r/entra

▲ 2 r/entra

Question&Rant: What is up with registration campaign not showing and forced passkey registration CAP not forcing?

To be fair, there has to be something else, a detail, or a deeper understanding that I am missing, and getting frustrated at this point is blinding the obvious.

Passkeys are enabled for all users, pretty basic config, nothing special. Registration campaign is targeting user group for registration of passkey. Nothing has happened for 9 days now. Targeted users are not prompted anywhere. Even forcing sign-out some, they are not prompted on the sign-in.

CAP was created which requires phish-resistant authentication method to access all apps, and this CAP is targeting a different subset of pilot users. This has not forced a single user in last 6 days to register for passkey. Granted, nearly all signin and use WHfB.

Now the weird part. 9 and 6 days ago I created two new test accounts and went through usual onboarding without passkeys. They are my control accounts that were targeted with registration campaign or CAP. Again, to be clear, these accounts went through onboarding to match the state of the pilot users. These test accounts were not setup with passkeys from the beginning.

So, these test accounts, one targeted with registration campaign was prompted for passkey on day 3 or 4, and the other targeted with CAP prompted for passkey setup within 30 minutes of being assigned the cap.

Please educate me why or what is wrong here. I cannot get consistent experience between existing accounts and new test accounts.

At this point we are considering instructing users to install MS Authenticator, sign-in with work or school account, and setup passkey in this flow using their existing MFA. This flow has worked for 5 users flawlessly, even if they already had authenticator with OTP, mfa number matching, or other. This flow always resulted in full setup of account with passkey, prompt to enable MS Authenticator in settings, even if account was already setup in past.

reddit.com
u/jM2me — 1 day ago
▲ 0 r/entra

Entra support tickets

Hey everyone — question for those of you who administer Microsoft identity environments, whether that’s Active Directory, Microsoft Entra ID, or a hybrid environment.
What are some actual support tickets / break-fix issues you’ve had to work?
I’m working on a project where I’m trying to build out realistic IAM/identity support scenarios. I’m not really looking for project work like “migrate AD to Entra” or “implement Conditional Access.” I’m more interested in the day-to-day tickets that land in your queue.
Things like:
A user suddenly can’t access an application
MFA or authentication issues
Group membership/permissions problems
SSO failures
Account lockouts or provisioning issues
Something broke after a policy/configuration change
A ticket that looked like an IAM problem but turned out to be user error
Basically: What are some memorable, weird, common, or difficult identity-related tickets you’ve actually had to troubleshoot?
The more realistic and specific, the better. I’m trying to avoid making up scenarios that wouldn’t actually happen in a production environment.

reddit.com
u/ITGUYRYX — 1 day ago
▲ 14 r/entra

Conditional Access is dialled for people, service principals are a total blind spot

Years getting conditional access right for humans device state, risk, mfa dead proud of it.

Then the AI stuff shows up, copilot agents, service principals someone stood up for a bot, app registrations with client secrets older than half my team. CA fires on interactive sign-ins, so all of this slides right under the controls I trust.

I can see the sign-ins after the fact. I can't put the same posture and least-privilege story on a service principal that I put on a person. That's the gap an auditor jabs at, and I've got no answer.

reddit.com
u/Muted_Math2750 — 1 day ago
▲ 4 r/entra+1 crossposts

AADSTS500032 - Cannot find signing certificate/private key to issue a certificate when logging into Entra ID Azure VMs

Hi everyone,

Last year I setup an AVD with SSO to EntraID. It worked perfectly until last week. 

Now I'm running into an issue affecting multiple Azure VMs configured for Microsoft Entra ID login.

I have verified AADLoginForWindows extension is healthy, confirmed affected accounts still have VM login permissions, tested with multiple admin accounts and then reviewed Entra sign-in logs and authentication appears successful but keep seeing this error inside Windows App.

my laptop is on Windows 11 and on the latest monthly update.

