r/entra

▲ 7 r/entra

FIDO2 not working with Security Defaults?

Hi everyone, so I recently noticed in some newer tenants that I can not sign in with Global Admin accounts that only have FIDO2 registered as a method. We are always using CA on most of our customers - but on some smaller customer tenants (5-10 accounts) we have just turned on security defaults instead. Now last week I noticed that my 4 GA-accounts - that only have FIDO2 registered - could not sign in - I was VERY lucky to have my backdoor through GDAP with privileged role admin... So I guess I'll have to revert to legacy/per user MFA on those tenants?

reddit.com
u/hullan_hollow — 2 days ago
▲ 22 r/entra

Locked out after enabling “Phishing-resistant MFA” CA for all admins — Authenticator passkey + WHfB rejected

I think I completely locked myself out of my M365 tenant.

I enabled a Conditional Access policy requiring “Phishing-resistant MFA” for all admin accounts.

I DO have:

  • a passkey created in Microsoft Authenticator
  • Windows Hello for Business configured

But both are rejected during sign-in.

I only get a generic error:
“Something went wrong”
with no additional details at all.

I expected Authenticator passkeys and WHfB to satisfy the phishing-resistant MFA requirement, but apparently not in my setup.

Has anyone already hit this exact issue?
Is there a known limitation/bug with Authenticator passkeys + Authentication Strength policies?

Right now I have no active admin session left open.

""This might be due to a timeout, a canceded request or a private browsing windows""

EDIT : It’s working again.

I finally managed to access the tenant by signing into a PC with my admin account and configuring Windows Hello. The PIN failed, but fingerprint authentication finally worked and let me back in.

I disabled the CA immediately and created a proper break-glass account. I fully admit I was careless, but honestly Microsoft also shares some responsibility here because this whole flow is clearly not mature enough yet.

reddit.com
u/Gloomy_Pie_7369 — 3 days ago
▲ 5 r/entra

What counts as a method for SSPR?

Hello everyone, I am having some trouble setting up PIM and one thing I am running into is SSPR issues I believe. My SSPR is set to all users and requires 2 methods. I assume this is what is enforcing everyone in my tenant to require to MFA methods. Right now I have a test account that has a Yubikey and MS App registered a MFA methods, yet when I login, it keeps prompting to register another method. It loops a few times and eventually lets me in.

I was hoping having both Yubikey and MS app as mfa would prevent from needing to add a third method.

reddit.com
u/ITquestionsAccount40 — 3 days ago
▲ 20 r/entra+2 crossposts

PIM activations, directly from your pocket! PIMActivation Portal announcement

Back in 2025 I created PIMActivation as a PowerShell module to make PIM activations faster and less frustrating. Since then, the project has evolved quite a bit.

Today I released the new PIMActivation Portal, a fully open-source Progressive Web App for Microsoft Entra PIM activations.

Main goals:

  • Faster activations
  • Bulk role activation
  • Cross-tenant support
  • Mobile + desktop support
  • Better UX overall

Some highlights:

  • No backend or token cache
  • Browser-only architecture using sessionStorage + IndexedDB
  • Installable as a desktop/mobile app
  • Self-hosted deployment option
  • Managed multi-tenant version available
  • MIT licensed

It supports Entra roles, Groups, Azure Resources, reduced scope activations, activation profiles, bulk deactivation, and more.

This was built together with Lukas Gosling after we independently ended up building very similar PoCs and decided to collaborate instead.

Would love feedback from others working heavily with PIM, RBAC, and cross-tenant administration.

You can check out the full write-up here:
https://www.chanceofsecurity.com/post/introducing-the-new-pimactivation-portal-managed-self-hosted-and-mobile-ready

Access the landing page:
https://pimactivation.com

Direct portal access:
https://portal.pimactivation.com

u/Noble_Efficiency13 — 4 days ago
▲ 8 r/entra

Restricted Management AUs in Entra ID: two undocumented paths that actually work

RMAU scenario's that should't be possible, i've made a very detailed article on LinkedIn with different scenario's that shouldn't be possible when looking at Microsofts documentation.

