▲ 2 r/entra

Question&Rant: What is up with registration campaign not showing and forced passkey registration CAP not forcing?

To be fair, there has to be something else, a detail, or a deeper understanding that I am missing, and getting frustrated at this point is blinding the obvious.

Passkeys are enabled for all users, pretty basic config, nothing special. Registration campaign is targeting user group for registration of passkey. Nothing has happened for 9 days now. Targeted users are not prompted anywhere. Even forcing sign-out some, they are not prompted on the sign-in.

CAP was created which requires phish-resistant authentication method to access all apps, and this CAP is targeting a different subset of pilot users. This has not forced a single user in last 6 days to register for passkey. Granted, nearly all signin and use WHfB.

Now the weird part. 9 and 6 days ago I created two new test accounts and went through usual onboarding without passkeys. They are my control accounts that were targeted with registration campaign or CAP. Again, to be clear, these accounts went through onboarding to match the state of the pilot users. These test accounts were not setup with passkeys from the beginning.

So, these test accounts, one targeted with registration campaign was prompted for passkey on day 3 or 4, and the other targeted with CAP prompted for passkey setup within 30 minutes of being assigned the cap.

Please educate me why or what is wrong here. I cannot get consistent experience between existing accounts and new test accounts.

At this point we are considering instructing users to install MS Authenticator, sign-in with work or school account, and setup passkey in this flow using their existing MFA. This flow has worked for 5 users flawlessly, even if they already had authenticator with OTP, mfa number matching, or other. This flow always resulted in full setup of account with passkey, prompt to enable MS Authenticator in settings, even if account was already setup in past.

reddit.com
u/jM2me — 21 hours ago

Is blocking list of urls/domains with Defender Indicators a viable solution until GSA/Zscaler implementation?

There is an urgent need to block roughly 9000 domains/urls from all of the company workstations. Quite a lot, but from initial analysis only ~10% actually detected in environment over last 6 months. The request from business higher up still stands, block all provided domains/url and provide evidence of the block list containing them.

In past there were concerns about using large number of Defender Indicators to block, is that still the case? Any caveats or warnings that other want to share before we proceed?

A proper GSA/Zscaler solution is 6-9 months out, but the block must happen yesterday...

reddit.com
u/jM2me — 6 days ago
▲ 2 r/entra

Is Passkey attestation still broken or not working?

With Passkey attestation enabled I am running into an issue where Passkey is created on the device but not registered in Entra. Disabling attestation and retrying after few minutes creates the passkey and does register in Entra.

During preview phase there was a tech community post with recommendation to disable attestation while in Preview, but we are in GA now, no? So should attestation work in GA, or still needs to be disabled? The policy is requiring/allowing Microsoft Authenticator only as passkey provider.

Edit: I guess it would help to include the message I am getting with Attestation enabled. It is:

"Passkey not registered (tringles with exclamations icons) This might be due to a timeout, a canceled request or a private browsing window."

CA policies:

  1. security registration - require TAP/FIDO/WHfB;
  2. all apps - require phish resistant MFA (excluding 6 specific resources)
  3. 6 specific resources - require phish resistant MFA or TAP
reddit.com
u/jM2me — 22 days ago
▲ 1 r/AZURE

Which resource do I connect content understanding to for production/live?

I built a prototype that processes blobs on storage account by sending it to content understanding classifier and if it is a certain type of document it is ran through analyzer for data extraction. Works as expected and currently connected to my test/dev ai foundry resource.

If this is were to be deployed into prod/live, does it still need to connect to ai foundry only? I find references to ai cognitive service and openai services, but those are not selectable from CU portal when building analyzers.

reddit.com
u/jM2me — 28 days ago

Any insights into when copilot studio built agents will read markdown files from sharepoint as knowledge source?

Like title says, agent built in copilot studio with sharepoint site knowledge is not reading markdown files for reference.

Were any hints or concrete timelines dropped by MS when it will be supported?

reddit.com
u/jM2me — 1 month ago

Why does adding myself to frontier program all of a sudden makes Copilot much better and produce output similar to that of Claude?

