Entra ๐ News #84 โ This week in Microsoft Entra
Learn about device code phishing and how you can block it ๐ฃ, common risk-based Conditional Access policy misconfigurations ๐ค, and more! ๐
Hi everyone,
Merill and Joshua here with this week's Microsoft Entra news roundup.
Important Security Alert: Microsoft Threat Intelligence has issued a warning about cyberattacks from the Storm-2372 group. They are targeting governments, NGOs, and various industries globally. Check out the Microsoft post for full details.
We've also re-shared a post from last year explaining device code flow and how to use conditional access policies to block them.
Enjoy!
Sponsored by:
EasyEntra: Consolidated Hybrid Microsoft 365 Management
Managing Microsoft 365 and hybrid AD doesnโt have to be slow and complex. EasyEntra streamlines user administration into a single, intuitive console and enables first-level IT support to resolve tickets quickly, consistently, and without escalating to senior IT. With EasyEntra, you can save time, reduce complexity, and improve service delivery.
โ Unified Hybrid Management โ Seamlessly manage Entra ID and on-prem AD in one console.
โ Fast & Responsive UI โ Perform user admin tasks at the speed of your thought.
โ User Lifecycle Automation โ Streamline user onboarding and offboarding with consistent automation.
โ Freemium Version โ Manage any number of small tenants (< 25 licensed users) side-by-side completely free.
โ No Infrastructure Changes โ Install and configure in less than one minute.
โก๏ธ Microsoft
๐ Read
Storm-2372 conducts device code phishing campaign โข Microsoft Threat Intelligence
๐บ Watch
Microsoft Entra Health Monitoring Introduction (18 min) โข Sarah Baranowski, Shreyes Nama Shankar
425 Show | Onboarding to Intune macOS and Protecting with Entra Solutions (62 min) โข Neil Johnson, Iris Yuning Ye
๐ Upcoming Events
New webinar series: How to secure access for your employees with the Microsoft Entra Suite โข Amelie Darchicourt
From the communityโฆ
๐ Most popular posts from last week
Entra configurations you MUST do! โข Julian Rasmussen
Automating Azure PIM Role Elevation with PowerShell โข รystein
Windows Hello for Business: Enhanced Sign-in Security โข Nicklas Ahlberg
โ๏ธ Learn
โ๏ธ ID Protection
๐ฎโโ๏ธ ID Governance
Now You See It, Now You Donโt: Secure Access with Entra ID Governance โข Dustin Gullett
๐ Private Access & Internet Access (GSA)
Secure Remote Desktop Services with Microsoft Entra Application Proxy โข Liam Robinson
Self-Service for Web Content Filtering Exceptions in Global Secure Access โข Christian Frohn
๐ฆ Apps
Microsoft Graph Bicep โ Part 1 โข Michele Blum
Practical Graph: Controlling App Access to SharePoint Online Sites โข Tony Redmond
Introduction to Entra ID multi-tenant applications โข Twan van Beers
Bicep for graph resources โข Maik van der Gaag
Securing API to API calls in Azure with Entra and API Management โข Dan Rios
๐ Authentication
Passkey Implementations: How to Do It Right โข Dr. Emin Huseynov
๐ฅ User & Group Management
Build your own user onboarding automation โ Entra ID user account creation โข Peter Klapwijk
How to Use Bulk User Operations in Entra Admin Center โข Tony Redmond
New bulk edit features for users in Microsoft Entra ID โข Daniel Bradley
Use Protected Actions to Stop Attackers Hard-Deleting Entra ID Accounts โข Tony Redmond
๐ค DevOps & PowerShell
Microsoft Graph PowerShell SDK Needs to Fix Its Password Problem โข Tony Redmond
Manage Guest Users in Microsoft 365 with PowerShell โข Ali Tajran
A Mini Dive into the Microsoft Entra PowerShell Module: An Intune Administratorโs Perspective โข Ben Whitemore
๐ฆ Conditional Access
The Main Reason You Shouldn't Exclude Break Glass By Group in Conditional Access โข Jay Kerai
Conditional Access Framework (2025.2.3) โข Joey Verlinden
Always On VPN and Entra Conditional Access โข Richard M. Hicks
Protected Actions: Adding Extra Guards to Your Entra ID Gate! โข Per-Torben Sรธrensen
Protected Actions โ Protect Hard Deletions of Objects โข Rudy Mens
๐ฅ๏ธ Devices
Configuring Windows LAPS โ Niklas Blog โข Niklas Rast
๐ฅท Security
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication โข Charlie Gardner, Steven Adair, Tom Lancaster
Microsoft Graph Activity to Basic Logs โข Debac Manikandan
Monitor Elevated Access in Microsoft Entra with Sentinel โข Charbel Nemnom
How to Set Up an Emergency Access App in Entra ID for Admin Recovery โข Sreejith Reghunathan Pillai
โป๏ธ Sync
From the field: You receive error โAADSTS9090561 The endpoint only accepts POST requests. Received a GET requestโ when signing in โข Sander Berkouwer
โ๏ธ Toolkit
zh54321/GraphPreConsentExplorer - A comprehensive list of usable Entra ID first-party clients with pre-consented Microsoft Graph scopes, in a simple YAML-file explorable with a simple HTML GUI โข zh54321
migrate-per-user-mfa-to-ca.ps1 - Script to migrate from Per user MFA to Conditional Access โข Nathan McNulty
๐๏ธ Podcasts
TrustedSec: Security Noise Podcast - Authentication in 2025 โข Geoff Walton, Skyler Tuter, Edwin David, Justin Bollinger
Identity at the Center Podcast: Mastering Group Management with Microsoft's David Johnson (51 min) โข Jim McDonald, Jeff Steadman, David Johnson
Cloudfirst Podcast: Using managed identities and federated credentials to eliminate secrets โข Marius Sandbu
๐บ Watch
FIDO Alliance: Stop Counting Factors... Start Describing Authentication Events (32 min) โข Pamela Dingle, Dean Saxe
Black Hat: Hook, Line and Sinker: Phishing Windows Hello for Business (25 min) โข Yehuda Smirnov
Azure Super Mode with Entra ID User Access Administrator and NEW Logging Ability (18 min) โข John Savill
Microsoft Entra ID 5 New Killer Features that you Have to Know! (17 min) โข Andy Malone
Entra ID - Must-Do configuration changes (9 min) โข Julian Rasmussen MVP
'Edit Users' option in Entra ID (Public Preview) (3 min) โข Rio Hindle
Difference between delegated and application permissions in Microsoft Entra ID (16 min) โข Lukas Beran
How to Retain Sign in logs in Entra beyond 30 days (20 min) โข Nick Ross
๐ฅ Maester
๐จ๐ฝโ๐ป Merillโs corner
๐ช Acknowledgement of Country
Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. I pay my respect to them and their cultures and to elders both past and present.