TL;DR

  • Restricted Management Administrative Units (isMemberManagementRestricted: true) block any principal without an AU-scoped role from mutating their members. That includes a service principal holding Application.ReadWrite.All.
  • Two configurations the design relies on aren't on Microsoft's supported list: applications and their service principals as RMAU members, and Application Administrator scoped to an AU. Microsoft Graph accepts both.
  • A third unsupported configuration lets Entitlement Management write to groups inside an RMAU, via a one-action custom role granted at the RMAU scope to the right governance SPs. This is what makes the standard access-package delivery flow work into protected groups.

Any service principal holding Application.ReadWrite.All can mutate every app registration and service principal in your tenant. RMAUs contain that, even when the design relies on two configurations Microsoft's docs don't acknowledge.

If your tenant has identities that can't be tampered with (pipeline service principals, customer-facing OAuth apps, identity-bridge SPs), the rest of this article will be relevant. Everything below is reproducible against your own tenant with az rest.

https://www.linkedin.com/pulse/restricted-management-aus-entra-id-two-undocumented-paths-janssens-2sfle

u/rohgin — 3 days ago
▲ 10 r/entra+1 crossposts

I broke external sharing for SharePoint

I was hardening the tenant and now no one can share SharePoint files with our clients/customers. We have a specific site but none of the settings work. Instead of getting a one-time code, users must authenticate to our tenant. This appeared to work before I messed with things but I am also reading online that OTP is going away soon. I suspect I broke it as I reverted and complete lockout was reversed but not everything.

Below is what I put in for my support ticket. My last support ticket was closed after two months of no contact so I am looking for other help.

On 5/14/2026 at 3:51 PM UTC, setting AllowEmailVerifiedUsersToJoinOrganization to false via Graph PowerShell triggered a Set Company Information event that added RestrictEmailVerifiedUsers to our tenant DirectoryFeatures. External guests can no longer authenticate via Google federation or email OTP — only Microsoft 365 login is presented. Reversing the setting via PowerShell and UI did not remove the DirectoryFeature. Need RestrictEmailVerifiedUsers removed from tenant DirectoryFeatures.

reddit.com
u/bjc1960 — 4 days ago
▲ 0 r/entra

Where to get hands on experience with Identity and Entra?

I have been wanting to get more into Identity, particularly the security aspect and wanted to see if there was a structured way of learning. I'm much more of a hands on type of learner, so I'd like a lab of some sorts, where I can break and tinker with stuff. I tried getting a developer tenant, but this was not a success.

Are there any good resources allowing for free/cheap and at your own pace learning?

reddit.com
u/Kagawan — 4 days ago
▲ 16 r/entra+1 crossposts

Workplace Ninjas US 2027 | First Speaker Announced: Merill Fernando

Hi All!!

As we officially announced over the weekend on Twitter/X, the one and only Merill Fernando is our first officially confirmed speaker for Workplace Ninjas US 2027 in Scottsdale.

Our dear friend Merill recently announced he's leaving Microsoft to do his own thing. He's someone who is very special to all of us and personifies our mantra of surrounding ourselves with good people who just contribute to that immaculate vibe aesthetic we showed throughout Dallas.

One of our core principles is to bring people YOU want to see to our events. Merill epitomizes that concept as one of the first events ever to bring Merill to the states. We saw how all of you responded through mentoring sessions, engagement, and just hanging out.

With Merill engaging on his new journey, you better believe we will be celebrating his time with Microsoft with a "Merill-bration" of sorts. Make sure you register now, and don't miss out at a bigger, better, and dare I say it MORE FUN year two in Scottsdale.

Join us and register now, as we still have a few early bird tickets remaining:

https://workplaceninjas.us/registration

reddit.com
u/Electronic-Bite-8884 — 4 days ago
▲ 46 r/entra

Microsoft, please, make PIM great!

As a user I have a list of roles available to me via PIM activation. Roles have permissions.

When I attempt to complete an action that requires a permission that I do not have active, how about instead of showing me access denied just show all the roles that are available to me for activation with least privileged first.

Instead of graying out an action button or link because I lack a required permission, put a shield or other indicator and when clicked on give a prompt, popup, or any other option to activate an available role.

Maybe stating the obvious and/or preaching to the choir, but is this not a simple workflow that will benefit all the admins and improve PIM experience?

reddit.com
u/jM2me — 7 days ago
▲ 43 r/entra+3 crossposts

Microsoft seems to be testing Time-Based Conditional Access through the beta Graph API, this is my take

I recently spent some time experimenting with the new “Time” condition that started appearing in Conditional Access policies through Graph, and I put together a write-up covering how it behaves today, how to create policies with it, and where it currently falls apart.