I have to be honest, I had issues using copilot at work for technical questions and requests. They were only okay while Claude would produce exactly what I needed in one shot. This is strictly for powershell scripts, python scripts, analyzing code and refactoring. Just snippets of code not a whole project.

Then few of us at our org devices to try joining Frontier program which game us the new copilot interface, Work IQ, and Coworker which we have not fully embraced yet but I know how good Claud coworker can be.

Anyway, after joining Frontier program, chat responses from Copilot are so much better and are very close if not identical to what I would expect to see from Claude. I genuinely stopped using Claude because with Work IQ copilot also had additional work context that Claude would not. Recalling information from chats or emails in scripts or even pointing out that I already had a draft version of script I was trying to recreate.

Seriously, this is truly at a point where i can not see going back to previous version nor to using standalone Claude.

reddit.com
u/jM2me — 1 month ago

What changed in Edge that makes it load web pages right away it starts?

For about a year I had an odd and slightly annoying issues with Edge browser. When I open edge (cold start, not running in background) it would take 10-15 seconds before pages or tabs would load. Both, previous tabs, or new tabs would spin for 10-15 seconds in "loading" state but not load until that time passed. As of recently, I think we version 150 upgrade, it is back to loading everything right on the startup like normal.

No change to extensions nor user settings (self-managed with registry).

Did something specific change that others have caught on or perhaps share my past experience and also noticed it resolved?

reddit.com
u/jM2me — 2 months ago

Recommendations for a WiFi/Zigbee connected heat pump thermostat with no smart features?

Is there a good WiFi or Zigbee connected thermostat that has all of the safety features that a normal thermostat would have (especially the heat pump) but none of the smart or internet connected things? I have ecobee smart thermostat premium, and despite it being dumbed down now it still does not provide simple controls to home assistant which is what I would like to drive the actual HVAC system.

I used Claude to mockup esphome configuration for esp32 with relays acting as a thermostat, accounting for all the safety features thermostats provide for heat pump systems. In theory and in simulations this works very well, but I am hesitant to try this on a live system mid-summer. If there was a dumb but connected thermostat instead then I would take that any time.

I did try dumbing down ecobee and it works, but only okay at best. There is lack of feedback, and the current status of thermostat is sometimes lagging or not updating back to home assistant in time. I attempted this with another ecobee just to rule out thermostat itself and it wasn't it.

reddit.com
u/jM2me — 2 months ago

Newly created and published agent is not showing up in teams and M365 channels

I can’t figure out whether there are some other org controls in place that are preventing the newly published agent not show up in teams nor M365.

On my personal tenant, where setting are obviously configured less strictly, I am able to see the agent published after few minutes.

So now in work tenant admin, the agent shows up but it does not indicate any blocks. The shared with section does show users, but neither they nor I see it.

Now as I post this, I recall something about teams apps being locked down and they need to be allowed, so maybe this is where I need to look tomorrow. However, doesn’t explain why it’s not in M365

reddit.com
u/jM2me — 2 months ago
▲ 2 r/solar

Need advice and feedback on whether solar is worth considering on this roof layout and house orientation because I am split

I am split on whether it is worth putting solar panels on our roof due to how many roof planes we have and the orientation of the house. Some days I look at it and also want to proceed, and on others hesitate. From the picture, yellow line is 18' for refence, red - attic vents, yellow sewer vents, orange is kitchen exhaust, pink is dryer exhaust, and blue is bathrooms exhaust. The picture is already oriented with North at the top. If I am not mistaken none of the SE and SW facing sides would have issues with trees blocking panels.

It kind of seems that some panels can be fit on SE facing side, more on main roof and few on garage. Then if sewer and dryer vents can be relocated then few more panels on garage SW side and a bit more on SW side. Garage+Home SE can be tied into one array and Garage+Home SW can be tied into another.

I was told that relocating vents and exhausts is going to be a nightmare, but if it wasn't I was thinking that NE could also get some panels for that summer sun over the top.

Located in SWFlorida. Ideal location for solar, not ideal roof planes and house orientation in my opinion.

u/jM2me — 2 months ago

How am I accidentally taking on multiple DHCP leases on single residential connection?

I have frontier fios fiber directly into my home and from the ONT box I get a single ethernet cable which I would normally plug into a router.