Has anyone seen AADSTS500032 in an Azure VM login scenario before?

u/BornIn2031 — 2 days ago
▲ 1 r/entra

How are you onboarding new hires before assets are assigned?

We have a workflow that sends new employees their account credentials via SMS. We ask them to sign into their account, set up Microsoft Authenticator, and create their new password. All of this is usually done before they get any company equipment. This gives them a day or more to start reading emails, sign into external work accounts, and - most importantly- sign all their onboarding paperwork before they get their company phone and computer.

We're starting to put the squeeze on using personal devices so I need a new policy.

How can we communicate with new employees before they have a company computer and phone in their hands?

I'm looking into generating a seven day temp access code. I just have to figure out how to do this in power autoamte. But is this what everyone's doing? Is there a better 'best practice'?

reddit.com
u/StandingDesk876 — 2 days ago
▲ 7 r/entra

Is Entra Cloud Sync Useful? (Hybrid)

So there seems to be very little fanfare about Entra Cloud Sync and that makes me think what I am hoping it solves is probably not the case.

I recently joined a new company and unlike my previous 8 year stint where I configured and totally understood the hybrid nuances in this environment not only do I not have design knowledge it seems totally backwards.

Although the Entra connection agents run on DC’s it seems automations all run on the exchange server (I tried to decom it with a scream test and things screamed loud). The service desk use the on prem exchange web admin to make most user object changes including new user creation and when they create directly in AD it doesn’t sync back and creates on-prem Mail Users instead of remote mailboxes.

So the big question is, does Entra cloud sync solve the one way sync of Entra connect? Once set up in a hybrid environment AD/AAD(Entra) can the service teams start using cloud portals for management, can I move automations to graph instead of scripts calling on prem exchange servers? I’ll await positive responses with my fingers crossed 🤞

reddit.com
u/CertainlyNotAnMVP — 2 days ago
▲ 7 r/entra

Registration campaign not prompting?

I'm trying the registration campaign with some test users, but I'm getting no prompts to install MS authenticator. The target is, as said MS authenticator, which is set as push and available for all users. The test users are the only ones targeted by the campaign, and those users only have SMS/phone as enrolled MFA method, No MS authenticator set or installed. The Campaign policy is enabled, targeted to Authenticator, 0 days allowed to snooze and applied to the right group. One of these user had no MFA method set initially, then on the first logon he was able to setup the SMS method. The campaign has been activated at least 4 hours ago, and still no sign of the MS authenticator push during the MFA process. Everything seems in place, and I think 4 hours should be enough for the campaign to be active. Any suggestion on what to look for?

reddit.com
u/Unable_Drawer_9928 — 3 days ago
▲ 3 r/entra

No Sign in logs for OIDC app

This is a perplexing one. I have an OIDC app using Entra for SSO. Everything great, generally PRT even works. I looked at logs of most sign ins and there's -at least- one login in a given day for the app PRT or otherwise.

That said we have an issue where we did not see any logins for a particular user (there are logins but not say, in a given day). We noticed that we see a Windows Signin and MyApps signin (So browser opened), but no actual login for the app itself.

My thought was that maybe user was leaving laptop on/open/logged in 24/7, and just re-starting the session, but even then I tried it this morning with my own login and it still showed a login in Entra.

Anyone have any ideas why the logins wouldn't show in the logs?

reddit.com
u/orion3311 — 2 days ago
▲ 13 r/entra+1 crossposts

Calculating the Licensing Requirement for Entra Conditional Access Policies

After the discussion about the licensing gap prompts shown in the Entra admin center, here’s a PowerShell script to compute the set of user accounts that should have Entra P1 licenses. The information comes from the conditions property of conditional access policies with group and directory role membership expanded to find individual accounts. The set is checked against the set of users licensed for Entra P1 to find the accounts that need to be licensed.

https://office365itpros.com/2026/08/18/find-entra-p1-accounts-to-license/

u/Unlikely_Tie1172 — 2 days ago
▲ 2 r/entra

Tagging users that are away (maternity leave)

For users who are on "pause" due to things like maternity leave, are you tagging their user accounts? Sometimes we also have season workers where there's a good chance they'll be back in a couple months so we may not want to purge them either, trying to think of a good way to tag/document their accounts as a "do not purge".

reddit.com
u/orion3311 — 2 days ago
▲ 4 r/entra

GSA Private Access and Conditional Access Policy

Is it possible to require an Intune complaint device before for GSA Private access works?

