8217;s new</strong> Invoke-EECreateHybridUserFromTemplate <strong>CmdLet changes that:</strong></p><p>&#128640; One command creates a fully provisioned hybrid user in ~30 secs.<br>&#128640; Just two parameters: DisplayName and TemplateName.<br>&#128640; Templates are defined from existing users with an intuitive UI in seconds.<br>&#128640; Schedule onboarding in advance or bulk-create users with a one-liner.<br>&#128640; EasyEntra is free for tenants with fewer than 25 licensed users.</p><p>No more context switching between consoles. No more provisioning drift between new hires.<br>Just fast, consistent, automated onboarding from a single command.</p><p><em><strong>&#8220;This product has been a miracle for our Helpdesk.&#8221;</strong></em><br>Manager of IT Customer Support, Junior Achievement, United States</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding&quot;,&quot;text&quot;:&quot;Learn More&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding"><span>Learn More</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join-using-microsoft-entra-kerberos">Microsoft Entra hybrid join using Microsoft Entra Kerberos (preview)</a> &#8226; <em>Microsoft Learn</em></p></li></ul><h2>&#128250; Watch</h2><ul><li><p><a href="https://www.youtube.com/watch?v=6MoV7SEEkJg">Identity Control Plane Under Attack: Consent Abuse and Hybrid Sync Risks</a> (42 min) &#8226; <em>Dima Zinkevich,  Nestori Syynimaa, Tal Guetta, and Luc van den Ende</em></p></li><li><p><a href="https://www.youtube.com/watch?v=xxitK6GpHhg">Explore Microsoft Agent 365 security and governance capabilities</a> (7 min) &#8226; <em>Irina Nechaeva</em></p></li><li><p><a href="https://www.youtube.com/watch?v=Uy6vWSuKDDI">Integrating verification in your app with Microsoft Entra Verified ID &#8211; Part I</a> (14 min) <a href="https://www.youtube.com/watch?v=oc5HaIUUehs">Part II</a> (16 min) &#8226; <em>Jas Suri, Yoel Horvitz</em></p></li><li><p><a href="https://www.youtube.com/watch?v=iU-zJIGFEYQ">How to Set Up Account Recovery with Microsoft Entra</a> (2 min) &#8226; <em>Microsoft Security</em></p></li></ul><h2>&#128483;&#65039; Message Center</h2><ul><li><p><a href="https://mc.merill.net/message/MC1179154">MC1179154 - Microsoft Authenticator app: Upcoming changes to jailbreak and root detection</a></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://ourcloudnetwork.com/microsoft-introduces-entra-hybrid-join-using-entra-kerberos/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-introduces-entra-hybrid-join-using-entra-kerberos">Microsoft Introduces Entra Hybrid Join using Entra Kerberos</a> &#8226; <em>Daniel Bradley</em></p></li><li><p>&#129352;<a href="https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/">What admins can learn from the new Entra ID Groups Insights blade</a> &#8226; <em>Jan Bakker</em></p></li><li><p>&#129353;<a href="https://controlaltdeletetechbits.co.uk/pim-for-groups-guide/">PIM for Groups Are You Still Assigning Roles to Users?</a> &#8226; <em>Control Alt Delete Tech Bits</em></p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.1.26" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JRBW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!JRBW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!JRBW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!JRBW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JRBW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:279516,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.1.26&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189526732?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JRBW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!JRBW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!JRBW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!JRBW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f5efbfa-d73a-41f1-826e-6b03be979dc8_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Scan, Score, and Secure Your Applications in Entra</strong></p><p>Application identities represent one of the largest attack surfaces in Entra and are often among the least consistently governed.<strong> </strong><a href="https://www.appgovscore.com/appgov-score?utm_campaign=AppGov%20Score&amp;utm_source=Entra.chat&amp;utm_medium=email&amp;utm_content=1.25.26">AppGov Score</a> helps Entra &amp; M365 teams understand where risk exists. The 24-check assessment evaluates Entra ID application integrations against Microsoft-recommended governance practices, analyzing:</p><ul><li><p>App registrations and enterprise apps for excessive permissions</p></li><li><p>Expired or unmanaged secrets</p></li><li><p>Ownerless apps</p></li><li><p>Risky consent grants, and</p></li><li><p>Privileged service principals</p></li></ul><p>Results are delivered as a clear, defensible risk score with actionable findings. No scripts. No manual inventory. Just a fast, read-only scan that reveals app sprawl, identity misconfigurations, and blast radius so you can prioritize remediation and strengthen your security posture with confidence.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.1.26&quot;,&quot;text&quot;:&quot;Get Your Baseline Score&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.appgovscore.com/appgov-score/?utm_campaign=AppGov%20Score&amp;utm_source=EntraNews&amp;utm_medium=email&amp;utm_content=3.1.26"><span>Get Your Baseline Score</span></a></p></blockquote><div><hr></div><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/DecryptedTech/status/2027059750622449912?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zE_a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 424w, https://substackcdn.com/image/fetch/$s_!zE_a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 848w, https://substackcdn.com/image/fetch/$s_!zE_a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 1272w, https://substackcdn.com/image/fetch/$s_!zE_a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zE_a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png" width="645" height="926.6352739726027" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1678,&quot;width&quot;:1168,&quot;resizeWidth&quot;:645,&quot;bytes&quot;:543710,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/DecryptedTech/status/2027059750622449912?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189526732?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zE_a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 424w, https://substackcdn.com/image/fetch/$s_!zE_a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 848w, https://substackcdn.com/image/fetch/$s_!zE_a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 1272w, https://substackcdn.com/image/fetch/$s_!zE_a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa633e4ee-5033-4f42-9ca2-5b81f943f178_1168x1678.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://dev.to/willvelida/understanding-microsoft-entra-agent-id-4972">Understanding Microsoft Entra Agent ID</a> &#8226; <em>Will Velida</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=WTcyL68qTo8">Agent 365 and Agent ID Overview</a> (48 min) &#8226; <em>John Savill</em></p></li></ul><h2>&#129520; Workload ID</h2><ul><li><p><a href="https://blog.mindcore.dk/2026/02/microsoft-graph-remembered-to-restict-mail-send-application-permission-app-access-policies/">Microsoft Graph &#8211; Remembered to restict Mail.Send Application Permission? (App Access Policies)</a> &#8226; <em>Michael Morten Sonne</em></p></li></ul><h2>&#128110;&#8205;&#9794;&#65039; ID Governance</h2><ul><li><p><a href="https://www.christianfrohn.dk/2026/02/23/admin-account-lifecycle-management-part-2-security-and-accesses/">Admin Account Lifecycle Management &#8211; Part 2: Security and Accesses</a> &#8226; <em>Christian Frohn</em></p></li><li><p><a href="https://agderinthe.cloud/2026/02/24/lifecycle-automation-beyond-the-happy-path/">Late Hires, Rehires, and Lifecycle Automation Beyond the Happy Path</a> &#8226; <em>Sandra Saluti</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=6L7v0qp41U4">Entra ID Access Reviews The beginners Guide</a> (19 min) &#8226; <em>Andy Malone</em></p></li><li><p>&#128250; <a href="https://youtube.com/watch?v=ck0RF8Gz_aQ&amp;si=ybH_bNq5ryweBhFf">Simplifying Access Governance with Microsoft Entra ID Access Packages</a> (33 min) &#8226; <em>David Nudelman</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p>&#128250; <a href="https://www.youtube.com/watch?v=l4xXA8wgsIA">Zero Trust, GSA &amp; Defender Automation: Breaking Up with VPNs (feat. Brumm &amp; Bader)</a> (30 min) &#8226; <em>Christopher Brumm, Fabian Bader, Frans Oudendorp and Michel van Vliet</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://office365itpros.com/2026/02/25/scoped-graph-permission-lists/">How to Use Scoped Graph Permissions with SharePoint Lists</a> &#8226; <em>Tony Redmond</em></p></li><li><p><a href="https://o365reports.com/difference-between-app-registrations-and-enterprise-apps/">Difference Between App Registrations and Enterprise Apps</a> &#8226; <em>Dhinesh</em></p></li><li><p><a href="https://www.thetechtrails.com/2026/02/restrict-admin-consent-specific-users-microsoft-entra-id.html">Stop Unintended Tenant-Wide App Access in Microsoft Entra ID</a> &#8226; <em>Sreejith Reghunathan Pillai</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=yfv9YnMjXKQ">The 1 MISTAKE Everyone is Making with Entra Enterprise Apps</a> (16 min) &#8226; <em>Ru Campbell</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://medium.com/@kmuitspice/windows-hello-for-business-multi-factor-unlock-smb-it-spice-68ba0846a209">Windows Hello for Business Multi Factor Unlock</a> &#8226; <em>Marco Wohler</em></p></li></ul><h2>&#128101; User &amp; Group Management</h2><ul><li><p><a href="https://ourcloudnetwork.com/microsoft-entra-one-person-one-license-now-what/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-entra-one-person-one-license-now-what">Microsoft Entra: One Person One License, Now What?</a> &#8226; <em>Daniel Bradley</em></p></li></ul><h2>&#129302; DevOps &amp; PowerShell</h2><ul><li><p><a href="https://alflokken.github.io/posts/graph-delta-queries/">Microsoft Graph Delta Query in PowerShell</a> &#8226; <em>Alf L&#248;kken</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://medium.com/@jhope188/conditional-access-demo-time-bound-access-c397bb9b2c29">Conditional Access Demo: Time-Bound Access</a> &#8226; <em>Jon Hope</em></p></li><li><p><a href="https://nothingbutcloud.net/2026-02-26-CAPolicyWorkbook/">How to Build a Log Analytics Workbook for Unused CA Policies</a> &#8226; <em>Klaus Bierschenk</em></p></li><li><p><a href="https://msendpointmgr.com/2026/02/25/troubleshooting-windows-first-sign-in-restore-when-conditional-access-gets-in-the-way/">Troubleshooting Windows First Sign&#8209;in Restore When Conditional Access Gets in the Way</a> &#8226; <em>Simon Skotheimsvik</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=J1B9TvO4GOI">Does Your Conditional Access Actually Work? Here&#8217;s How to Check</a> (12 min) &#8226; <em>Jonathan Edwards</em></p></li></ul><h2>&#128272; Credential Management</h2><ul><li><p><a href="https://agderinthe.cloud/2026/02/26/passkey-onboarding-in-entra-what-microsoft-doesnt-tell-you/">Passkey onboarding in Entra: What Microsoft doesn&#8217;t tell you!