Mateusz Jendza's Avatar

Mateusz Jendza

@mjendza.bsky.social

Architect/Consultant/IAM/Azure/AWS

20 Followers  |  59 Following  |  30 Posts  |  Joined: 29.12.2024  |  1.7124

Latest posts by mjendza.bsky.social on Bluesky


Preview
GitHub - mjendza/workshop-entra-as-code-interactive Contribute to mjendza/workshop-entra-as-code-interactive development by creating an account on GitHub.

Announcing: Entra as Code Interactive Workshop - Now Public!

I'm excited to share that I've just released my Entra as Code Interactive Workshop as a public GitHub repository.

github.com/mjendza/work...

09.01.2026 09:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐‡๐จ๐ฐ ๐๐จ ๐ฒ๐จ๐ฎ ๐ž๐ง๐ฌ๐ฎ๐ซ๐ž ๐œ๐จ๐ฆ๐ฉ๐ฅ๐ข๐š๐ง๐œ๐ž ๐š๐ง๐ ๐š๐ฎ๐๐ข๐ญ๐š๐›๐ข๐ฅ๐ข๐ญ๐ฒ ๐ฐ๐ก๐ž๐ง ๐ฆ๐š๐ง๐š๐ ๐ข๐ง๐  ๐’๐ž๐ซ๐ฏ๐ข๐œ๐ž ๐๐ซ๐ข๐ง๐œ๐ข๐ฉ๐š๐ฅ๐ฌ ๐š๐ง๐ ๐’๐’๐Ž ๐š๐ฉ๐ฉ๐ฅ๐ข๐œ๐š๐ญ๐ข๐จ๐ง๐ฌ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ?

My proposal with Backstage & Maester
#EntraID #IAM #DigitalIdentity

20.10.2025 08:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Save What Matters Curate Feeds | Make Collections | Customize Email Briefs

Google Pixel 10 phones natively support C2PA Content Credentials, providing verifiable, offline-capable provenance and hardware-backed security for photos and media.

11.09.2025 17:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐๐š๐ซ๐ญ๐ง๐ž๐ซ ๐ฏ๐ฌ ๐‚๐ฎ๐ฌ๐ญ๐จ๐ฆ๐ž๐ซ:
๐Ÿ‘‰ Social Federation (Apple ID) vs Workforce Federation (Okta).
๐Ÿ‘‰ Different levels of compliance and security.
๐Ÿ‘‰ Different business owners and processes - but maybe the same tools and applications.
๐Ÿ‘‰ Different SLA.

10.09.2025 15:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ‘‰ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐ข๐ฌ๐ง'๐ญ ๐ฃ๐ฎ๐ฌ๐ญ ๐š๐›๐จ๐ฎ๐ญ ๐ก๐š๐ฏ๐ข๐ง๐  ๐ฌ๐ญ๐ซ๐จ๐ง๐  ๐ฉ๐š๐ฌ๐ฌ๐ฐ๐จ๐ซ๐๐ฌ...

It's about understanding your users, risk profile, and regulatory requirements to implement the RIGHT security measures for each context.
And you? Do you use similar authentication/authorization methods like on the screen?

04.09.2025 07:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

What is the best tool to review public Entra ID Tenant data?

For me: AADInternals OSINT (site & PowerShell module)

We can get complete details about the tenant, including:
๐Ÿ‘‰ Tenant ID
๐Ÿ‘‰ Tenant Name (onmicrosoft domain)
๐Ÿ‘‰ Domains (all domains connected with tenant)
๐Ÿ‘‰ Brand name

#EntraID

11.04.2025 16:00 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Do you need to meet complicated password requirements?
Feel free to use a 60-character password.

PS> To improve security, I pasted it as a picture!