I’m tasked with requiring Intune compliant devices before access to a Windows Server hosted on Azure VM is granted.

I created an CAP targeting the Microsoft managed “GSA-PrivateAccessTrafficForwardingProfile” app and the Private Access app for the target VM. I configured the Grant rule to “Require device to be marked compliant” and scoped the policy to a test account.

It doesn’t seem to be working and the sign-in logs don’t even show an authentication event for any of the target resources/apps of my CAP. I can still connect to the target VM from a test company laptop and my personal laptop (which shouldn’t be allowed)

Any advice? I’m starting to think it’s not possible and honestly I need to convince my manager to let me block all personal devices in general

reddit.com
u/Bbrazyy — 3 days ago
▲ 7 r/entra

Weird behaviour SAML Global Protect

We have configured SAML for Global Protect requiring sign in frequency every time and MFA.

Some users periodically experience that they can just connect without any MFA. I can also confirm within the logs it is well past the threshold of 5 minutes. Devices are Entra joined. 25H2 latest updates. Authentication happens via Default Browser (Edge) not embedded Browser. Cookie Lifetime also only 2 hours.

reddit.com
u/Failnaughtp — 4 days ago
▲ 2 r/entra

Guest Account Collaboration but No Mailbox

We have a case where all externals needs to be enrolled in our SaaS Hr system and they eventually get and AD account — synced to Entra as Members but will have no Mailbox - How do we achieve the following

  1. We want to have their external email address mentioned in their profile so that emails reach to them. ( external mailbox provided by their own org)
  2. Once their account is visible in Entra, we want to make sure that , they are shown in Teams for collaboration
  3. They get access to some sharepoint sites and some lion of business apps

We do not want to use azure b2b because this in someway removes the. source of authority, thats why we have them in HR system , b2b kinda bypasses this - creates cloud only accounts and granting access to internal apps to these ( external ids ) accounts is seen as risk by security team.

What can be a possible solution?

reddit.com
u/snow-leapord-1 — 3 days ago
▲ 0 r/entra

How to do a CA with app protection policy?

Hi,
I’m looking to figure out how we can block native mobile mail apps (Apple Mail, Samsung Mail, etc.) so users are required to use Microsoft Outlook for email access from mobile.

Web browser login / OWA is approved

The same approach would ideally apply to other apps as well, where we want to restrict access to approved/managed applications only.
Thank you!

reddit.com
u/xoxoxxy — 4 days ago
▲ 3 r/entra

One user account not sending group memberships during SAML authentication

We’re a hybrid environment using cloud sync. I’ve got a single user who during SAML authentication isn’t sending group memberships to the connected enterprise application. I’ve confirmed this using SAML-Tracer in the browser. I’ve compared this account to others and can’t see anything different except that the user in question has no “user type” in Entra where every other user in the tenant has “member.” I’m not sure if this is the issue or not, but it’s the only difference. Anyone seen anything like this before?

Edit: the fix https://www.reddit.com/r/entra/comments/1vp2ffn/comment/p3uy8jp

reddit.com
u/size0618 — 6 days ago
▲ 7 r/entra

Per-user MFA to Conditional Access

I want to migrate my tenant from Per-user MFA to Conditional Access.