</a> &#8226; <em>Per-Torben S&#248;rensen</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p><a href="https://f12.hu/2026/02/22/delegating-laps-password-retrieval-at-device-level/">Delegating LAPS password retrieval at device level</a> &#8226; <em>D&#225;niel Kov&#225;cs</em></p></li><li><p><a href="https://patchmypc.com/blog/disable-mdm-enrollment-when-adding-a-work-or-school-account/">Disable MDM Enrollment When Adding a Work or School Account on Windows</a> &#8226; <em>Rudy Ooms</em></p></li><li><p><a href="https://blog.admindroid.com/entra-kerberos-for-hybrid-join-devices/">Entra Hybrid-Join Devices Using Microsoft Entra Kerberos</a> &#8226; <em>Blesslin Rinu</em></p></li><li><p><a href="https://blog.admindroid.com/disable-allow-my-organization-to-manage-my-device-prompt/">How to Disable &#8216;Allow My Organization to Manage My Device&#8217; Prompt</a> &#8226; <em>AIMA</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://skiptotheendpoint.co.uk/intune-administrator-is-the-new-domain-admin/">Intune Administrator Is the New Domain Admin</a> &#8226; <em>James Robinson</em></p></li><li><p><a href="https://blog.timcappalli.me/p/passkeys-prf-warning/">Please, please, please stop using passkeys for encrypting user data</a> &#8226; <em>Tim Cappalli</em></p></li><li><p><a href="https://mynster9361.github.io/posts/LeastPrivilegedMSGraphSetup/">Step by step guide for getting up and running with least privileged msgraph</a> &#8226; <em>Morten Mynster</em></p></li><li><p><a href="https://virtualizationreview.com/articles/2026/02/09/the-zero-trust-workshop-your-free-nitro-boosted-cybersecurity-strategy.aspx">The Zero Trust Workshop - Your Free Nitro-Boosted Cybersecurity Strategy Virtualization Review</a> &#8226; <em>Paul Schnackenburg</em></p></li><li><p><a href="https://kknowl.es/posts/untangling-microsoft-batch/">Untangling Microsoft Graph&#8217;s $batch requests in Burp</a> &#8226; <em>Katie Knowles</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://blog.admindroid.com/new-cloud-licensing-api-for-license-management-in-microsoft-graph/">New Cloud Licensing API in Microsoft Graph for License Management in Public Preview</a> &#8226; <em>Dhinesh</em></p></li></ul><h2>&#128717;&#65039; External ID - Customers</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/azure-ad-b2c-to-entra-external-id-eeid-migration-kit-attribute-mapping-c817cbed3b92?source=rss-6601e21c1210------2">Azure AD B2C to Entra External ID (EEID) Migration Kit &#8212; Attribute Mapping</a> &#8226; <em>Rory Braybrook</em></p></li></ul><div><hr></div><h2>&#9874;&#65039; Toolkit</h2><ul><li><p><a href="https://github.com/JeffBley/SamlCertRotation/blob/main/README.md">SamlCertRotation</a>: An automation tool to rotate and set as active Saml certificates in Entra ID &#8226; <em>Jeff Bley</em></p></li><li><p><a href="https://github.com/emiliensocchi/entra-ca-insight">emiliensocchi/entra-ca-insight: Discover gaps in Entra Conditional Access policies before attackers do</a> &#8226; <em>Emilien Socchi</em></p></li></ul><div><hr></div><h2>&#127897;&#65039; Podcasts</h2><ul><li><p><a href="https://www.msclouditpropodcast.com/episode421/">Episode 421: Microsoft 365 Mergers and Divestitures with Frank Lesniak</a> &#8226; <em>Frank Lesniak, Scott Hoag</em></p></li><li><p><a href="https://share.transistor.fm/s/616b64f1">Breaking into Microsoft security as a career</a> &#8226; <em>Jussi Roine &amp; Tobias Zimmergren</em></p></li></ul><div><hr></div><h2>&#128293; Maester</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/NathanMcNulty/status/2027613074069590205?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ss7J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 424w, https://substackcdn.com/image/fetch/$s_!Ss7J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 848w, https://substackcdn.com/image/fetch/$s_!Ss7J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!Ss7J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ss7J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png" width="1158" height="1018" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/babe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1018,&quot;width&quot;:1158,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:340866,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/NathanMcNulty/status/2027613074069590205?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189526732?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ss7J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 424w, https://substackcdn.com/image/fetch/$s_!Ss7J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 848w, https://substackcdn.com/image/fetch/$s_!Ss7J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!Ss7J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbabe44ad-aecd-483b-9a1d-4c42abaea07a_1158x1018.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/merill/status/2026549770047619414?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KTmN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 424w, https://substackcdn.com/image/fetch/$s_!KTmN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 848w, https://substackcdn.com/image/fetch/$s_!KTmN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 1272w, https://substackcdn.com/image/fetch/$s_!KTmN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KTmN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png" width="725" height="967.0869565217391" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1534,&quot;width&quot;:1150,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:1352591,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/merill/status/2026549770047619414?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189526732?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KTmN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 424w, https://substackcdn.com/image/fetch/$s_!KTmN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 848w, https://substackcdn.com/image/fetch/$s_!KTmN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 1272w, https://substackcdn.com/image/fetch/$s_!KTmN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39f5cace-9992-46b1-ae5b-ca29ed157f1e_1150x1534.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/merill/status/2027732957583261757?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eY23!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 424w, https://substackcdn.com/image/fetch/$s_!eY23!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 848w, https://substackcdn.com/image/fetch/$s_!eY23!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 1272w, https://substackcdn.com/image/fetch/$s_!eY23!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eY23!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png" width="1164" height="1184" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1184,&quot;width&quot;:1164,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:823057,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/merill/status/2027732957583261757?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189526732?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eY23!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 424w, https://substackcdn.com/image/fetch/$s_!eY23!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 848w, https://substackcdn.com/image/fetch/$s_!eY23!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 1272w, https://substackcdn.com/image/fetch/$s_!eY23!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e3e969-e806-4a31-8e59-5087b6ea6d07_1164x1184.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[We Gave Away Our Microsoft Entra Masterclass Labs → Full Governance, Privileged Access & Agent ID Labs Walkthrough]]></title><description><![CDATA[Entra.Chat | &#127465;&#127472; Experts Live Denmark Edition]]></description><link>https://entra.news/p/we-gave-away-our-microsoft-entra</link><guid isPermaLink="false">https://entra.news/p/we-gave-away-our-microsoft-entra</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 28 Feb 2026 12:41:05 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/189421747/289d3bec6a13d65af7970b8c8017b57d.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hey folks, I have to start with a massive shout-out to <strong><a href="https://www.linkedin.com/in/knudsenmorten/">Morten Knudsen</a> </strong>and his entire team at <a href="https://eldk26.expertslive.dk/">Experts Live Denmark</a> where I&#8217;m just returning from. </p><p>Organizing an event for over 1,200+ attendees is no small feat, and they pulled it off with incredible energy and precision. It was easily one of the most impressive community gatherings I&#8217;ve been a part of.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DTrD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DTrD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 424w, https://substackcdn.com/image/fetch/$s_!DTrD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 848w, https://substackcdn.com/image/fetch/$s_!DTrD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 1272w, https://substackcdn.com/image/fetch/$s_!DTrD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DTrD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png" width="1456" height="314" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:314,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:454203,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189421747?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DTrD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 424w, https://substackcdn.com/image/fetch/$s_!DTrD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 848w, https://substackcdn.com/image/fetch/$s_!DTrD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 1272w, https://substackcdn.com/image/fetch/$s_!DTrD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ff31be-f5eb-4ae6-a863-81f393c865f1_2780x600.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Amidst that massive crowd, I had the privilege of co-leading a deep-dive Identity Masterclass alongside four exceptional Microsoft MVPs: <strong><a href="https://www.linkedin.com/in/janvidarelven/">Jan Vidar Elven</a>, <a href="https://www.linkedin.com/in/pimjacobs89/">Pim Jacobs</a>, <a href="https://www.linkedin.com/in/thomasnaunheim/">Thomas Naunheim</a>, </strong>and<strong> <a href="https://www.linkedin.com/in/klabier/">Klaus Bierschenk</a></strong>.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/jpeg&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ca93819-2876-4804-89f4-2dcb2bb7e8a7_2048x1536.jpeg&quot;},{&quot;type&quot;:&quot;image/jpeg&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8fc0b8a-3083-496c-a198-7827bf798666_1600x1200.jpeg&quot;}],&quot;caption&quot;:&quot;Identity Masterclass @ ELDK26&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f4adc81-3721-43e3-8abf-0d130d7f9113_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>We weren&#8217;t sure what to expect, but the response was overwhelming. We had over 120 dedicated attendees who stayed with us for the full 7-hour session - diving deep into the weeds of Entra ID, governance, privileged access, Agent ID and more. Instead of theory-heavy slides, we built a practical, end-to-end governance story.</p><p>Because we believe this knowledge should be accessible, <strong>we are now giving away the labs for free</strong> so everyone can skill up, learn, and implement these patterns in their own environments.</p><p>Here&#8217;s the core of what we covered, and what you will learn in this podcast walk through of the labs and what you can try out yourself today!</p><p>Links to GitHub repo and YouTube video below.</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.action1.com/free-edition/?utm_source=paidmedia&amp;refid=Podcast_Q126_Entra" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3wBh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!3wBh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!3wBh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!3wBh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3wBh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:480763,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.action1.com/free-edition/?utm_source=paidmedia&amp;refid=Podcast_Q126_Entra&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/189421747?