01.04.2025 12:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
A Comprehensive Overview of Our SSO Implementation Work efficiently with your Identity Provider: Entra ID and enable SSO for your applications (IAM and CIAM)

๐Ÿ’ฅ Blog Post Alert ๐Ÿ’ฅ
๐€ ๐‚๐จ๐ฆ๐ฉ๐ซ๐ž๐ก๐ž๐ง๐ฌ๐ข๐ฏ๐ž ๐Ž๐ฏ๐ž๐ซ๐ฏ๐ข๐ž๐ฐ ๐จ๐Ÿ ๐Ž๐ฎ๐ซ ๐’๐’๐Ž ๐ˆ๐ฆ๐ฉ๐ฅ๐ž๐ฆ๐ž๐ง๐ญ๐š๐ญ๐ข๐จ๐ง
Do you move from the SQL table with username & password?
Do you own more than one application?
Are you facing a sign-in screen all the time?

Check my blog post on how Sing Sign In works ๐Ÿš€
mjendza.net/post/sso/

#EntraID #SSO

28.03.2025 09:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ’ก ๐Œ๐ฒ ๐„๐ง๐ญ๐ซ๐š ๐„๐ฑ๐ญ๐ž๐ซ๐ง๐š๐ฅ ๐ˆ๐ƒ ๐€๐ซ๐œ๐ก๐ข๐ญ๐ž๐œ๐ญ๐ฎ๐ซ๐ž ๐Ÿ’ก

I recommend a couple of components:
๐Ÿ‘‰ Management API.
๐Ÿ‘‰ User Flows & Customization.
๐Ÿ‘‰ Entra ID as Code.
๐Ÿ‘‰ Profile as a central place to manage user details.
๐Ÿ‘‰ My demo application: Portal.

๐Ÿท๏ธ Extra: Verified ID for External ID tenant
#EntraID #CIAM

26.03.2025 08:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

A friendly reminder ;)
๐Ÿ‘‰ Use Fido2 keys
๐Ÿ‘‰ Use software passkey with your password managers
๐Ÿ‘‰ Verifiable Credentials can also be used as a passwordless method
๐Ÿš€ Passwordless is easier to use than complex long password

12.03.2025 17:27 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I checked my bank account history three times. The wire was not provided to me ;)

Link: www.ft.com/content/9921...

04.03.2025 07:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Entra External ID Token Enrichment Entra External ID Token Enrichment overview

mjendza.net/post/entra-e...

05.02.2025 07:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ‘‰Blog Post Alert

Discover how token enrichment can streamline your customer authentication processes and enhance security.
Explore how the Identity Platform can support your business needs and unlock new possibilities.

05.02.2025 07:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿš€I stopped using Visio, and other tools for:

๐Ÿ‘‰ Big Picture diagrams
๐Ÿ‘‰ Sequence Diagrams

And moved to PlantUML, creating all diagrams as code.

And you?

31.01.2025 07:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - microsoft/documentdb: DocumentDB offers a native implementation of document-oriented NoSQL database, enabling seamless CRUD operations on BSON data types within a PostgreSQL framework. DocumentDB offers a native implementation of document-oriented NoSQL database, enabling seamless CRUD operations on BSON data types within a PostgreSQL framework. - microsoft/documentdb

๐ŸŽ‰ pg_documentdb is open source

I created the initial version with Vinod Sridharan (an absolutely brilliant engineer) at Microsoft a few years ago and it's come a long way since.

It reimplements Mongo API with exact semantics in PostgreSQL. Already used by FerretDB!

github.com/microsoft/do...

23.01.2025 19:58 โ€” ๐Ÿ‘ 46    ๐Ÿ” 16    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

Simple & Amazing tool to stress your HTTP
github.com/codesenberg/...

PS> Are you ready to return 429 status code ๐Ÿค”

28.01.2025 17:54 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Next place where you can check the technical details for Verifiable Credentials: sandbox to play around with different business types and Data Model 1.1 and 2.0

#verifiablecdedentials #sandbox

vcplayground.org

23.01.2025 15:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Entra ID vs Entra External ID

๐Ÿ‘‰Do you know that there are two different tenant types?
๐Ÿ‘‰Do you know that there is a dedicated tenant for your customers? Were you fully separated from your organization?
#IAM #CIAM #EntraID

23.01.2025 06:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
LinkedIn This link will take you to a page thatโ€™s not on LinkedIn

๐Ÿ’ฅ If you're looking to dive deep into the Verifiable Credentials flow, this is the first place you should visit!

lnkd.in/dak5xidM

The diagrams in the article are amazing and provide a clear visual representation of the process.

