๐ข Breaking changes: Guest billing for Entra ID Governance
I haven't seen any announcements on this and guidance is extremely lacking, so Joe Stocker gave me time to create a script to help everyone assess costs early :)
I would love your feedback!
github.com/nathanmcnult...
23.07.2025 23:21 โ ๐ 8 ๐ 6 ๐ฌ 1 ๐ 1
Dll conflicts between AZ and Graph Sdk auth modules. To avoid this you need to import the modules in correct order plus have versions that can work together. It's awful.
22.07.2025 04:30 โ ๐ 1 ๐ 0 ๐ฌ 2 ๐ 0
What about Az? That's the real pain mostly.
21.07.2025 20:45 โ ๐ 0 ๐ 0 ๐ฌ 2 ๐ 0
OSINT
Entra ID Open Source Intelligence tool
Struggling to find a caller by object ID in AzureActivity in your directory? It may be from another directory.
Check the claims field, the tenant ID is contained within the claim and you can use something like aadinternals.com/osint/ to find out which tenant the caller is from.
02.07.2025 10:33 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Basically if I take the code it can be used to backup our sentinel settings (after some modification of course)?
26.06.2025 04:48 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Not run o lot of tests but in general batching was faster for me (probably because of parallel overhead)
05.06.2025 12:06 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
I am a little bit surprised you didn't show graph batching which is much faster ๐ค
05.06.2025 04:20 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Ever wonder exactly what Defender AV settings are configured and where they got those settings from?
This new feature in Defender for Endpoint shows the effective configuration and the source the settings came from
Very helpful for troubleshooting :)
learn.microsoft.com/...
29.05.2025 04:35 โ ๐ 13 ๐ 2 ๐ฌ 0 ๐ 0
Sure. It's reappearing issue that won't be solved without teams that create those modules coordination though.
16.05.2025 05:22 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
They should with every sdk release inform with what version of AZ modules this one is compatible for (doesn't have dll conflicts). Otherwise I stay on the 2.25 ๐
15.05.2025 17:22 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
One of the questions during our #MSGraph sessions at @mmsmoa.bsky.social was around filtering. Highly recommend checking out @merill.netโs blog post for a deeper dive and fantastic visuals
merill.net/2024/07/prop...
#PowerShell #MMSMOA
09.05.2025 21:40 โ ๐ 27 ๐ 6 ๐ฌ 4 ๐ 0
Not seeing out-gridview getting fixed? ๐
26.04.2025 06:00 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Linking to page aka.ms/GetMicrosoftAuthenticator
๐จ PSA: FAKE Microsoft Authenticator apps are flooding the App Store & Play Store! โ ๏ธ
Protect your users!
ONLY send them to the official download link ๐
Bookmark this! Update your user guides & intranet NOW. RT to spread the word!
#CyberSecurity #MFA
๐งตโ
22.04.2025 09:00 โ ๐ 14 ๐ 8 ๐ฌ 2 ๐ 3
Microsoft Attempts to Fix Microsoft Graph PowerShell SDK
V2.26 and V2.26.1 of the Microsoft Graph PowerShell SDK were low-quality, buggy disasters. Microsoft aims to fix the problem in the next version.
Microsoft attempts to fix the problem with V2.26.1 of the Graph #PowerShell SDK and Azure Automation. This is the kind of issue that should never have appeared in public. Sad to see vital components abused.
office365itpros.com/2025/04/14/m...
#Microsoft365
14.04.2025 09:42 โ ๐ 3 ๐ 1 ๐ฌ 2 ๐ 0
100% true.
I would add other incompatibilities like with AZ auth module and that it requires you to authenticate in the correct order ๐
15.04.2025 04:44 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Recover Admin Account with Entra Break Glass Access Application
Learn how to configure break glass access application in Entra ID to recover admin accounts from the lockouts.
I've been mulling over this concept of a break glass application in Entra, and thought I'd share some important notes for anyone that might be considering it
For reference, here's the article:
blog.admindroid.com/...
Short thread, but my primary concern is privilege escalation
11.04.2025 03:42 โ ๐ 11 ๐ 2 ๐ฌ 3 ๐ 0
So, uhh, this seems like something that is highly abusable that I bet almost nobody is monitoring for... :-/
learn.microsoft.com/...
