Announcing: Entra as Code Interactive Workshop - Now Public!
I'm excited to share that I've just released my Entra as Code Interactive Workshop as a public GitHub repository.
github.com/mjendza/work...
@mjendza.bsky.social
Architect/Consultant/IAM/Azure/AWS
Announcing: Entra as Code Interactive Workshop - Now Public!
I'm excited to share that I've just released my Entra as Code Interactive Workshop as a public GitHub repository.
github.com/mjendza/work...
๐๐จ๐ฐ ๐๐จ ๐ฒ๐จ๐ฎ ๐๐ง๐ฌ๐ฎ๐ซ๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐ข๐๐ง๐๐ ๐๐ง๐ ๐๐ฎ๐๐ข๐ญ๐๐๐ข๐ฅ๐ข๐ญ๐ฒ ๐ฐ๐ก๐๐ง ๐ฆ๐๐ง๐๐ ๐ข๐ง๐ ๐๐๐ซ๐ฏ๐ข๐๐ ๐๐ซ๐ข๐ง๐๐ข๐ฉ๐๐ฅ๐ฌ ๐๐ง๐ ๐๐๐ ๐๐ฉ๐ฉ๐ฅ๐ข๐๐๐ญ๐ข๐จ๐ง๐ฌ ๐ข๐ง ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ซ๐ ๐๐?
My proposal with Backstage & Maester
#EntraID #IAM #DigitalIdentity
Google Pixel 10 phones natively support C2PA Content Credentials, providing verifiable, offline-capable provenance and hardware-backed security for photos and media.
๐๐๐ซ๐ญ๐ง๐๐ซ ๐ฏ๐ฌ ๐๐ฎ๐ฌ๐ญ๐จ๐ฆ๐๐ซ:
๐ Social Federation (Apple ID) vs Workforce Federation (Okta).
๐ Different levels of compliance and security.
๐ Different business owners and processes - but maybe the same tools and applications.
๐ Different SLA.
๐ ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐ข๐ฌ๐ง'๐ญ ๐ฃ๐ฎ๐ฌ๐ญ ๐๐๐จ๐ฎ๐ญ ๐ก๐๐ฏ๐ข๐ง๐ ๐ฌ๐ญ๐ซ๐จ๐ง๐ ๐ฉ๐๐ฌ๐ฌ๐ฐ๐จ๐ซ๐๐ฌ...
It's about understanding your users, risk profile, and regulatory requirements to implement the RIGHT security measures for each context.
And you? Do you use similar authentication/authorization methods like on the screen?
What is the best tool to review public Entra ID Tenant data?
For me: AADInternals OSINT (site & PowerShell module)
We can get complete details about the tenant, including:
๐ Tenant ID
๐ Tenant Name (onmicrosoft domain)
๐ Domains (all domains connected with tenant)
๐ Brand name
#EntraID
Do you need to meet complicated password requirements?
Feel free to use a 60-character password.
PS> To improve security, I pasted it as a picture!
๐ฅ Blog Post Alert ๐ฅ
๐ ๐๐จ๐ฆ๐ฉ๐ซ๐๐ก๐๐ง๐ฌ๐ข๐ฏ๐ ๐๐ฏ๐๐ซ๐ฏ๐ข๐๐ฐ ๐จ๐ ๐๐ฎ๐ซ ๐๐๐ ๐๐ฆ๐ฉ๐ฅ๐๐ฆ๐๐ง๐ญ๐๐ญ๐ข๐จ๐ง
Do you move from the SQL table with username & password?
Do you own more than one application?
Are you facing a sign-in screen all the time?
Check my blog post on how Sing Sign In works ๐
mjendza.net/post/sso/
#EntraID #SSO
๐ก ๐๐ฒ ๐๐ง๐ญ๐ซ๐ ๐๐ฑ๐ญ๐๐ซ๐ง๐๐ฅ ๐๐ ๐๐ซ๐๐ก๐ข๐ญ๐๐๐ญ๐ฎ๐ซ๐ ๐ก
I recommend a couple of components:
๐ Management API.
๐ User Flows & Customization.
๐ Entra ID as Code.
๐ Profile as a central place to manage user details.
๐ My demo application: Portal.
๐ท๏ธ Extra: Verified ID for External ID tenant
#EntraID #CIAM
A friendly reminder ;)
๐ Use Fido2 keys
๐ Use software passkey with your password managers
๐ Verifiable Credentials can also be used as a passwordless method
๐ Passwordless is easier to use than complex long password
I checked my bank account history three times. The wire was not provided to me ;)
Link: www.ft.com/content/9921...