#VerifiableCredentials #Identity #DigitalIdentity

22.01.2025 11:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Hello token friends, do you use the content of the access token as part of your application. Then be aware that Microsoft will switch to encrypted access token and this might break stuff.

Switch to id token. #EntraID

https://devblogs.microsoft.com/identity/access-tokens-and-id-tokens/

21.01.2025 18:30 โ€” ๐Ÿ‘ 16    ๐Ÿ” 11    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1
Post image

Magic Link? Three facts about:
#authentication #authorization #digitalidentity

20.01.2025 10:37 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ’ก With Verifiable Credentials

๐Ÿ‘‰ a full authorization flow for payments (I created a Factorlabs Bank Demo to show you the Business Case ๐Ÿช™

๐Ÿ‘‰also authorize access (also physical access) as a security guard ๐Ÿคต

Do you have any scenario with authentication and/or authorization scenarios?

18.01.2025 12:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - mivano/azure-cost-cli: CLI tool to perform cost analysis on your Azure subscription CLI tool to perform cost analysis on your Azure subscription - mivano/azure-cost-cli

I plan to test, maybe from the console it will be faster to get the same result
github.com/mivano/azure...

18.01.2025 11:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

My favourite 'Cost analysis' view is Group by resource with the Daily Granuariry:
- My workloads are 'stable' I don't have picks so monthly prediction can be based on a daily consumption
- Based on the diagram I can decide and move to another resource type to limit the cost of the solution

18.01.2025 11:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Need a Morse Code Translator?
Check morsecodetranslator.com also there is a GitHub repository :)
github.com/ozdemirburak...

Build your own Morse Translator ๐Ÿฅธ

#ItCanBeFun

18.01.2025 11:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
VC demo page

Demo for authentication: demo.factorlabs.pl
VC for Europeans github.com/goeIDAS/test...
Enable Entra Verified ID for your workforce or customer tenant: www.microsoft.com/en-us/securi...
check my blog post: mjendza.net/post/07-07-2...

18.01.2025 10:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Verifiable Credentials (VC) facts and cases:
- passwordless for your Identity Provider (authentication)
- a framework used by EIDAS to authorize via National ID
- coupons, gift cards
- authorize physical access and person-people verification
- with national ID can be a captcha verification

1/2

18.01.2025 10:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Solving Fine-Grained Authorization by Turning the Problem on its Head Build a high-performance policy engine with only a few lines of SQL.

Look at the blog post if you are thinking about the solution to speed up token enrichment with authorization data.

In my opinion many cases for 80% of calls the response is static (Pareto principal) and with a key-value store, we can deliver the response fast!

www.feldera.com/blog/fine-gr...

16.01.2025 07:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
DOOMยฎ CAPTCHA Prove you're human by playing DOOM

DOOM as captcha ๐Ÿ˜

One of the methods to protect your CIAM system from synthetic (for example fake accounts with 10 min mailbox) is the captcha system.

The best one is not involving you as a user to prove you are human.

But look this one is amazing ;)
doom-captcha.vercel.app

#CIAM #syntetic

11.01.2025 13:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - openwallet-foundation/credo-ts: Typescript framework for building decentralized identity and verifiable credential solutions Typescript framework for building decentralized identity and verifiable credential solutions - openwallet-foundation/credo-ts

๐Ÿฅธ VC Backend can based on Credo github.com/openwallet-f...
๐Ÿฅธ Wallet (Android and iOS) TrustBloc Wallet SDK github.com/trustbloc/wa...

10.01.2025 12:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@mjendza is following 19 prominent accounts