Some key findings:

- The condition appears across user, workload, and agent-based policy types

- Only user/group-based policies currently work in practice

- No GUI support yet, so policies very interesting in the portal

I also explored some practical use cases, including:

  1. Restricting critical applications to working hours 
  2. Shift-based access enforcement for production workers 
  3. Tightening sessions and auth requirements after hours

I think this has huge potential!

Check out the post here: Getting With The Times: Time-Based Conditional Access

What use cases do you see for this feature?

u/Noble_Efficiency13 — 7 days ago
▲ 6 r/entra

Entra ID - Backup Recovery

Anyone really planning Entra ID failover to another tenant?

We are looking at Entra ID backup/recovery vendor now because of some gaps with Microsoft recovery for hard deleted objects. One vendor is pushing there ability to recovery to second tenant very heavily.

At first sound very good, but more we think about it, more it feels difficult in real life. Everything is tied to current tenant, mailbox, Teams, SharePoint, OneDrive, app registrations, integrations, company.onmicrosoft.com etc.

Do people actually keep second licensed tenant ready for this? In real incident, is it really faster to move to another tenant, or just recover the original tenant as fast as possible?

Curious if people are really testing this successfully or if this is more marketing from vendors?

reddit.com
u/Temporary-Myst-4049 — 7 days ago
▲ 3 r/entra+1 crossposts

Admin account showing as last user

I'm having a strange issue on some Entra joined PCs. Win 11 25h2. No matter which user was the last user to log on to a pc, my admin account is always showing as the last logged in user at the login screen. If I sign in as the local admin, it will do the same with that account too. I've tried Intune settings to disable showing the last logged in user but that hasn't changed anything. I'd rather not show my admin account name or local admin account name to our users. Has anyone else come across this?

reddit.com
u/sunnipraystation — 7 days ago
▲ 6 r/entra

Open Source tenant scanners

Can any one recommend open source projects that scan tenants for configuration deficiencies?

We have CISA scuba today, and I used to use Azure Security Kit (AzSK) and Azure Tenant Scanner(AzTS) at another company. We also use Defender's secure score.

Searching here, I found https://maester.dev/

Can anyone recommend others or have you looked at maester.dev?

u/bjc1960 — 7 days ago
▲ 2 r/entra+1 crossposts

entra connect sync problems

Hey there. I am trying to set up entra as in the title into an existing m365. I got the sync software installed on my server but when i go to sync it up i keep getting this duplicate attributes error for all accounts. What should be my next step? I really dont want to lose any user data, which is why i came here. What should i do? Any suggestions?

reddit.com
u/mighty_moosewithlips — 8 days ago
▲ 26 r/entra

Entra Connect Sync to Entra Cloud Sync transition

Microsoft published a what's new post, and at the bottom in the Announcements section, it states that Entra Connect Sync is transitioning to Entra Cloud Sync starting April 2026. Can anyone explain? Does this mean Entra Connect Sync may be decommissioned soon?

u/danfratamico — 9 days ago
▲ 14 r/entra

How are you guys handling temporary M365 Geo-Blocking exemptions for traveling users?

Hey everyone,

We run into a bit of an administrative nightmare. Most of our clients are strictly geo-blocked to our home country via Conditional Access.

Lately, we have been getting a surge of "I'm going abroad for a week" tickets. Our current process is manually creating/editing Named Locations and CA policies for each user/trip. It’s becoming impossible to track, and we’re constantly finding "stale" policies for trips that ended months ago.
How are you scaling this?

Would love to hear how you guys keep your CA policies clean without spending 5 hours a week on travel tickets.

reddit.com
u/genusjoy — 10 days ago
▲ 12 r/entra+1 crossposts

Runbook to Auto-Rotate App Registration Secrets

Hey Everyone, as managing App Registration secrets can be annoying... either you stay on top of them or they expire.

Initially, I had built scripts to alert app owners when secrets were expiring through email/tickets. But then I started thinking: why not just automate the whole rotation process?

Especially since these secrets are created & stored in a secret manager like a Key Vault for scripts, runbooks, or apps to consume.