๐Blog Post Alert
Discover how token enrichment can streamline your customer authentication processes and enhance security.
Explore how the Identity Platform can support your business needs and unlock new possibilities.
๐I stopped using Visio, and other tools for:
๐ Big Picture diagrams
๐ Sequence Diagrams
And moved to PlantUML, creating all diagrams as code.
And you?
๐ pg_documentdb is open source
I created the initial version with Vinod Sridharan (an absolutely brilliant engineer) at Microsoft a few years ago and it's come a long way since.
It reimplements Mongo API with exact semantics in PostgreSQL. Already used by FerretDB!
github.com/microsoft/do...
Simple & Amazing tool to stress your HTTP
github.com/codesenberg/...
PS> Are you ready to return 429 status code ๐ค
Next place where you can check the technical details for Verifiable Credentials: sandbox to play around with different business types and Data Model 1.1 and 2.0
#verifiablecdedentials #sandbox
vcplayground.org
Entra ID vs Entra External ID
๐Do you know that there are two different tenant types?
๐Do you know that there is a dedicated tenant for your customers? Were you fully separated from your organization?
#IAM #CIAM #EntraID
๐ฅ If you're looking to dive deep into the Verifiable Credentials flow, this is the first place you should visit!
lnkd.in/dak5xidM
The diagrams in the article are amazing and provide a clear visual representation of the process.
#VerifiableCredentials #Identity #DigitalIdentity
Hello token friends, do you use the content of the access token as part of your application. Then be aware that Microsoft will switch to encrypted access token and this might break stuff.
Switch to id token. #EntraID
https://devblogs.microsoft.com/identity/access-tokens-and-id-tokens/
Magic Link? Three facts about:
#authentication #authorization #digitalidentity
๐ก With Verifiable Credentials
๐ a full authorization flow for payments (I created a Factorlabs Bank Demo to show you the Business Case ๐ช
๐also authorize access (also physical access) as a security guard ๐คต
Do you have any scenario with authentication and/or authorization scenarios?
I plan to test, maybe from the console it will be faster to get the same result
github.com/mivano/azure...
My favourite 'Cost analysis' view is Group by resource with the Daily Granuariry:
- My workloads are 'stable' I don't have picks so monthly prediction can be based on a daily consumption
- Based on the diagram I can decide and move to another resource type to limit the cost of the solution
Need a Morse Code Translator?
Check morsecodetranslator.com also there is a GitHub repository :)
github.com/ozdemirburak...
Build your own Morse Translator ๐ฅธ
#ItCanBeFun
Demo for authentication: demo.factorlabs.pl
VC for Europeans github.com/goeIDAS/test...
Enable Entra Verified ID for your workforce or customer tenant: www.microsoft.com/en-us/securi...
check my blog post: mjendza.net/post/07-07-2...
Verifiable Credentials (VC) facts and cases:
- passwordless for your Identity Provider (authentication)
- a framework used by EIDAS to authorize via National ID
- coupons, gift cards
- authorize physical access and person-people verification
- with national ID can be a captcha verification
1/2
Look at the blog post if you are thinking about the solution to speed up token enrichment with authorization data.
In my opinion many cases for 80% of calls the response is static (Pareto principal) and with a key-value store, we can deliver the response fast!
www.feldera.com/blog/fine-gr...
DOOM as captcha ๐
One of the methods to protect your CIAM system from synthetic (for example fake accounts with 10 min mailbox) is the captcha system.
The best one is not involving you as a user to prove you are human.
But look this one is amazing ;)
doom-captcha.vercel.app
#CIAM #syntetic
๐ฅธ VC Backend can based on Credo github.com/openwallet-f...
๐ฅธ Wallet (Android and iOS) TrustBloc Wallet SDK github.com/trustbloc/wa...