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!3wBh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!3wBh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!3wBh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!3wBh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0df15248-14b2-4a73-9b6b-9fcf3f3db329_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>If you&#8217;re a systems administrator, you already know &#8211; patching is painful. It&#8217;s time-consuming, risky, and one small mistake can mean downtime. So, it gets postponed. Again. And again. What if patching was just&#8230; <em>Easy?</em></p><p>Introducing <strong>Action1</strong>, a cloud-native patch management platform for Windows, macOS, Linux, and third-party apps. You&#8217;ll be up and running in five minutes. No infrastructure to maintain. No complexity.</p><p>And here&#8217;s the best part: <strong>you can use Action1 on your first 200 endpoints for free. Forever.</strong> No feature limits. No credit card. No hidden tricks. Seriously, It&#8217;s NOT a disguised free trial. Too good to be true? Too good and actually true! Check for yourself, go to: <a href="https://on.action1.com/entrachat">on.action1.com/entrachat</a></p><p>So, if you&#8217;re looking for an easy-to-use patching tool that would help you save weeks, if not months of your time, go to <a href="https://on.action1.com/entrachat">on.action1.com/entrachat</a> and sign up for&#8239;<em>&#8220;Patching That Just Works&#8221;</em>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.action1.com/free-edition/?utm_source=paidmedia&amp;refid=Podcast_Q126_Entra&quot;,&quot;text&quot;:&quot;Sign up!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.action1.com/free-edition/?utm_source=paidmedia&amp;refid=Podcast_Q126_Entra"><span>Sign up!</span></a></p></blockquote><div><hr></div><h3>1&#65039;&#8419; Inbound Provisioning: Start with a Source of Truth</h3><p>Most identity problems start with one issue:</p><p>There is no clean, authoritative identity source.</p><p>We demonstrated how to use <strong>Inbound Provisioning</strong> in Entra to:</p><ul><li><p>Accept identity payloads via Microsoft Graph</p></li><li><p>Create users in a disabled state</p></li><li><p>Capture attributes like hire date, leave date, department</p></li><li><p>Treat HR (or another system) as the lifecycle authority</p></li></ul><h4>Why this matters</h4><p>If identities are manually created:</p><ul><li><p>Joiners are inconsistent</p></li><li><p>Leavers are missed</p></li><li><p>Privileged accounts become orphaned</p></li></ul><p>Inbound provisioning allows you to:</p><ul><li><p>Standardize creation</p></li><li><p>Attach lifecycle automation immediately</p></li><li><p>Reduce manual admin overhead</p></li></ul><p><strong>Key concept:</strong><br>Provision first. Enable later. Automate everything in between.</p><div><hr></div><h3>2&#65039;&#8419; Lifecycle Workflows: Automate Joiner / Mover / Leaver</h3><p>Once a user is provisioned, lifecycle workflows take over.</p><p>We implemented:</p><ul><li><p>Pre-hire workflow</p></li><li><p>Day-one onboarding workflow</p></li><li><p>Post-onboarding actions</p></li></ul><p>Triggers included:</p><ul><li><p>Employee hire date</p></li><li><p>Creation time</p></li><li><p>Group membership</p></li><li><p>Attribute changes</p></li></ul><h4>Real-world onboarding pattern</h4><ol><li><p>Account is created disabled</p></li><li><p>Workflow enables the account at the correct time</p></li><li><p>Temporary Access Pass (TAP) is generated</p></li><li><p>TAP is sent securely</p></li><li><p>Access is assigned automatically</p></li></ol><p>This reduces:</p><ul><li><p>Manual enablement</p></li><li><p>Helpdesk load</p></li><li><p>Security gaps</p></li></ul><p><strong>Design principle:</strong><br>Automation should enforce timing &#8212; not people.</p><div><hr></div><h3>3&#65039;&#8419; Privileged Account Design: Separate the Identities</h3><p>We had a strong opinion in the session:</p><p><strong>Admin accounts should be separate and cloud-only.</strong></p><p>Why?</p><ul><li><p>Syncing privileged accounts from on-prem introduces risk</p></li><li><p>HR systems should not directly control privileged identities</p></li><li><p>Governance features work best with cloud-native identities</p></li></ul><p>We explored three creation patterns:</p><ol><li><p>Inbound provisioning for privileged accounts</p></li><li><p>Access Packages (with auto-assignment or request model)</p></li><li><p>Lifecycle workflows + custom Logic Apps</p></li></ol><p>Each has trade-offs.</p><p><strong>What matters most:</strong><br>Privileged identities must be:</p><ul><li><p>Separately authenticated</p></li><li><p>Phishing-resistant (FIDO2 or passkeys)</p></li><li><p>Independently governed</p></li><li><p>Linked for offboarding</p></li></ul><div><hr></div><h3>4&#65039;&#8419; Linking Identities for Investigation</h3><p>One challenge in Entra:</p><p>There&#8217;s no native &#8220;this person owns these 3 accounts&#8221; view.</p><p>We explored identity linking in Microsoft Defender XDR, where:</p><ul><li><p>Multiple accounts can be associated to one identity</p></li><li><p>Incident investigations become clearer</p></li><li><p>Privileged activity can be correlated with user context</p></li></ul><p>This becomes critical during:</p><ul><li><p>Compromise investigations</p></li><li><p>Insider threat analysis</p></li><li><p>Lateral movement tracking</p></li></ul><p><strong>Security takeaway:</strong><br>If you can&#8217;t correlate identities, you can&#8217;t fully investigate them.</p><div><hr></div><h3>5&#65039;&#8419; Backup &amp; Restore: The Truth About Entra</h3><p>There is no traditional backup system in Entra.</p><p>Instead, you have:</p><ul><li><p>Soft-delete (with recycle bin)</p></li><li><p>Hard-delete (irreversible)</p></li><li><p>API-based recovery</p></li><li><p>Configuration export strategies</p></li></ul><p>We discussed:</p><ul><li><p>Protecting deleted items with Protected Actions</p></li><li><p>Using Conditional Access to restrict destructive operations</p></li><li><p>Exporting configuration JSON regularly</p></li><li><p>Monitoring configuration drift</p></li></ul><p><strong>Reality:</strong><br>If you aren&#8217;t exporting your tenant configuration, recovery becomes manual and painful.</p><p>Governance is not just about creation &#8212; it&#8217;s about resilience.</p><div><hr></div><h3>6&#65039;&#8419; Protected Actions + Conditional Access</h3><p>A powerful but underused feature:</p><p>Protected Actions.</p><p>You can require Conditional Access enforcement before allowing:</p><ul><li><p>Hard deletes</p></li><li><p>Sensitive configuration changes</p></li></ul><p>Example:</p><ul><li><p>Only allow permanent deletion from a compliant device</p></li><li><p>Only allow from a trusted location</p></li><li><p>Require phishing-resistant authentication</p></li></ul><p>Even Global Admins must pass policy.</p><p><strong>Security mindset shift:</strong><br>Admin role &#8800; unlimited ability.</p><div><hr></div><h3>7&#65039;&#8419; Agent ID &amp; Blueprints: The Future of Identity for AI</h3><p>We also explored Agent ID &#8212; one of the newer capabilities in Entra.</p><p>Why not just use a service principal?</p><p>Because agents:</p><ul><li><p>Need stronger guardrails</p></li><li><p>Must support per-user instances</p></li><li><p>Require conditional access enforcement</p></li><li><p>Must be auditable at scale</p></li></ul><p>Blueprints allow:</p><ul><li><p>A parent definition of permissions</p></li><li><p>Individual agent instances per user</p></li><li><p>Centralized governance over many agents</p></li></ul><p>As AI agents scale, identity must scale securely with them.</p><p><strong>Forward-looking insight:</strong><br>Agent governance will soon be as important as user governance.</p><div><hr></div><h3>8&#65039;&#8419; Design Philosophy Behind the Lab</h3><p>The entire masterclass was built around one principle:</p><p>Identity is a lifecycle, not a login.</p><p>We covered:</p><p>Provision &#8594; Enable &#8594; Assign &#8594; Elevate &#8594; Monitor &#8594; Protect &#8594; Offboard &#8594; Recover</p><p>If any step is manual, inconsistent, or undocumented &#8212; risk increases.</p><p>The labs give you a complete pattern you can implement in your own tenant.</p><div><hr></div><h3>&#127919; What You Should Do Next</h3><ol><li><p>Watch/listen to the full podcast where we walk you through the labs.</p></li><li><p>Go try out the labs at <a href="https://github.com/IdentityMan/MasterclassELDK26">github.com/IdentityMan/MasterclassELDK26</a> in your own tenant.</p></li></ol><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-HakQyk7PTtI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;HakQyk7PTtI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/HakQyk7PTtI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About us</h3><ul><li><p>Jan Vidar Elven, Security MVP - <a href="https://www.linkedin.com/in/janvidarelven/">https://www.linkedin.com/in/janvidarelven</a></p></li><li><p>Pim Jacobs, Security MVP - <a href="https://www.linkedin.com/in/pimjacobs89/">https://www.linkedin.com/in/pimjacobs89</a></p></li><li><p>Thomas Naunheim, Security MVP - <a href="https://www.linkedin.com/in/thomasnaunheim/">https://www.linkedin.com/in/thomasnaunheim</a></p></li><li><p>Klaus Bierschenk, Security MVP - <a href="https://www.linkedin.com/in/klabier/">https://www.linkedin.com/in/klabier</a></p></li></ul><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p><a href="https://github.com/IdentityMan/MasterclassELDK26">https://github.com/IdentityMan/MasterclassELDK26</a></p></li><li><p><a href="https://discord.entra.news">https://discord.entra.news</a></p></li><li><p><a href="https://on.action1.com/entrachat">https://on.action1.com/entrachat</a></p></li></ul><div><hr></div><h2>&#128215; Chapters</h2><p>00:00 Intro </p><p>00:50 Open Sourcing the Entra Lab </p><p>03:42 Entra ID Inbound Provisioning </p><p>08:05 Lifecycle Workflows and Governance </p><p>10:57 Securing Privileged Admin Accounts </p><p>16:21 Offboarding and Linked Identities </p><p>19:51 Sponsor: ActionOne </p><p>21:02 Entra ID Backup, Restore &amp; Protected Actions </p><p>26:08 Exploring Agent ID and Blueprints </p><p>30:28 How to Access the Open Source Lab</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat</p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple</p><p>&#128250; YouTube &#8594; https://entra.chat/youtube</p><p>&#128250; Spotify &#8594; https://entra.chat/spotify</p><p>&#127911; Overcast &#8594; https://entra.chat/overcast</p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast</p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #137 → This week in Microsoft Entra]]></title><description><![CDATA[Learn about Securing Entra ID Administration: Tier 0, AI with Zero Trust Security and more!]]></description><link>https://entra.news/p/entra-news-137-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-137-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 22 Feb 2026 16:32:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/-JltxxCd0wc" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#128075; Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news in Microsoft Entra from around the globe &#127757;</p><p>This edition is coming to you from Copenhagen, Denmark &#127465;&#127472; where I&#8217;m spending the week at <a href="https://eldk26.expertslive.dk/">Experts Live Denmark</a>. I&#8217;m looking forward to catching up with the incredible Entra community here and hearing how organizations across the region are approaching identity and device modernization.</p><p>In this week&#8217;s Entra Chat, I sat down with Michael and Prem to unpack how large enterprises are moving to cloud-native devices using Entra Join and Intune and what it really takes to make that transition successful at scale.</p><div id="youtube2-XZOIpzSPRzw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;XZOIpzSPRzw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/XZOIpzSPRzw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Enjoy!