My setup is a bit special since this ethernet connection is connected to managed switch and the link is TRUNKED on VLAN10 to OPNsense VM. This has been the working for over 5 years, no issues with internet or services. Only one OPNsense gets connected to this VLAN10 for the WAN connection.

Very recently I mistakenly connected another test VM to VLAN10 and it picked up a new public leased from frontier. OPNsense lease still operates and this test VM has been operational for almost a week. Neither dropped connection nor had issues with lease.

This is surely a mistake and will be corrected, right? It was never an option from Frontier, and if I wanted to do this intentionally in a past the second lease would never come through.

reddit.com
u/jM2me — 2 months ago

Would there be any legal/compliance applications for running AVD Hybrid on personal physical hardware?

AVD Hybrid has been great in my personal testing and a small POC at work to a point where it is going to be our solution if we maintain apps on on-premises servers.

Personally I have been trying few other odd things, like setting it up on Physical server and with Win 11 multi-session which is possible but can’t be legally licensed. (Yet?)

Another thing I tried is setting up personal computers in personal AVD Hybrid pool, both are Entra joined and Intune managed Win11 Pro machines. This works pretty amazing as well.

A secure access to my personal computers from anywhere where I can access AVD.

Obviously it is not being used in a business setting and my tenant is for personal use but properly licensed and all (Business Premium).

Do you reckon there would be serious or any legal or compliance implications to continue using AVD Hybrid from physical personal computers? I would think and hope no.

reddit.com
u/jM2me — 2 months ago
▲ 1 r/Intune

M365 Apps for enterprise deployed via ODT xml are no longer updating consistently during autopilot. Is this new or expected now?

I deployed M365 apps for enterprise using ODT and XML and it has not been touched for over 2 years, working with no issues during all deployment scenarios. However, recently I noticed that whiteglove preprovision deployments are not always installing latest or most updated version of M365 apps for enterprise.

Out of roughly 10 devices, 3 have older versions. They do eventually update within 1-3 days after getting to user, but from security side there are now vulnerabilities generated for "outdated office" for those 3 devices.

XML does have Updates set to Enabled and update channel is Current.

reddit.com
u/jM2me — 3 months ago
▲ 46 r/entra

Microsoft, please, make PIM great!

As a user I have a list of roles available to me via PIM activation. Roles have permissions.

When I attempt to complete an action that requires a permission that I do not have active, how about instead of showing me access denied just show all the roles that are available to me for activation with least privileged first.

Instead of graying out an action button or link because I lack a required permission, put a shield or other indicator and when clicked on give a prompt, popup, or any other option to activate an available role.

Maybe stating the obvious and/or preaching to the choir, but is this not a simple workflow that will benefit all the admins and improve PIM experience?

reddit.com
u/jM2me — 3 months ago

For how long should air handler run after a cooling cycle?

Located in SW Florida, so hot humid air outside, always trying to get the humidity down indoors.

Our air handler does not have a motherboard but is rather simply wired with some relays. (Read it as "cheap goodman unit" from 2020). Simple heat pump with 8kw aux heat strips.

A year ago "A-coil" was replaced as it had a small leak and txv (if that is what it is called) was replaced along with it. The HVAC tech noted that we have a timed relay for blower fan, which makes it run for 5 more minutes after the cycle. This re-introduces humidity back into air.

He explained that normally 1) it is good for dryer regions to get the last bit of cooling out of the coil, and 2) for emergency/aux heat strips this is a safety feature. Both makes sense.

He recommended that we rewire air handler so that blower fan does not run past the cooling cycle and still runs for 5 more minutes after the aux heat strips cycle for safety. Alternatively, he could install a "smarter" board which would do the same thing plus a bit more.

Neither was done because he didn't have either of parts on hand and we honestly never reconnected on this. With hot a humid season just around the corner, I want to revisit this.

What are your thoughts? Do you agree with the tech? Is 5 minutes enough to reintroduce humidity back? Any opinions on just rewiring and keeping the air handler sort of "dumb" or go with a board option?

We already have whole home dehumidifier, ducted separately, but still called for by the ecobee thermostat when needed.

reddit.com
u/jM2me — 3 months ago