The situation at the moment:

  • Most of the users have saved an OTP Token in 1Password instead of using MS Authenticator. How can i force a user to change it to MS Authenticator instead of this OTP Token?
  • When i create a user in Entra ID, the user has no MFA method in his account. How is the user experience? Entra ID will likely require to register MS Authenticator and enforce MFA upon the next login?
  • Which licenses for a user is needed for CA?
reddit.com
u/Certain-Mountain-564 — 5 days ago
▲ 3 r/entra+1 crossposts

Mac os compliance issues in all browsers say registere device

macOS + Intune – Browser shows “Device Not Compliant”
Question:
We started experiencing this issue after the user’s password was changed twice using the local account on the Mac.
The Mac is enrolled in Microsoft Intune with Conditional Access requiring the device to be compliant.
The Mac shows as Compliant in Intune and Microsoft Entra, and Microsoft applications work normally. However, when the user accesses Microsoft 365 through a browser, Conditional Access reports:
“Device is not compliant” / “Set up your device”
Company Portal is already installed and the device is enrolled
Questions:
Could changing the password twice through the local macOS account cause the Platform SSO/device identity or SSO token to become out of sync?
Has anyone experienced the Mac remaining compliant in Intune/Entra while browser authentication stops working after a local password change?
Has anyone resolved this without completely re-enrolling or wiping the Mac?

reddit.com
u/arjunmichel — 6 days ago
▲ 6 r/entra

UAC Prompt Elevation Issues with Admin (MSP Cleanup)

Hoping I can get some help with this one, been running into issues with it for a bit and haven't found the root cause yet.

An org I work with is getting rid of their MSP because they do a terrible job, I (among others) have been tasked with getting them out and cleaning things up.

One issue we have had for a while now is some devices that are Entra joined don't allow Global Admins to elevate UAC prompts and I can't figure out why.

Firstly, both the admin accounts are in the Microsoft Entra Joined Device Local Administrator role, which, as I understand it, should "just work" but alas UAC elevation still doesn't work.

Devices are refreshing PRTs just fine so it's not that, not to mention the accounts have had the above role assigned for months now.

I haven't found any consistency to which devices are having this issue, and the only solution I've found so far is to reinstall Windows (just for good measure) and rejoin to Entra.

Any help troubleshooting this would be great.

reddit.com
u/planedrop — 6 days ago
▲ 3 r/entra+1 crossposts

Phishing-Resistant MFA: Planning Your Passkey Rollout in Microsoft 365

There's a ton of resources out there from great people in the space but I wanted to share my thoughts and typical process for helping organisations adopt passkeys. Hopefully it helps someone out.

The blog covers:

  • Info on the Microsoft notification to retire SMS and Voice, and why
  • The different types of passkeys available
  • Strategy and rollout approach
  • Considerations for legacy systems
  • Considerations around downgrade attacks

Phishing-Resistant MFA: Planning Your Passkey Rollout in Microsoft 365

u/NateHutchinson — 7 days ago
▲ 22 r/entra

Hardware keys for users without phone or refuse to use personal phone at work.

Hey all,

With the changes that MS is making to deprecate SMS and Voice auth, how would you go about setting up users with only a hardware key/Yubikey?

I tested it out on a dummy account by just trying to add a Yubikey to the account but it doesn't give me the option unless I have a different MFA setup already like Authenticator.

So for the couple users we have that either don't have a smart phone or refuse to add the Authenticator app to it we've instead just set up the voice auth to their IP desk phone, and then set up a Yubikey and that seems to satisfy the requirements.

When SMS/Voice auth is gone, the only method remaining for those users is Yubikey, but you can't only have a Yubikey without another MFA method. Will alternate email + Yubikey work?

Also, how would this affect break glass accounts? Right now they have a Yubikey set up and locked in a safe, the phone/email goes to a Google voice number/email.

Are hardware tokens still good in 2026? I see that as an option in our authentication methods list. Is Token2 a good brand?

I know there's a bunch of these posts lately, but everyone's org is different.

Thanks,

reddit.com
u/sysadmin532 — 8 days ago