08.04.2025 05:24 โ ๐ 19 ๐ 3 ๐ฌ 3 ๐ 0
# Find apps missing SPs, select and register
Get-MgBetaAuditLogSignIn -Filter "signInEventTypes/any(t: t eq 'servicePrincipal') and servicePrincipalId eq '00000000-0000-0000-0000-000000000000'" | Out-GridView -PassThru | ForEach-Object {New-MgBetaServicePrincipal -AppId $_.appId}
06.04.2025 00:20 โ ๐ 6 ๐ 1 ๐ฌ 1 ๐ 0
Managing Restricted Groups with Access Packages
๐ฎ Restricted Management Admin Units (RMAU) in #EntraID
Hackers HATE This Hidden Entra ID Feature Most Admins Never Use@NathanMcNulty breaks it down for us ๐
๐ง Get the full podcast episode at https://t...
New website and first blog post in a couple years! :)
I got to talk with @merill.net recently about Restricted Management Admin Units, but some noted they break Access Packages and PIM making them less useful
While true by design, we can actually fix this!
nathanmcnulty.com/blog/2025/04...
04.04.2025 19:57 โ ๐ 21 ๐ 8 ๐ฌ 3 ๐ 0
Retire Service Principal-Less Authentication - Microsoft identity platform
Learn about the mitigation steps tenant administrators should perform for service principal-less authentication behavior deprecation.
This is awesome! Microsoft is killing off the ability for multi-tenant applications to authenticate in directories where a service principal has not been registered.
learn.microsoft.com/...
I'd like to automate discovery and remediation for admins, but I need help testing :)
05.04.2025 02:11 โ ๐ 14 ๐ 2 ๐ฌ 2 ๐ 1
Yak Shaver of the highest order.
GitHub: github.com/JustinGrote
Twitter: twitter.com/JustinWGrote
Bluesky handle for the Microsoft Intune Customer Success Blog and the Intune CxE team in @MSIntune Engineering. #MSIntune
#IntuneInspired Blog: https://aka.ms/IntuneCustomerSuccess
X: https://aka.ms/IntuneSuppTeam
Bluesky.ms is a community effort to connect with folks at Microsoft & label accounts as
โ
Microsoft employee
โ
Microsoft MVP & RD
This service is managed by @merill.net as a personal project & is not affiliated with Microsoft
See Posts tab for guide ๐
Sarcastic. Subtle. Curious.
Principal Identity Security Researcher @Microsoft. Ex-Secureworks (PhD, MSc, MEng, CITP, CCSK).
And yes, opinions are my own ;)
SecOps Witch ๐ฎ
Lego zealot & Blizzard tragic ๐ฎ
Slave to 7yo terror ๐ถ
Australian based ๐ฆ
Provider of sarcasm & profanity ๐คฌ
she/her โ๏ธ
Views ALL MINE ๐
https://linktr.ee/girlgerms
Cybersecurity Specialist, Public Speaker, Ex-Hacker.
https://marcushutchins.com
UK Based Security MVP, Head Of Presales for Atech Cloud and single dad to 3 boys
Hacker. Friend. Cybersecurity Researcher at Huntress.
I'm Thee Sarcastic Warrior, Keeper of Secrets in MSR, Inquisitor of the CTO, Defender of Caturdays, Hugger of Trees and Hunter of Bots.
Security researcher.
I have a blog: https://sapirxfed.com
PM Microsoft Sentinel ๐จ๐ปโ๐ป One SOC team @Microsoft | My dog ๐ถ | Home automation ๐๐ก | Gaming ๐ฎ | Photography ๐ท | Opinions mine.
Azure Technical Trainer @ Microsoft | MCT | Founder AzureCrazy.com | Blog at cloudbuild.co.uk | #Microsoft #Azure | Views are mine
Microsoft Security MVP + Microsoft Security Practice Lead at Threatscape
Mostly: Entra, Defender, Intune, Purview, and Microsoft 365
Also: dad, metal, lifting, wrestling, cars
Mostly on Twitter rather than here: @rucam365
AI and Teams MVP
alexholmeset.blog
โ #Cloud and #CyberSecurity Architect @itnetX_CH, Information #Security Manager, and #Microsoft #Azure #MVP #MCT #CCSP #CISM.
๐ฃ Speaker, Blogger, Author, and Instructor @ charbelnemnom.com
Microsoft MVP for Identity and Graph API
Blog at https://ourcloudnetwork.com/
Microsoft MVP ๐ป
Leading Expert @UMB โ๏ธ
Travel Enthusiast โ๏ธ
Blog: https://scloud.work/
Contact: https://elFlorian.ch
Azure MVP, software engineer, software architect, blogger and speaker loving all things serverless C# and Azure. Certified Azure Solutions Architect.