</p><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/introducing-security-dashboard-for-ai-now-in-public-preview/4494637">Introducing Security Dashboard for AI (Now in Public Preview)</a> &#8226; <em>Amanda Lowe</em></p></li></ul><h2>&#128250; Watch</h2><ul><li><p><a href="https://www.youtube.com/watch?v=OnlN-2Q5QsE">AI with Zero Trust Security</a> (11 min) &#8226; <em>Michael Madrigal</em></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/UK_Daniel_Card/status/2023827894141894995?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tW0d!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 424w, https://substackcdn.com/image/fetch/$s_!tW0d!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 848w, https://substackcdn.com/image/fetch/$s_!tW0d!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 1272w, https://substackcdn.com/image/fetch/$s_!tW0d!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tW0d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png" width="1274" height="1446" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1446,&quot;width&quot;:1274,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:533183,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/UK_Daniel_Card/status/2023827894141894995?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/188753219?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tW0d!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 424w, https://substackcdn.com/image/fetch/$s_!tW0d!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 848w, https://substackcdn.com/image/fetch/$s_!tW0d!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 1272w, https://substackcdn.com/image/fetch/$s_!tW0d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9734209-1006-4ebb-b113-a19020f1fb31_1274x1446.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://trustedsec.com/blog/securing-entra-id-administration-tier-0">Securing Entra ID Administration: Tier 0</a> &#8226; <em>Sean Metcalf</em></p></li><li><p>&#129352;<a href="https://blog.mindcore.dk/2026/02/blocking-tor-botnet-anonymous-proxy-access-to-m365/">Blocking Tor/Botnet/Anonymous Proxy access to M365</a> &#8226; <em>Frank van Zandwijk</em></p></li><li><p>&#129353;&#128736;&#65039; <a href="https://www.joeyverlinden.com/conditional-access-framework-5/">Conditional Access Framework (2026.2.1)</a> &#8226; <em>Joey Verlinden</em></p></li></ul><h1>&#9728;&#65039; Learn</h1><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://hybridbrothers.com/posts/agentid-remediation/">Remediating Agent Identities for Identity Admins and SOCs | Hybrid Brothers</a> &#8226; <em>Robbe Van den Daele</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=mpxFs-h_VDE">Entra ID - Block risky Agents with Conditional Access</a> (3 min) &#8226; <em>Julian Rasmussen</em></p></li></ul><h2>&#129520; Workload ID</h2><ul><li><p><a href="https://office365itpros.com/2026/02/18/scoped-access-files-and-folders/">How to Use Scoped Graph Permissions to Access SharePoint Files</a> &#8226; <em>Tony Redmond</em></p></li><li><p><a href="https://office365itpros.com/2026/02/17/mail-send-rbac-for-applications/">Primer: Use RBAC for Applications to Control App Use of the Mail.Send Permission</a> &#8226; <em>Tony Redmond</em></p></li></ul><h2>&#9937;&#65039; ID Protection</h2><ul><li><p><a href="https://medium.com/@erik_lindeboom/migrate-your-entra-id-risk-policies-to-conditional-access-e050d588b624">Migrate your Entra ID risk policies to Conditional Access</a> &#8226; <em>Erik Lindeboom</em></p></li><li><p><a href="https://www.vansurksum.com/2026/02/20/require-risk-remediation-in-entra-conditional-access/">Require Risk Remediation in Entra Conditional Access</a> &#8226; <em>Kenneth van Surksum</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=8g_6Pmpfq_E">Microsoft Doesn&#8217;t Wait For You Anymore (Auto-Remediation)</a> (10 min) &#8226; <em>Jonathan Edwards</em></p></li></ul><h2>&#128110;&#8205;&#9794;&#65039; ID Governance</h2><ul><li><p>&#128250; <a href="https://youtu.be/jYMJR9-NJEI?si=4_2pFBNE5bNRufqb">What If Governance Wasn&#8217;t Overhead BUT Your Strongest Security Control?</a> &#8226; <em>Tee Earls, Ramiro Calderon, Jef Kazimer, Russell Smith</em></p></li><li><p><a href="https://controlaltdeletetechbits.co.uk/pim-for-groups-guide/">PIM for Groups Are You Still Assigning Roles to Users?</a> &#8226; <em>Control Alt Delete Tech Bits</em></p></li><li><p><a href="https://agderinthe.cloud/2026/02/18/stop-identifying-users-by-display-name/">Stop Identifying Users by Display Name</a> &#8226; <em>Sandra Saluti</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p><a href="https://www.thetolkienblackguy.com/post/app-registration-ownership-a-silent-path-to-persistence-in-entra-id">App Registration Ownership: A Silent Path to Persistence in Entra Id</a> &#8226; <em>Gabriel Delaney</em></p></li><li><p><a href="https://www.alitajran.com/deactivate-application-microsoft-entra-id/">How to Deactivate Application in Microsoft Entra ID</a> &#8226; <em>Ali Tajran</em></p></li><li><p><a href="https://mssec.wordpress.com/2026/02/20/tag-your-entra-id-applications-with-custom-data/">Tag your Entra ID applications with custom data</a> &#8226; <em>Tom Aafloen</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p><a href="https://www.michaelvink.com/l/passkeyprofiles/">Passkey Profiles And Auto-Enable</a> &#8226; <em>Michael Vink</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=xUlw79Sjvi0">Microsoft Automatic Passkey Rollout</a> (9 min) &#8226; <em>RioCloudSync</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=O6sOceugWU4">The Hidden Traps in Microsoft Entra Passkey Rollouts [MVP Lessons]</a> (41 min) &#8226; <em>Ru Campbell, Eric Woodruff</em></p></li></ul><h2>&#128101; User &amp; Group Management</h2><ul><li><p><a href="https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/">What admins can learn from the new Entra ID Groups Insights blade</a> &#8226; <em>Jan Bakker</em></p></li></ul><h2>&#129302; DevOps &amp; PowerShell</h2><ul><li><p><a href="https://www.systanddeploy.com/2026/02/send-mail-using-azure-automation.html">Send mail using Azure Automation, PowerShell and a managed identity</a> &#8226; <em>Damien Van Robaeys</em></p></li><li><p><a href="https://office365itpros.com/2026/02/19/dev-proxy-graph-sdk/">Using Dev Proxy with the Microsoft Graph PowerShell SDK</a> &#8226; <em>Tony Redmond</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://medium.com/@jhope188/conditional-access-mfa-for-all-but-not-the-same-135be9f6bc86">Conditional Access: MFA for All&#8230; But Not the Same</a> &#8226; <em>Jon Hope</em></p></li><li><p><a href="https://www.cswrld.com/2026/02/how-conditional-access-policies-are-evaluated-in-microsoft-entra-id/">How Conditional Access Policies Are Evaluated in Microsoft Entra ID</a> &#8226; <em>Lukas Beran</em></p></li><li><p><a href="https://specterops.io/blog/2026/02/17/stop-the-cap-making-entra-id-conditional-access-make-sense-offline/?utm_campaign=SOC%20-%20Twitter%20-%20260211%20-%20Stop%20the%20Cap&amp;utm_medium=Social&amp;utm_source=Twitter&amp;Latest_Campaign=701Uw00000fPVVe">STOP THE CAP: Making Entra ID Conditional Access Make Sense Offline</a> &#8226; <em>Lee Robinson</em></p></li><li><p><a href="https://inthecloud247.com/never-persistent-browser-session-microsoft-365-explained/">Why &#8216;Never persistent&#8217; isn&#8217;t really never persistent: understanding browser sessions in Microsoft 365 Web Apps</a> &#8226; <em>Peter Klapwijk</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p><a href="https://ourcloudnetwork.com/microsoft-introduces-entra-hybrid-join-using-entra-kerberos/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=microsoft-introduces-entra-hybrid-join-using-entra-kerberos">Microsoft Introduces Entra Hybrid Join using Entra Kerberos</a> &#8226; <em>Daniel Bradley</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p>&#128250; <a href="https://youtube.com/watch?v=rzfAutv6sB8&amp;si=92NQzCXkU1QRNSJL">Advanced Active Directory to Entra ID Lateral Movement Techniques - Black Hat USA 2025</a> (39 min) &#8226; <em>Dirk-jan Mollema</em></p></li><li><p><a href="https://www.wiz.io/blog/detecting-malicious-oauth-applications#tldr-0">Uncovering Malicious OAuth Campaigns in Entra ID</a> &#8226; <em>Shahar Dorfman, Sapir Federovsky</em></p></li><li><p><a href="https://azurehacking.com/post.html?slug=federated-identity-credential-injection-proof-of-concept">Federated Identity Credential Injection - Proof of Concept</a> &#8226; <em>Rogier Dijkman</em></p></li></ul><h2>&#9851;&#65039; Sync</h2><ul><li><p>&#128250; <a href="https://youtube.com/watch?v=yjUYWmHIO8I&amp;si=K0byyP9ZM4YsfcJd">The Hybrid Exit Strategy: Making Entra ID the Source of Authority</a> (8 min) &#8226; <em>Azure Brother</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/a-neat-entra-id-way-to-find-out-what-entity-a-guid-belongs-to-de65bff97541?source=rss-6601e21c1210------2">A neat Entra ID way to find out what entity a GUID belongs to</a> &#8226; <em>Rory Braybrook</em></p></li><li><p><a href="https://c7solutions.com/2026/02/decommissioning-old-tenants">Decommissioning Old Tenants</a> &#8226; <em>Brian Reid</em></p></li><li><p><a href="https://www.linkedin.com/posts/sewild_entraid-microsoft365-m365-activity-7426522536315600896-FcmJ?utm_source=share&amp;utm_medium=member_android&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0">Monitoring Entra ID Configuration Drift with entrasnapshot.com and UTCM APIs</a> &#8226; <em>Sebastian Wild</em></p></li></ul><h2>&#128717;&#65039; External ID - Customers</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/azure-ad-b2c-to-entra-external-id-eeid-migration-kit-evaluating-the-login-be0c316840ee?source=rss----3a246e667a75---4">Azure AD B2C to Entra External ID (EEID) Migration Kit &#8212; Evaluating the login</a> &#8226; <em>Rory Braybrook</em></p></li></ul><div><hr></div><h2>&#9874;&#65039; Toolkit</h2><ul><li><p><a href="https://github.com/magic-tool/magic">magic-tool/magic: The MAGIC tool is a wrapper around the Microsoft Graph Python SDK, designed to download incident response-relevant data from M365 environments.</a> &#8226; <em>Alexander G&#246;deke</em></p></li></ul><div><hr></div><h2>&#128104;&#127997;&#8205;&#128187; Merill&#8217;s corner</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_your-powershell-is-probably-full-of-stale-activity-7430158511004864512-sIDl?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zTzN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 424w, https://substackcdn.com/image/fetch/$s_!zTzN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 848w, https://substackcdn.com/image/fetch/$s_!zTzN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 1272w, https://substackcdn.com/image/fetch/$s_!zTzN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zTzN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png" width="1108" height="1470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1470,&quot;width&quot;:1108,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:843346,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_your-powershell-is-probably-full-of-stale-activity-7430158511004864512-sIDl?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/188753219?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zTzN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 424w, https://substackcdn.com/image/fetch/$s_!zTzN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 848w, https://substackcdn.com/image/fetch/$s_!zTzN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 1272w, https://substackcdn.com/image/fetch/$s_!zTzN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe848ec5-8c46-4644-8ca8-36a5b7dd3d19_1108x1470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div id="youtube2--JltxxCd0wc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;-JltxxCd0wc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/-JltxxCd0wc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[They migrated 40,000 devices to Entra Join in 9 months]]></title><description><![CDATA[Why Haven&#8217;t You?]]