All topics and tags

Microsoft Entra ID

42 articles tagged Microsoft Entra ID.

  1. A Microsoft 365 tenant security baseline you can apply in a day

    Harden a new or existing Microsoft 365 tenant in one working day: emergency access, admin roles, MFA and legacy auth, app consent, email protection, external forwarding, audit logging and Secure Score.

  2. AADSTS50076, 50079 and 50158: fix Microsoft Entra MFA sign-in errors

    What AADSTS50076, AADSTS50079 and AADSTS50158 mean, how to find the policy that demanded MFA in the Entra sign-in logs, and how to fix each one for users, scripts and federated domains.

  3. AADSTS53003 blocked by Conditional Access: find the policy and fix it

    Troubleshoot AADSTS53003 in Microsoft Entra ID: trace the correlation ID to the sign-in log, identify the blocking Conditional Access policy, and fix the user, device or policy without weakening security.

  4. AVD pooled host pool with FSLogix profiles on Azure Files (Entra Kerberos)

    Build an Azure Virtual Desktop pooled host pool with Microsoft Entra joined session hosts and FSLogix profile containers stored on Azure Files, using Microsoft Entra Kerberos instead of domain controllers.

  5. Azure mandatory MFA phase 2: fix CLI, PowerShell and Terraform sign-ins

    Phase 2 of Azure mandatory MFA blocks create, update and delete calls from user accounts without MFA. Find the scripts that break and move them to managed identities, service principals or OIDC.

  6. Azure OpenAI Keyless Access: Managed Identity, Entra ID and Private Endpoints

    Remove API keys from Azure OpenAI: call it with a managed identity and Entra ID RBAC, disable local auth, and reach it only through a private endpoint with public network access turned off.

    AI engineering12 min read
  7. Azure SQL Entra Authentication: Entra-Only Mode and Managed Identity

    Replace SQL logins on Azure SQL Database and Managed Instance with Microsoft Entra ID: set the Entra admin, create users for groups and managed identities, then enable Entra-only authentication.

    Databases & HA11 min read
  8. Block legacy authentication in Microsoft 365 without breaking printers

    Find every device and app that still signs in with legacy authentication, move printers and scanners to a supported sending method, then block legacy auth with Conditional Access.

  9. Break-glass accounts in Entra ID: a lockout-proof Conditional Access setup

    Create two emergency access accounts in Microsoft Entra ID, protect them with FIDO2 passkeys, exclude them safely from Conditional Access, and alert on every sign-in with Azure Monitor.

  10. Build RAG Over SharePoint Documents Without Breaking Permissions

    Ground an internal AI assistant on SharePoint files so each user only gets answers from documents they can open, using the Copilot Retrieval API or Azure AI Search with ACL ingestion.

    AI engineering12 min read
  11. Compromised Microsoft 365 account runbook: contain, investigate, recover

    A step-by-step runbook for a confirmed Microsoft 365 account takeover: disable and revoke, remove attacker persistence, scope the breach with audit logs and restore the user safely.

  12. Conditional Access All resources exclusions: test the 2026 change

    Since June 2026, Conditional Access enforces All resources policies with exclusions on sign-ins that request only baseline scopes. Find the affected apps, test them and choose an enforcement setting.

  13. Conditional Access token protection: stop stolen token replay

    Bind Microsoft 365 sign-in sessions to the device with Conditional Access token protection: supported apps, report-only rollout, sign-in log status codes, KQL and exclusions.

  14. Configure Entra certificate-based authentication with smart cards and PKI

    Set up native Microsoft Entra certificate-based authentication: upload your PKI, publish reachable CRLs, bind certificates to users and enforce CBA as phishing-resistant MFA.

  15. Copilot Studio SharePoint Knowledge: Set It Up and Fix No-Answer Errors

    Add SharePoint sites and lists as Copilot Studio knowledge, choose the right authentication, and fix agents that answer "I'm not sure how to help with that."

    AI engineering12 min read
  16. Dataverse Application Users: Server-to-Server Auth with an Entra App

    Register a Microsoft Entra app, create a Dataverse application user with a least-privilege security role, get a client credentials token and call the Web API, then fix common errors.

    Architecture10 min read
  17. Deploy passkeys in Entra ID: Authenticator, Windows Hello and FIDO2 keys

    Roll out phishing-resistant passwordless sign-in in Microsoft Entra ID with passkey profiles, passkeys in Microsoft Authenticator, FIDO2 security keys, Windows Hello for Business and authentication strengths.

  18. Entra cross-tenant access settings: trust partner MFA, devices and apps

    Configure Microsoft Entra cross-tenant access settings for a partner: scope inbound and outbound B2B access, trust their MFA and device claims, and enforce Conditional Access for partner users.

  19. Entra ID dynamic groups: rule syntax and examples that actually work

    Write Microsoft Entra ID dynamic membership rules for users and devices: syntax, operators, tested examples for HR attributes, licences and Autopilot, validation, processing status and fixes for common rule errors.

  20. Entra SMS and voice MFA retirement: move users to passkeys before 2027

    Microsoft-provided SMS and voice MFA in Entra ID retires on 1 February 2027 (1 July 2027 for Global Administrators and external users). Find affected users, move them to passkeys and clean up policies.