So I built a process in PowerShell that does the following:

  • With a list of app registrations (to control which ones we autorotate)
  • Rotate their secrets automatically (when a date hits since creation that you set)
  • Update Key Vault with its new secret
  • Keep the old secret on the app for a grace period (to avoid breaking a service that happens to be consuming it at the time of this script run)

Throw it in an Automation Account, run it daily, and secret rotation becomes a managed process instead of a manual task.

I did a full walkthrough for this here: https://www.youtube.com/watch?v=smKhyZ1xL6I

In case all you want is alerting. Where it sends HTML emails to the owners of the app registrations when their secrets are about to expire, I made a walk through on that as well: https://www.youtube.com/watch?v=E3wnj0bVRWg

u/AdeelAutomates — 8 days ago
▲ 2 r/entra

Legacy system integration with Entra ID - what's actually tripping you up

Been working through a hybrid setup lately where the on-prem AD isn't going anywhere soon. Kerberos dependencies, some older line-of-business apps that just assume domain membership, GPO-driven workflows. the usual. Application Proxy helps for publishing the web-based stuff, but it won't touch your classic Kerberos, or SMB dependencies, and anything that needs a domain controller in sight is still a problem. The thing I keep running into is that Entra DS gets floated as a fix, but it really isn't a drop-in for full AD DS. It'll give you managed LDAP, Kerberos, and NTLM support, which covers some ground, but the, moment you need forest trusts, schema extensions, or full domain admin control, you're out of luck. Forest and domain trusts aren't supported in Entra DS at all, so if that's part of your environment, you're keeping AD DS regardless. Worth flagging too that hybrid Entra join is an AD DS plus Entra ID, device state, not really an Entra DS story, so that framing can muddy the conversation. End result is you keep a minimal on-prem AD footprint for the legacy dependencies while moving users and devices to Entra and Intune. That's not really a failure of cloud-first strategy, it's just the realistic middle ground most orgs are sitting in right now. The other pressure I'm seeing is legacy auth deprecation. If any of those older apps are still leaning on Basic Auth or similar, that's becoming a harder conversation alongside the domain dependency problem. Curious how others are handling the apps that genuinely can't modernise yet. Wrapping them with a secure access layer, keeping AD DS alive indefinitely, looking at OAuth or API, patterns where the app can support it, or just accepting the hybrid reality for a few more years?

reddit.com
u/heartmocog — 9 days ago
▲ 8 r/entra+1 crossposts

Best approach for integrating HR REST API with Entra ID API-Driven Provisioning in a hybrid environment?

ey everyone,

I’m working on a relatively small hybrid environment (~300 users) with on-prem AD + Entra ID.

Recently, I managed to set up an API-Driven Provisioning flow for the on-prem AD, and I already validated user creation through MS Graph successfully provisioning all the way down to the local AD.

Now I’m looking to evolve this into a more automated setup by periodically querying the HR authoritative source, which currently exposes the data through a REST API.

My main question is really around architecture/best practices:
what would be the best way to handle this periodic integration between the HR API and Entra ID?

My first idea was to build something in Python that consumes the HR REST API and sends the data to Entra/API-Driven Provisioning, but that would require maintaining a scheduled job running on-premises (Windows Task Scheduler, container, service, etc.).

I’d like to understand how you usually implement this kind of scenario in hybrid environments.

The main goal is to keep the solution simple, reliable, and easy to maintain over time.

If anyone has implemented something similar, especially using API-Driven Provisioning, I’d really appreciate hearing your experience or recommendations.

reddit.com
u/Difficult-Help2148 — 10 days ago
▲ 52 r/entra+3 crossposts

Learning Microsoft Graph

Hey everyone,

I built a series of content on Microsoft Graph. I thought I share it here.

Microsoft Graph, if you don’t know, is Microsoft’s unified platform to interact with Entra ID, Microsoft 365, Teams, SharePoint, Intune, and more through APIs.

This is what allows you to truly automate against the Microsoft cloud platform. It has replaced many of the PowerShell modules for everything but Microsoft Exchange.

If you wish to understand it so you can start automating on these platforms (both Graph Module & API), I got you! Here are some of the episodes for you may be interested in checking:

Putting it all together, here is the kind of things you can do with Graph: Build a Report on Azure, Entra & M365 Permissions! This builds a identity permissions report of your tenant & stores it in SharePoint in a new excel doc. If nothing else check out @ 40:04 , one of my favorite things about Graph is seeing excel docs come alive in real time with the data!

u/AdeelAutomates — 11 days ago