></description><link>https://entra.news/p/they-migrated-40000-devices-to-entra</link><guid isPermaLink="false">https://entra.news/p/they-migrated-40000-devices-to-entra</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 21 Feb 2026 09:47:07 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/188573179/39ce4ec4318e5c6cfb71ca3a967372c9.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>What does it take to migrate 40,000 devices to a cloud-native environment in a massive, complex enterprise? For most IT leaders, the prospect of moving away from 20 years of legacy infrastructure is enough to cause a sleepless night.</p><p>In our latest episode of Entra Chat, we sat down with enterprise veterans Michael Brunker and Prem Kothandapani to deconstruct their recent, massive rollout. They successfully converted nearly 40,000 devices from on-premises Active Directory to <strong>Entra Joined</strong> in just nine to ten months&#8212;all with a lean team of 10&#8211;15 people.</p><p>Here are the high-stakes lessons they learned from the trenches of modern management.</p><h3>The &#8220;Nuclear Option&#8221;: Cleaning Up 20 Years of GPO Debt</h3><p>One of the most controversial decisions the team made was what they called the &#8220;nuclear option&#8221; regarding Group Policy Objects (GPOs). Instead of porting over decades of legacy policies that no one fully understood, they chose to start from scratch.</p><p>By building a new security baseline from the ground up in Intune, they ensured the new environment was clean, modern, and free from the &#8220;stale&#8221; configurations that often plague legacy estates.</p><h3>Killing the &#8220;VPN Tax&#8221;</h3><p>For the end user, the primary driver for this migration was a radically improved experience. In a cloud-native world, the dependency on legacy VPN technology disappears.</p><ul><li><p><strong>Work from Anywhere:</strong> Users can sign on and get access without the friction of starting a VPN or worrying about office cabling.</p></li><li><p><strong>Security at the Edge:</strong> Moving to Entra ID shrinks the attack surface by removing devices as a direct entry point to your core on-prem Active Directory.</p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="http://on.action1.com/entrachat" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PylG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!PylG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!PylG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!PylG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PylG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:480763,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://on.action1.com/entrachat&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/188573179?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!PylG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!PylG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!PylG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!PylG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36717d1c-059f-4c71-8776-a5a18f600e88_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>If you&#8217;re a systems administrator, you already know &#8211; patching is painful. It&#8217;s time-consuming, risky, and one small mistake can mean downtime. So, it gets postponed. Again. And again. What if patching was just&#8230; <em>Easy?</em></p><p>Introducing <strong>Action1</strong>, a cloud-native patch management platform for Windows, macOS, Linux, and third-party apps. You&#8217;ll be up and running in five minutes. No infrastructure to maintain. No complexity.</p><p>And here&#8217;s the best part: <strong>you can use Action1 on your first 200 endpoints for free. Forever.</strong> No feature limits. No credit card. No hidden tricks. Seriously, It&#8217;s NOT a disguised free trial. Too good to be true? Too good and actually true! Check for yourself, go to: <a href="https://on.action1.com/entrachat">on.action1.com/entrachat</a></p><p>So, if you&#8217;re looking for an easy-to-use patching tool that would help you save weeks, if not months of your time, go to <a href="https://on.action1.com/entrachat">on.action1.com/entrachat</a> and sign up for&#8239;<em>&#8220;Patching That Just Works&#8221;</em>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.action1.com/free-edition/?utm_source=paidmedia&amp;refid=Podcast_Q126_Entra&quot;,&quot;text&quot;:&quot;Sign up now!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.action1.com/free-edition/?utm_source=paidmedia&amp;refid=Podcast_Q126_Entra"><span>Sign up now!</span></a></p></blockquote><div><hr></div><h3>The &#8220;Gnarly&#8221; Problems: What Breaks First?</h3><p>Success wasn&#8217;t just about the big picture; it was about mastering the &#8220;fundamental basic building blocks&#8221;. Michael and Prem highlighted several technical hurdles that can derail a migration if not handled early:</p><ul><li><p><strong>The Proxy Trap:</strong> Many organizations fail to update their proxy server allow-lists with the specific Microsoft URLs required for cloud authentication.</p></li><li><p><strong>App Authentication:</strong> Moving from Kerberos-based device auth to OAuth and modern cloud flows requires rigorous testing across different &#8220;personas,&#8221; such as front line workers versus corporate office users.</p></li></ul><h3>The Secret to Scaling: Small Teams, Big Strategy</h3><p>Perhaps the most surprising takeaway was that a project of this scale didn&#8217;t require an army. By focusing on a &#8220;small team&#8221; of highly skilled engineers and dedicated communications experts, they maintained momentum and avoided &#8220;stop-start&#8221; migration fatigue.</p><p><strong>Want to hear the full technical breakdown, including how they handled zero-downtime requirements for front line workers?</strong></p><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-XZOIpzSPRzw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;XZOIpzSPRzw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/XZOIpzSPRzw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About Michael Brunker</h3><p>Michael Brunker has approaching 40 years in the IT industry and has operated as an enterprise architect across major organizations like BP, Woodside, and Telstra. </p><p>LinkedIn - <a href="https://www.linkedin.com/in/michaelbrunker/">https://www.linkedin.com/in/michaelbrunker/</a></p><h3>About Prem Kothandapani</h3><p>Prem Kothandapani is an EndPoint Architect with over 14 years of experience in endpoint computing and major migrations, having worked at NBN, Australian Unity, and Telstra.</p><p>LinkedIn - <a href="https://www.linkedin.com/in/premnath-kothandapani-41744153/">https://www.linkedin.com/in/premnath-kothandapani-41744153/</a></p><div><hr></div><h3>&#128215; Chapters</h3><p>00:00 Cloud-Native Device Management </p><p>02:58 The True Cost of Legacy Infrastructure </p><p>07:47 Moving to Modern Management </p><p>11:13 The Blueprint for a 40,000 Device Migration </p><p>20:07 Handling Complex App Dependencies </p><p>28:07 Crafting a Seamless User Migration Experience </p><p>33:28 Automating with Graph API and Autopilot </p><p>43:09 Avoiding the Co-Management Trap </p><p>55:01 The New Starter Experience </p><p>57:24 Migration Velocity and Lessons Learned</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat - https://entra.chat </p><p>&#127911; Apple Podcast &#8594; https://entra.chat/apple </p><p>&#128250; YouTube &#8594; https://entra.chat/youtube </p><p>&#128250; Spotify &#8594; https://entra.chat/spotify </p><p>&#127911; Overcast &#8594; https://entra.chat/overcast </p><p>&#127911; Pocketcast &#8594; https://entra.chat/pocketcast </p><p>&#127911; Others &#8594; https://entra.chat/rss</p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a> </p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a> </p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a> </p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a> </p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a> </p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a> </p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a> </p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item><item><title><![CDATA[Entra 🆔 News #136 → This week in Microsoft Entra]]></title><description><![CDATA[Alex Simons has left the building &#129761;]]></description><link>https://entra.news/p/entra-news-136-this-week-in-microsoft</link><guid isPermaLink="false">https://entra.news/p/entra-news-136-this-week-in-microsoft</guid><dc:creator><![CDATA[Joshua Fernando]]></dc:creator><pubDate>Sun, 15 Feb 2026 08:56:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ps4g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>&#128075;</em> Hi, Merill and Joshua here with this week&#8217;s roundup of the latest news on Microsoft Entra from around the globe &#127757;.</p><p><strong>The End of an Era: Alex Simons is Retiring</strong> </p><p>The biggest news this week is that <strong><a href="https://www.linkedin.com/in/alexsimons/">Alex Simons</a></strong>, who has led the Entra product team for years, announced his retirement from Microsoft.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/alexsimons_howdy-folks-sharing-the-news-today-that-activity-7427441284459466752-ZUsY?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8ITv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 424w, https://substackcdn.com/image/fetch/$s_!8ITv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 848w, https://substackcdn.com/image/fetch/$s_!8ITv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 1272w, https://substackcdn.com/image/fetch/$s_!8ITv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8ITv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png" width="1096" height="1548" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1548,&quot;width&quot;:1096,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1511121,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/alexsimons_howdy-folks-sharing-the-news-today-that-activity-7427441284459466752-ZUsY?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187929851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8ITv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 424w, https://substackcdn.com/image/fetch/$s_!8ITv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 848w, https://substackcdn.com/image/fetch/$s_!8ITv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 1272w, https://substackcdn.com/image/fetch/$s_!8ITv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1736ae70-c74f-4211-b9a6-3a055bae8d92_1096x1548.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s hard to overstate Alex&#8217;s impact. While many have contributed to the org over the years, if there is one person who truly shaped and molded Entra into what it is today, it&#8217;s him. From fostering the unique culture of the Identity team to serving as the primary face of the brand, Alex is one of those rare &#8220;unicorns&#8221; who did it all. His passion for the product and the customer never wavered. Even in his final month, I saw him personally reviewing docs and proposals for the standards specs we are contributing toward Agentic AI.</p><p>I&#8217;ve even heard that my own team, the <em>Microsoft Identity Customer Experience Engineering (CxE) org</em>, was something he personally championed to create.