  21. Entra SSPR with password writeback: setup and the registered-methods change

    Set up Microsoft Entra self-service password reset with writeback to Active Directory through Entra Connect or Cloud Sync, and get users ready for SSPR accepting only registered methods.

  22. Fix Entra Connect AttributeValueMustBeUnique and duplicate proxy addresses

    Find which object already holds the duplicated proxyAddresses or userPrincipalName value, remove it from the right side, and confirm the next Entra Connect sync exports cleanly.

  23. Fix Microsoft Entra hybrid join failures with dsregcmd /status

    Read dsregcmd /status output to find out why a domain-joined Windows device won't hybrid join: error phase, client error codes, SCP, proxy, sync and devices stuck in Pending.

  24. Fix Microsoft Graph 429 throttling with Retry-After, batching and delta

    Stop 429 Too Many Requests errors from Microsoft Graph: honour Retry-After, tune the SDK retry handler, batch correctly, cut request cost and replace polling with delta queries.

    Architecture13 min read
  25. Hybrid Configuration Wizard errors and fixes with Exchange Server SE

    Fix the Hybrid Configuration Wizard failures you hit with Exchange Server SE: TLS, HCW8001, HCW8057, HCW8078, HCW8064 and the dedicated Exchange hybrid app that rich coexistence now needs.

    Microsoft 36511 min read
  26. Microsoft 365 Copilot License Assignment: Prerequisites and Rollout

    Check base licenses, update channels, mailboxes, OneDrive, Teams and network access, then assign Copilot licenses with group-based licensing or Microsoft Graph PowerShell.

    AI engineering11 min read
  27. Migrate EWS apps to Microsoft Graph before Exchange Online turns off EWS

    Move mail, calendar and contact integrations from EWS to Microsoft Graph: map operations, replace impersonation with scoped permissions, convert stored IDs and plan for gaps.

    Architecture13 min read
  28. Migrate from AD FS to Entra cloud authentication with staged rollout

    Move federated Microsoft Entra domains from AD FS to password hash sync or pass-through authentication, pilot with staged rollout, cut over each domain and retire AD FS.

  29. Multi-tenant SaaS on Entra ID: admin consent, tenant allowlist, app lock

    Register a multi-tenant SaaS app in Microsoft Entra ID, onboard customer tenants through admin consent, enforce a tenant allowlist in token validation and lock service principal credentials with app instance property lock.

    Architecture12 min read
  30. PIM for Groups and access reviews: govern privileged group membership

    Put privileged Microsoft Entra groups under PIM for Groups so membership is eligible and time-bound, protect activation, and recertify members with access reviews.

  31. Plan a Microsoft 365 MFA rollout with Conditional Access and Authenticator

    A phased plan to require MFA for every Microsoft 365 user: pick security defaults or Conditional Access, set authentication methods, drive registration, pilot in report-only mode, then enforce.

  32. Replace Conditional Access custom controls with external MFA in Entra ID

    Conditional Access custom controls are frozen and retire in 2027. Move Duo or another third-party MFA provider to external MFA, switch policies to the MFA grant and remove the custom control.

  33. Report expiring Entra app secrets and certificates with Graph PowerShell

    Build a Microsoft Graph PowerShell report of every client secret and certificate on Entra app registrations and service principals, find which ones are in use, and rotate them before they expire.

  34. Require compliant devices for Microsoft 365 with Conditional Access

    Build Intune compliance policies for Windows and iOS, mark unassigned devices noncompliant, then require a compliant device in Conditional Access without locking users out.

  35. Require phishing-resistant MFA for admins with authentication strengths

    Use Conditional Access authentication strengths to require passkeys (FIDO2), Windows Hello for Business or certificate-based authentication for Microsoft Entra admin roles, including PIM activation.

  36. Restore deleted Conditional Access policies with Entra Backup and Recovery

    Recover deleted or misconfigured Conditional Access policies, named locations and other Entra objects using soft delete, difference reports and targeted recovery jobs in Microsoft Entra Backup and Recovery.

  37. Secure APIs in Azure API Management with validate-jwt and Rate Limits

    Protect backend APIs behind Azure API Management by validating Microsoft Entra access tokens with validate-jwt and throttling each client application with rate-limit-by-key and quota-by-key.

    Architecture13 min read
  38. Set Up Business Central OAuth Service-to-Service Access with Microsoft Entra

    Register a Microsoft Entra app, grant API.ReadWrite.All, add it on the Microsoft Entra Applications page and call Business Central APIs with client credentials, then fix 401 errors.

    Architecture10 min read
  39. Set up Entra Privileged Identity Management for just-in-time admin roles

    Replace standing admin access with eligible role assignments in Microsoft Entra PIM: inventory current admins, configure role settings, assign, activate, and monitor Entra and Azure roles.

  40. Stop illicit consent grants with user consent settings and admin approval

    Restrict which apps users can consent to in Microsoft Entra ID, route everything else through the admin consent workflow, and find and revoke risky OAuth grants that already exist.

  41. Temporary Access Pass in Entra ID: passwordless onboarding and recovery

    Use a Temporary Access Pass in Microsoft Entra ID to onboard new users straight to passkeys and Windows Hello, and to recover users who lost their MFA method, without ever handing out a password.

  42. Troubleshoot Conditional Access with the What If tool and sign-in logs

    Find out why a Conditional Access policy did or did not apply to a sign-in by reading the sign-in log, simulating it with What If, and querying results at scale.