Whenever you are managing a Microsoft 365 environment, you regularly come across repetitive tasks: Creating new Intune policies Setting up users Retrieving security data … For all these tasks, Microsoft … Continue Reading An introduction into the Graph API
If you are working with Office 365, some organizations will have the requirement that Office 365 data is only available offline when users are using their company-provided devices. This means … Continue Reading AzureAD – Device not recognized as Hybrid Joined
When organizations are starting their journey to the cloud, they are most likely starting off by joining their Windows 10 machines to both their local Active Directory domain and Azure … Continue Reading Hybrid vs Azure AD Join
In one of my previous blogs, I already talked about the dangers of OAuth and why you should be managing these. Monitoring and managing OAuth applications is also possible with … Continue Reading Managing OAuth applications with MCAS
Last month, the combined MFA and password reset registration portal has been made generally available. Previously, a user could register his security information on two separate locations, for MFA and … Continue Reading Requiring two MFA methods with the Combined Registration
Microsoft Endpoint Manager (Intune) currently supports fours different Android Enterprise enrollment methods: Work Profile Dedicated Device Fully Managed Fully Managed Devices with Work Profile (Corporate Owned – Personally Enabled (COPE)) … Continue Reading Android Enterprise Dynamic Groups for Intune
Every Microsoft 365 Security engineer has the same struggle: maintaining corporate IP-address range needs to be done in two places. Once in trusted named locations in Azure AD and once … Continue Reading Sync Named Locations to MCAS IP Ranges using Azure Automation
Break The Glass or emergency accounts are a necessity in the cloud world we live today. Every year Azure AD goes down for a few hours because of some Multifactor … Continue Reading Best Practices for Emergency Accounts
Dynamic Groups in Azure AD are truly an amazing feature. It lets you manage a large group of users without the need to manually add every one of them in … Continue Reading Creating a dynamic group with all AAD Premium licensed users
During recent weeks, an increase in OAuth phishing attacks has been spotted. OAuth Phishing attacks are an evolution of the old phishing attacks we all know and hate. During a … Continue Reading Protecting against OAuth attacks: Setting-up Admin Consent Workflow
Last Thursday a new preview feature in Azure was announced for which I was very excited about: AAD Authentication to Windows/Linux VM’s on Azure. What? What does this mean exactly? … Continue Reading Azure AD Sign-in to an Azure VM
A while back Azure AD has announced Azure AD Security Defaults. Azure AD Security defaults is positioned as a baseline to harden the security of your Azure AD Tenant. Conditional … Continue Reading What is Azure AD Security Defaults & should you be using it?
Passwordless has been one of those buzzwords in 2019. So many articles and announcements have been made around it recently. First there was passwordless through the Microsoft Authenticator app. I … Continue Reading My thoughts on passwordless in AzureAD
I have been doing quite a few projects involving Hybrid Azure AD Join lately and have learnt a lot about it and how you should begin your troubleshooting journey. What … Continue Reading Troubleshooting Hybrid Azure AD Join
Checking the domain join type of a computer used to be easy (here was only one :)). We could to go to System Information pane of the Control Panel. Here … Continue Reading Checking the join method on a Windows 10 computers.
On the 19th of November Office365 Multifactor Authentication was down starting from 4.39 UTC until 19 UTC in almost all regions. This meant that users who have MFA enabled weren’t … Continue Reading Lessons learned from the O365 MFA Outage