</p><p>To give you an idea of his &#8220;customer-obsessed&#8221; mindset: back in 2017, long before I joined Microsoft, I started following Alex on Twitter. Out of the blue, he sent me a DM offering to help if I ever ran into trouble with Azure AD. That wasn&#8217;t an anomaly; it was the culture he built. While we&#8217;re sad to see him go, please join us in wishing him incredible fun and success in his &#8220;second career&#8221; as a volleyball coach! &#127952;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aMAO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aMAO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 424w, https://substackcdn.com/image/fetch/$s_!aMAO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 848w, https://substackcdn.com/image/fetch/$s_!aMAO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 1272w, https://substackcdn.com/image/fetch/$s_!aMAO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aMAO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png" width="1308" height="524" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:524,&quot;width&quot;:1308,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:118565,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187929851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aMAO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 424w, https://substackcdn.com/image/fetch/$s_!aMAO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 848w, https://substackcdn.com/image/fetch/$s_!aMAO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 1272w, https://substackcdn.com/image/fetch/$s_!aMAO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c5728c-6e6f-4830-b7d8-e8859d183c1d_1308x524.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>A Piece of Entra Lore</strong> </p><p>Fun fact: Did you know there is a tweet memorializing the actual birth of Azure Active Directory (now Entra ID) by Alex himself? I can&#8217;t believe it&#8217;s now February 2026, <em>13 years later</em>, and that historic post only has one like!</p><p>Let&#8217;s change that. <a href="https://x.com/Alex_A_Simons/status/321289610040864768?s=20">Go smash the like button on it</a> and become a part of Entra ID history!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/Alex_A_Simons/status/321289610040864768?s=20" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!epKb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 424w, https://substackcdn.com/image/fetch/$s_!epKb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 848w, https://substackcdn.com/image/fetch/$s_!epKb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 1272w, https://substackcdn.com/image/fetch/$s_!epKb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!epKb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png" width="1296" height="538" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:538,&quot;width&quot;:1296,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98366,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/Alex_A_Simons/status/321289610040864768?s=20&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187929851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!epKb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 424w, https://substackcdn.com/image/fetch/$s_!epKb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 848w, https://substackcdn.com/image/fetch/$s_!epKb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 1272w, https://substackcdn.com/image/fetch/$s_!epKb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30fa8b33-9441-4b53-ac1a-7aa4691040ec_1296x538.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>This Week on Entra Chat</strong> </p><p>We tried something a little different this week. <strong>Ewelina Paczkowska</strong> and <strong>Daniel Bradley</strong> joined me to count down the top five Entra stories of the month, including some critical changes admins need to prep for right now.</p><p>I&#8217;m planning to do this monthly wrap-up moving forward. Watch the episode and let me know what you think!</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;1deaeaa0-c701-436d-9462-0232729b2f58&quot;,&quot;caption&quot;:&quot;March 2026 is shaping up to be one of the most important months for Microsoft Entra ID administrators in recent memory.&quot;,&quot;cta&quot;:&quot;Listen now&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Microsoft Is Auto-Enabling Passkeys in March 2026&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:13653245,&quot;name&quot;:&quot;Merill Fernando&quot;,&quot;bio&quot;:&quot;Product Manager &#8226; Microsoft Entra | Creator of cmd.ms &#8226; idPowerToys.merill.net &#8226; Graph X-Ray &#8226; &#127462;&#127482; &#8226; &#127473;&#127472; &#8226; Posts are my own&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a42318-1b15-490d-a0bf-a68f9ea04f79_400x400.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100}],&quot;post_date&quot;:&quot;2026-02-14T09:00:12.375Z&quot;,&quot;cover_image&quot;:&quot;https://substack-video.s3.amazonaws.com/video_upload/post/187926435/2e2f2a3d-0667-42b3-9eac-e9181ca3c867/transcoded-1771138150.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://entra.news/p/microsoft-is-auto-enabling-passkeys&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:187926435,&quot;type&quot;:&quot;podcast&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1804560,&quot;publication_name&quot;:&quot;Entra.News - Your weekly dose of Microsoft Entra&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4mCy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b3b3378-703b-4f6a-ab4d-10470336b06f_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Enjoy!</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ptSX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!ptSX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!ptSX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!ptSX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ptSX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png" width="619" height="309.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:619,&quot;bytes&quot;:286752,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187929851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ptSX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!ptSX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!ptSX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!ptSX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469cd873-9d6b-4a83-a5a2-1283ecd1a4e6_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Hybrid User Onboarding: One CmdLet &#8211; Two Parameters</strong></p><p>Fact: Hybrid user onboarding across AD, Entra ID, and Exchange Online is time-consuming and error-prone.</p><p><strong>EasyEntra&#8217;s new</strong> Invoke-EECreateHybridUserFromTemplate <strong>CmdLet changes that:</strong></p><p>&#128640; One command creates a fully provisioned hybrid user in ~30 secs.<br>&#128640; Just two parameters: DisplayName and TemplateName.<br>&#128640; Templates are defined from existing users with an intuitive UI in seconds.<br>&#128640; Schedule onboarding in advance or bulk-create users with a one-liner.<br>&#128640; EasyEntra is free for tenants with fewer than 25 licensed users.</p><p>No more context switching between consoles. No more provisioning drift between new hires.<br>Just fast, consistent, automated onboarding from a single command.</p><p><em><strong>&#8220;This product has been a miracle for our Helpdesk.&#8221;</strong></em><br>Manager of IT Customer Support, Junior Achievement, United States</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding&quot;,&quot;text&quot;:&quot;Learn More&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://easyentra.com/?utm_source=entranews&amp;utm_medium=paid&amp;utm_campaign=easyentra&amp;utm_content=onboarding"><span>Learn More</span></a></p></blockquote><div><hr></div><h1>&#9889;&#65039; Microsoft</h1><h2>&#128293; Public Preview</h2><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-bring-your-own-device">Learn about bring your own device (BYOD) with the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access</a> &#8226; <em>Microsoft Learn</em></p></li></ul><h2>&#128250; Watch</h2><ul><li><p><a href="https://www.youtube.com/watch?v=N-B-kD28P2I">Microsoft Entra Agent ID explained</a> (10 min) &#8226; <em>Leandro Iwase</em></p></li></ul><div><hr></div><h1>From the community&#8230;</h1><h2>&#128640; Most popular posts from last week</h2><ul><li><p>&#129351;<a href="https://blog.hametbenoit.info/2026/02/03/entra-you-can-now-disable-registered-applications-preview/">Entra &#8211; You can now disable registered applications (preview)</a> &#8226; <em>Benoit Hamet</em></p></li><li><p>&#129352;<a href="https://blog.admindroid.com/microsoft-disabling-ntlm-by-default-in-windows/">Microsoft Disables NTLM by Default in Upcoming Windows Releases</a> &#8226; <em>Lokesh</em></p></li><li><p>&#129353;<a href="https://blog.icewolf.ch/archive/2026/02/07/entra-connect-sync-2-6-1-released/">Entra Connect Sync 2.6.1 released - Icewolf Blog</a> &#8226; <em>Andres Bohren</em></p></li></ul><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.enowsoftware.com/webinar/your-application-security-roadmap-entra-2026?utm_campaign=35456420-WBN-AppGov-Feb.25.2026&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=2.15.2026" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SO-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!SO-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!SO-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!SO-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SO-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:367768,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.enowsoftware.com/webinar/your-application-security-roadmap-entra-2026?utm_campaign=35456420-WBN-AppGov-Feb.25.2026&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=2.15.2026&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187929851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SO-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!SO-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!SO-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!SO-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9776a7c9-8036-4fd2-b33c-29751717cc2b_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Live Entra Webinar: Application Security Roadmap</strong></p><p>[ Feb 25, 2026 | 1 PM ET ] Most organizations know they have application risk in Entra ID. Far fewer know where to start, what to prioritize, or how to operationalize governance without slowing the business. In this expert-led session we&#8217;ll lay out a practical, phased roadmap for securing applications in Entra ID. You&#8217;ll learn:</p><ul><li><p>How to inventory and classify applications by risk, access, and business impact</p></li><li><p>How to apply least privilege and lifecycle ownership to apps at scale</p></li><li><p>A realistic roadmap for reducing app attack surface without breaking integrations</p></li></ul><p>This webinar is designed for teams who are past awareness and ready for execution. Join us to build a roadmap toward continuous control in Entra. All registrants will receive the recording.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.enowsoftware.com/webinar/your-application-security-roadmap-entra-2026?utm_campaign=35456420-WBN-AppGov-Feb.25.2026&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=2.15.2026&quot;,&quot;text&quot;:&quot;Register Now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.enowsoftware.com/webinar/your-application-security-roadmap-entra-2026?utm_campaign=35456420-WBN-AppGov-Feb.25.2026&amp;utm_source=EntraNews&amp;utm_medium=Email&amp;utm_content=2.15.2026"><span>Register Now</span></a></p></blockquote><div><hr></div><h1>&#9728;&#65039; Learn</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/moe-kinani-7b530159_msftadvocate-entra-security-activity-7427178704910315520-rG8L?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zjTR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 424w, https://substackcdn.com/image/fetch/$s_!zjTR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 848w, https://substackcdn.com/image/fetch/$s_!zjTR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!zjTR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zjTR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png" width="609" height="606.5881188118811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1006,&quot;width&quot;:1010,&quot;resizeWidth&quot;:609,&quot;bytes&quot;:417960,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/moe-kinani-7b530159_msftadvocate-entra-security-activity-7427178704910315520-rG8L?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187929851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zjTR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 424w, https://substackcdn.com/image/fetch/$s_!zjTR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 848w, https://substackcdn.com/image/fetch/$s_!zjTR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!zjTR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a955098-e9e6-4b30-b148-3c431dded100_1010x1006.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128105;&#8205;&#9992;&#65039; AI &amp; Copilot</h2><ul><li><p><a href="https://www.linkedin.com/pulse/ai-agent-architecture-security-deep-dive-tagrerout-mvp-and-rd--pfwye?utm_source=share&amp;utm_medium=member_android&amp;utm_campaign=share_via">AI Agent Architecture &amp; Security: Deep Dive</a> &#8226; <em>Seyfallah Tagrerout</em></p></li></ul><h2>&#9937;&#65039; ID Protection</h2><ul><li><p>&#129513; <a href="https://mssec.wordpress.com/2026/02/12/manually-set-an-entra-user-as-risky-via-microsoft-graph/">Manually set an Entra user as Risky via Microsoft Graph</a> &#8226; <em>Tom Aafloen</em></p></li></ul><h2>&#128110;&#8205;&#9794;&#65039; ID Governance</h2><ul><li><p><a href="https://www.cswrld.com/2026/02/how-to-use-access-packages-to-manage-group-memberships/">How to use access packages to manage group memberships</a> &#8226; <em>Lukas Beran</em></p></li><li><p>&#128736;&#65039; <a href="https://docs.kaidojarvemets.com/products/pim-assessment-free-tool">Free Entra ID PIM Assessment Tool</a> &#8226; <em>Kaido J&#228;rvemets</em></p></li><li><p>&#128736;&#65039; <a href="https://addons.mozilla.org/en-US/firefox/addon/pimfox-for-entra/">PIMfox for Entra &#8211; Get this Extension for &#129418; Firefox</a> &#8226; <em>Michel de Rooij</em></p></li></ul><h2>&#127760; Private Access &amp; Internet Access (GSA)</h2><ul><li><p><a href="https://directaccess.richardhicks.com/2026/02/10/entra-private-access-and-bring-your-own-device-byod/">Entra Private Access and Bring Your Own Device (BYOD)</a> &#8226; <em>Richard M. Hicks</em></p></li><li><p><a href="https://www.cloudcoffee.ch/microsoft-azure/microsoft-entra-private-access-byod-entra-registered/">Microsoft Entra Private Access BYOD: Access Internal Resources with Entra Registered Devices</a> &#8226; <em>Oliver M&#252;ller</em></p></li><li><p><a href="https://zerototrust.tech/prompt-injection-is-the-new-phishing-heres-how-gsa-can-help/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=prompt-injection-is-the-new-phishing-heres-how-gsa-can-help">Prompt Injection is the New Phishing&#8230;. Here&#8217;s how GSA Can Help</a> &#8226; <em>Dustin Gullett</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=oTDymmwsZg8">Episode 35 - &#8220;Entra Global Secure Access - Internet Access&#8221;, a secure identity-driven Web Gateway.</a> (28 min) &#8226; <em>Matthew Levy, Dinant Paardenkooper</em></p></li></ul><h2>&#128230; Apps</h2><ul><li><p>&#129513; <a href="https://office365itpros.com/2026/02/11/deactivate-application-entra/">Deactivating an Entra ID Application</a> &#8226; <em>Tony Redmond</em></p></li><li><p>&#129513; <a href="https://ourcloudnetwork.com/how-to-find-and-remove-application-owners-from-disabled-applications/?utm_source=feedly&amp;utm_medium=rss&amp;utm_campaign=how-to-find-and-remove-application-owners-from-disabled-applications">How to Find and Remove Application Owners from Disabled Applications</a> &#8226; <em>Daniel Bradley</em></p></li><li><p><a href="https://devblogs.microsoft.com/aspire/securing-dotnet-aspire-apps-with-microsoft-entra-id/">Securing Aspire Apps with Microsoft Entra ID</a> &#8226; <em>Jean-Marc Prieur</em></p></li></ul><h2>&#129734; Authentication</h2><ul><li><p>&#129513; <a href="https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/">How to find unattested device-bound passkeys in Entra ID</a> &#8226; <em>Jan Bakker</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=dd9sXrHbcmc">Authentication Contexts in Microsoft 365 &#8211; Explained Simply</a> (10 min) &#8226; <em>Jonathan Edwards</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=jDTtv9JwLIM">Everything Azure Admins Know About Azure Auth Just Changed</a> (7 min) &#8226; <em>Azure Academy</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=j_g-Dq8hIEI">Passkeys in Entra: Passwords Are Dead &#8212; Here&#8217;s How to Enable Them Today</a> (9 min) &#8226; <em>Peter Rising</em></p></li></ul><h2>&#129302; DevOps &amp; PowerShell</h2><ul><li><p><a href="https://www.thelazyadministrator.com/2026/02/09/using-dev-proxy-to-identify-excessive-microsoft-graph-permissions-in-your-powershell-scripts/">Using Dev Proxy to Identify Excessive Microsoft Graph Permissions in Your PowerShell Scripts</a> &#8226; <em>Brad Wyatt</em></p></li></ul><h2>&#128678; Conditional Access</h2><ul><li><p><a href="https://blog.mindcore.dk/2026/02/blocking-tor-botnet-anonymous-proxy-access-to-m365/">Blocking Tor/Botnet/Anonymous Proxy access to M365</a> &#8226; <em>Frank van Zandwijk</em></p></li><li><p>&#128736;&#65039; <a href="https://www.joeyverlinden.com/conditional-access-framework-5/">Conditional Access Framework (2026.2.1)</a> &#8226; <em>Joey Verlinden</em></p></li><li><p>&#128250; <a href="https://www.youtube.com/watch?v=ANZLw1jkX8s">Conditional Access Documenter</a> &#8226; <em>Brian Veldman</em></p></li></ul><h2>&#128421;&#65039; Devices</h2><ul><li><p><a href="https://jamesvincent.co.uk/2026/02/06/how-to-enable-platform-sso-psso-for-apple-macos-using-intune/">How to enable Platform SSO (PSSO) for Apple macOS using Intune</a> &#8226; <em>James Vincent</em></p></li></ul><h2>&#127961;&#65039; External ID - Guests &amp; Multi-Tenant Organizations</h2><ul><li><p><a href="https://duo-infernale.ch/b2b-guest-stop-losing-external-users-to-blank-planner/">B2B Guest: Stop Losing External Users To Blank Planner</a> &#8226; <em>Flavio Meyer</em></p></li><li><p><a href="https://kempeneers.eu/2026/02/08/using-gmail-and-google-workspace-as-external-identities-in-windows-365/">Using Google Workspace and Gmail as External Identities in Windows 365</a> &#8226; <em>Dieter Kempeneers</em></p></li></ul><h2>&#129399; Security</h2><ul><li><p><a href="https://trustedsec.com/blog/securing-entra-id-administration-tier-0">Securing Entra ID Administration: Tier 0</a> &#8226; <em>Sean Metcalf</em></p></li><li><p><a href="https://www.edtechirl.com/p/phishing-persistence-10-steps-to">Phishing Persistence: 10 Steps to Securing a Compromised M365 Account</a> &#8226; <em>Andy Lombardo</em></p></li><li><p><a href="https://www.linkedin.com/pulse/i-wrote-4-part-guide-building-on-prem-pki-powershell-michael-waterman-jmh4e?utm_source=share&amp;utm_medium=member_android&amp;utm_campaign=share_via">I wrote a 4-part guide on building an on-prem PKI with PowerShell</a> &#8226; <em>Michael Waterman</em></p></li><li><p>&#128736;&#65039; <a href="https://cloudbymoe.com/f/zero-trust-assessment-tool">Zero Trust Assessment Tool</a> &#8226; <em>Moe Kinani</em></p></li><li><p>&#128736;&#65039; <a href="https://github.com/anak0ndah/OAuthBandit">OAuthBandit: OAuthBandit is a post-exploitation tool that automates the extraction, validation, and exploitation of Microsoft OAuth tokens from compromised Windows endpoints</a> &#8226; <em>Hamza Kondah</em></p></li><li><p>&#128736;&#65039; <a href="https://azurehacking.com/post.html?slug=blackcat-module-getting-started">Getting Started with the BlackCat - A PowerShell Module that consolidates the techniques a red team or security auditor needs into a single, well-documented module</a> &#8226; <em>Rogier Dijkman</em></p></li></ul><h2>&#128210; Tenant Configuration</h2><ul><li><p><a href="https://petervanderwoude.nl/post/being-careful-with-the-ability-to-configure-the-preferred-entra-tenant-domain-name/">Being careful with the ability to configure the preferred Entra tenant domain name</a> &#8226; <em>Peter van der Woude</em></p></li><li><p>&#129513; <a href="https://cloudtips.nl/unified-tenant-configuration-management-utcm-apis-in-microsoft-graph-%EF%B8%8F-82209852b9ba">Unified Tenant Configuration Management (UTCM) APIs in Microsoft Graph</a> &#8226; <em>Brian Veldman</em></p></li><li><p>&#128736;&#65039; <a href="https://www.linkedin.com/pulse/solving-tenant-configuration-drift-utcm-introducing-ugur-koc-nqike?utm_source=share&amp;utm_medium=member_android&amp;utm_campaign=share_via">Solving tenant configuration drift with UTCM - Introducing TenantBaseline</a> &#8226; <em>Ugur Koc</em></p></li></ul><h2>&#128717;&#65039; External ID - Customers</h2><ul><li><p><a href="https://medium.com/the-new-control-plane/using-the-ropc-flow-with-azure-ad-b2c-df50b28de91b?source=rss-6601e21c1210------2">Using the ROPC flow with Azure AD B2C</a> &#8226; <em>Rory Braybrook</em></p></li></ul><div><hr></div><h2>&#128293; Maester</h2><ul><li><p><a href="https://maester.dev/blog/maester-2-0">Introducing Maester 2.0 &#128640;</a> &#8226; <em>Maester Core Team</em></p></li><li><p><a href="https://office365itpros.com/2026/02/10/maester-and-utcm/">Maester and UTCM Are Complementary Tools for Microsoft 365 Tenant Management</a> &#8226; <em>Tony Redmond</em></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/posts/merill_maester-activity-7427505129832132608-3nRf?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ps4g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 424w, https://substackcdn.com/image/fetch/$s_!Ps4g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 848w, https://substackcdn.com/image/fetch/$s_!Ps4g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!Ps4g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ps4g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png" width="583" height="872.8406072106262" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1578,&quot;width&quot;:1054,&quot;resizeWidth&quot;:583,&quot;bytes&quot;:642710,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/posts/merill_maester-activity-7427505129832132608-3nRf?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAE2HdgBr18Dks1IiZ7TlCEOKbW_5legOj0&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187929851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ps4g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 424w, https://substackcdn.com/image/fetch/$s_!Ps4g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 848w, https://substackcdn.com/image/fetch/$s_!Ps4g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!Ps4g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c74b04b-63fd-4315-9d0c-c147f7aedb45_1054x1578.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><ul><li><p>Want to get featured on Entra.News? &#8594; <a href="https://tally.so/r/3Nb1l0">Submit your content</a> &#128526;</p></li><li><p>Want us to say nice things about your company? <a href="https://www.passionfroot.me/jozra">Sponsor entra.news</a> &#129321;</p></li><li><p>Love the newsletter? <a href="https://love.entra.news/">Tell us</a> &#128154;&#10084;&#65039;&#128156;</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://entra.news/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Entra.News - Your weekly dose of Microsoft Entra is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#129667; Acknowledgement of Country</h2><p><em>Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.</em></p>]]></content:encoded></item><item><title><![CDATA[Microsoft Is Auto-Enabling Passkeys in March 2026]]></title><description><![CDATA[Here&#8217;s What You Need to Know]]></description><link>https://entra.news/p/microsoft-is-auto-enabling-passkeys</link><guid isPermaLink="false">https://entra.news/p/microsoft-is-auto-enabling-passkeys</guid><dc:creator><![CDATA[Merill Fernando]]></dc:creator><pubDate>Sat, 14 Feb 2026 09:00:12 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/187926435/4e37f35cd39989d8cbed05c826e60c8c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>March 2026 is shaping up to be one of the most important months for Microsoft Entra ID administrators in recent memory.</p><p>Microsoft is automatically enabling passkey profiles in Entra ID, and if you don&#8217;t configure them yourself, your tenant will be migrated with default settings.</p><p>In this episode of Entra Chat, I sat down with Microsoft Security MVPs <strong>Daniel Bradley</strong> and <strong>Ewelina Paskowska</strong> to break down what this really means for Microsoft 365 administrators.</p><p>But passkeys aren&#8217;t the only story this month.</p><div><hr></div><h2>1&#65039;&#8419; Passkey Profiles Are Becoming the Default</h2><p>Starting March 2026:</p><ul><li><p>Passkey profiles will be auto-enabled</p></li><li><p>Tenants that haven&#8217;t configured profiles will be migrated</p></li><li><p>Registration campaigns will shift from Authenticator-first to passkey-first</p></li></ul><p>This is a major shift toward phishing-resistant authentication.</p><p>You&#8217;ll now be able to:</p><ul><li><p>Separate hardware-backed vs synced passkeys</p></li><li><p>Apply granular group-based controls</p></li><li><p>Enforce stronger authentication for privileged users</p></li></ul><div><hr></div><h2>2&#65039;&#8419; Source of Authority Conversion Is Finally GA</h2><p>For years, admins used messy delete-and-restore hacks to convert synced users to cloud-only.</p><p>Now it&#8217;s officially supported.</p><p>You can convert individual users from on-premises authority to cloud-managed &#8212; without breaking hybrid entirely.</p><p>Why this matters:</p><ul><li><p>Easier M&amp;A transitions</p></li><li><p>Full access to Entra ID Governance features</p></li><li><p>Cleaner lifecycle management</p></li><li><p>Reduced dependency on legacy infrastructure</p></li></ul><p>For hybrid environments moving toward cloud-first identity, this is huge.</p><div><hr></div><p><strong>Sponsored by:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="http://on.action1.com/entrachat" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0GUd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!0GUd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!0GUd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!0GUd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0GUd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png" width="628" height="314" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:628,&quot;bytes&quot;:480763,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://on.action1.com/entrachat&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://entra.news/i/187926435?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!0GUd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!0GUd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!0GUd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!0GUd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f407b1d-7ae4-4c1f-8323-9a1013651f79_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you are a&#8239;<em>systems administrator managing endpoints every day</em>, you&#8217;ve probably postponed patching at least once &#8212; not because you forgot&#8230; But because you didn&#8217;t feel like gambling with uptime. Meanwhile, the backlog grows, vulnerabilities pile up, and patching stays stuck in manual mode.</p><p><strong>Action1</strong>&#8239; fixes that.</p><p><strong>Action1 </strong>is a cloud-native patch management platform for Windows, macOS, Linux, and third-party apps &#8212; all from one place, no VPN needed. Curious how easy it is to start?&#8239;<em>You can use it on your first 200 endpoints, for free, forever</em>, with no functional limits. It&#8217;s not a disguised free trial. No credit card required, no hidden limits, no tricks.</p><p>All you have to do is visit <a href="https://on.action1.com/entrachat">on.action1.com/entrachat</a> and get started today.</p><p>So, if you&#8217;re looking to automate patching&#8239;<em>at scale&#8239;</em>and get weeks&#8212; even months&#8212;of your time back, go to <a href="https://on.action1.com/entrachat">on.action1.com/entrachat</a> and sign up for&#8239;<em>patching&#8212;that&#8212;just&#8212;works</em>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://on.action1.com/entrachat&quot;,&quot;text&quot;:&quot;Visit Action1 and get started today&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://on.action1.com/entrachat"><span>Visit Action1 and get started today</span></a></p><div><hr></div><h2>3&#65039;&#8419; App Registration Deactivation (A Quietly Powerful Feature)</h2><p>Microsoft added the ability to deactivate app registrations.</p><p>Instead of deleting an app (and losing configuration), you can now:</p><ul><li><p>Immediately stop token issuance</p></li><li><p>Preserve metadata and permissions</p></li><li><p>Investigate safely</p></li><li><p>Re-enable without rebuilding</p></li></ul><p>For incident response scenarios &#8212; especially in multi-tenant or MSP environments &#8212; this is a big step forward.</p><div><hr></div><h2>4&#65039;&#8419; Conditional Access Behavior Changes</h2><p>There&#8217;s also a change impacting tenants with Conditional Access policies targeting &#8220;All resources&#8221; but excluding certain apps.</p><p>Previously, certain minimal-scope apps could bypass enforcement under specific conditions.</p><p>That loophole is closing.</p><p>Admins should:</p><ul><li><p>Review message center notifications</p></li><li><p>Audit legacy apps</p></li><li><p>Validate MFA handling before rollout</p></li></ul><p>As always with identity changes: being proactive is critical.</p><div><hr></div><h2>5&#65039;&#8419; Sync Security Hardening (Hard Match Protection)</h2><p>Microsoft is adding additional validation to protect against malicious hard matching scenarios in hybrid environments.</p><p>This reduces the risk of identity takeover via manipulated on-prem objects.</p><p>It&#8217;s automatic &#8212; but important to understand if you manage hybrid identity or MSP transitions.</p><div><hr></div><p>Watch the full episode for the deep technical breakdown and real-world implications.</p><div class="pullquote"><p>Subscribe with your favorite podcast player or watch on YouTube &#128071;</p><div id="youtube2-AkcdhhvlDBE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;AkcdhhvlDBE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/AkcdhhvlDBE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div></div><h3>About Daniel Bradley</h3><p>Daniel is a Senior Solution Architect for CDW and Microsoft MVP in Identity &amp; Graph API. He is a avid writer who enjoys investigating new features and building practical tools to share with the community through his blog. He also is one of the moderators for the r/entra subreddit.</p><ul><li><p><strong>Website:</strong> <a href="https://ourcloudnetwork.com">https://ourcloudnetwork.com</a></p></li><li><p><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/danielbradley2/">https://www.linkedin.com/in/danielbradley2</a></p></li><li><p><strong>X:</strong> <a href="https://x.com/DanielatOCN">https://x.com/DanielatOCN</a></p></li></ul><h3>About Ewelina Paczkowska</h3><p>Ewelina is a Solution Architect at Theatscape and a Microsoft Security MVP. She is a content creator and speaker who enjoys breaking down complex solutions into clear, practical guidance. Ewelina is also an organiser of the Microsoft 365 Security &amp; Compliance user group and the creator behind Welka&#8217;s World, where she shares insights and real-world knowledge around Microsoft security and compliance.</p><ul><li><p><strong>Website:</strong> <a href="https://welkasworld.com">https://welkasworld.com</a></p></li><li><p><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/ewelinapaczkowska">https://www.linkedin.com/in/ewelinapaczkowska</a></p></li><li><p><strong>X:</strong> <a href="https://x.com/WelkasWorld">https://x.com/WelkasWorld</a></p></li></ul><div><hr></div><h3>&#128279; Related Links</h3><ul><li><p>MC1221452 - Microsoft Entra ID: Auto-enabling passkey profiles - <a href="https://mc.merill.net/message/MC1221452">https://mc.merill.net/message/MC1221452</a></p></li><li><p>Ability to convert Source of Authority of synced on-prem AD users to cloud users is now available - <a href="https://learn.microsoft.com/en-us/entra/identity/hybrid/user-source-of-authority-overview">https://learn.microsoft.com/en-us/entra/identity/hybrid/user-source-of-authority-overview</a></p></li><li><p>Service Principal creation audit logs for alerting &amp; monitoring - <a href="https://learn.microsoft.com/en-us/entra/identity/monitoring-health/understand-service-principal-creation-with-new-audit-log-properties">https://learn.microsoft.com/en-us/entra/identity/monitoring-health/understand-service-principal-creation-with-new-audit-log-properties</a></p></li><li><p>Deactivate an app registration - <a href="https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/deactivate-app-registration">https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/deactivate-app-registration</a></p></li><li><p>MC1223829 - Upcoming Conditional Access change: Improved enforcement for policies with resource exclusions - <a href="https://mc.merill.net/message/MC1223829">https://mc.merill.net/message/MC1223829</a></p></li><li><p>Microsoft Entra Connect security hardening to prevent user account takeover - <a href="https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---microsoft-entra-connect-security-hardening-to-prevent-user-account-takeover">https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---microsoft-entra-connect-security-hardening-to-prevent-user-account-takeover</a></p></li></ul><div><hr></div><h3>&#128215; Chapters</h3><p>06:16 Converting Source of Authority to Cloud </p><p>15:37 Auto-Enabling Passkey Profiles </p><p>24:33 Deactivating App Registrations </p><p>31:56 Conditional Access for Excluded Apps </p><p>38:48 Sync Jacking Protection </p><p>41:45 Unified Tenant Configuration Management </p><p>46:31 Service Principal Creation Logs</p><div><hr></div><h3>Podcast Apps</h3><p>&#127897;&#65039; Entra.Chat &#8594; https://entra.chat</p><p>&#127911; Apple Podcast &#8594; <a href="https://entra.chat/apple">https://entra.chat/apple</a></p><p>&#128250; YouTube &#8594; <a href="https://entra.chat/youtube">https://entra.chat/youtube</a></p><p>&#128250; Spotify &#8594; <a href="https://entra.chat/spotify">https://entra.chat/spotify</a></p><p>&#127911; Overcast &#8594; <a href="https://entra.chat/overcast">https://entra.chat/overcast</a></p><p>&#127911; Pocketcast &#8594; <a href="https://entra.chat/pocketcast">https://entra.chat/pocketcast</a></p><p>&#127911; Others &#8594; <a href="https://entra.chat/rss">https://entra.chat/rss</a></p><div><hr></div><h3>Merill&#8217;s socials</h3><p>&#128250; YouTube &#8594; <a href="https://youtube.com/@merillx">youtube.com/@merillx</a></p><p>&#128084; LinkedIn &#8594; <a href="https://linkedin.com/in/merill">linkedin.com/in/merill</a></p><p>&#128036; Twitter &#8594; <a href="https://twitter.com/merill">twitter.com/merill</a></p><p>&#128378; TikTok &#8594; <a href="https://www.tiktok.com/@merillf">tiktok.com/@merillf</a></p><p>&#129419; Bluesky &#8594; <a href="https://bsky.app/profile/merill.net">bsky.app/profile/merill.net</a></p><p>&#128024; Mastodon &#8594; <a href="https://infosec.exchange/@merill">infosec.exchange/@merill</a></p><p>&#129525; Threads &#8594; <a href="https://www.threads.net/@merillf">threads.net/@merillf</a></p><p>&#129302; GitHub &#8594; <a href="https://github.com/merill">github.com/merill</a></p>]]></content:encoded></item></channel></rss>