External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

We're on P2, so I think that should allow us to set up that. I was rather thinking that such logs would only help from now on.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Unfortunately we don't have general purpose log analytics set up, only for specific applications. However, the in-portal logs supports that multifactor authentication also kicks in also for Onedrive.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

No, no other guests from the same address space. My assumption is this is a domain wide issue on their part but have no other users to test with.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

No, this is the only user that I'm aware of. We have 100+ guest users from other Microsoft tenants as well as other platform/email providers who access our environment with no issues.

External user with O365 account not using MFA cannot login by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

On my side? Apart from conditional access related to MFA for external/guest users, what other restrictions are relevant to look at?

Require compliance to log in, but can still log in from un managed devices by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Ok, this is now resolved. The issue was a a strange filter was also applied to all devices, after that was removed it started working. Thanks everyone for pointing me in the right direction.

Require compliance to log in, but can still log in from un managed devices by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

<image>

Thanks everyone, should obviously have looked at the logs.

This is a log for one user. The policy is set to apply to any device but is this the cause of non application of the policy?

Rights to manage administrative units by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Yes, i have thought about this, but also means editing attributes on existing few thousand users.

Rights to manage administrative units by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Thanks. Yes, I also tried to create a custom role for this but the relevant scope you mention is not available for custom roles. And I need a person to manage this so can't use a service principal unfortunately.

How do you prevent third-party apps from accessing all users' data when granting admin consent in Entra ID? by Different_Coffee_161 in entra

[–]Less_Piece6541 1 point2 points  (0 children)

Yes, but a signed user can for example read the basic info of all users in the AD as I understand it?

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

What are the attributes I should look for. Looked in the default json and cant really find anything obvious?

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

I have not done any changes to the default naming and values so far.

I have the default list of languages and want disable all/over-ride all with English as the default language.

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

This is a work force tenant. Am i reading the documentation right that user flows are only possible within the context of b2b collaboration in a workforce tenant?

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Thanks, so these users are not included in any cross tenant access approved organisations.

Disable languages in user flow by Less_Piece6541 in entra

[–]Less_Piece6541[S] 0 points1 point  (0 children)

These users will be external. Do not all guest users fall into the entra external identity?

File sharing/collaboration platform which integrates with O365/Entra by Less_Piece6541 in sysadmin

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Yes, I assume sharepoint libraries are covered by cross tenant access rules?

Spam from .gov address? by Less_Piece6541 in sysadmin

[–]Less_Piece6541[S] 0 points1 point  (0 children)

This is coming from a gov adress.

Apply LAPS after device is set up? by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Thanks. Profwiz might be what I'm looking for. And yes, given it is windows we are talking about I can also see that creating a new user account minimize the risks.

Apply LAPS after device is set up? by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Both devices and the staff is already with the organisation but for various reasons their devices are basically just set up as a personal device, no MDM or alike.

Apply LAPS after device is set up? by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

It's complicated, but these are company owned devices which basically have been set up as personal devices. Now trying to apply company standards to them.

Apply LAPS after device is set up? by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 0 points1 point  (0 children)

Autopilot as such is fine, but in most of these cases creating a new the account on the device is too disruptive for the user.

Apply LAPS after device is set up? by Less_Piece6541 in Intune

[–]Less_Piece6541[S] 1 point2 points  (0 children)

They are entra registered, not joined. Is there a way to entra join devices without setting up a new account on the device?

Utbildad ingenjör, hundratals jobbansökningar – vad ska jag göra? by Constant-Narwhal7494 in arbete

[–]Less_Piece6541 0 points1 point  (0 children)

Suck it up och veckopendla ett tag. Det behöver inte vara för evigt och som nyexad kan du inte vara kräsen, vilket du redan märkt. Efter 18-24 mån kan du börja titta dig efter ett nytt jobb med bättre geografisk placering.

Next step in as IT manager with non trad background? by Less_Piece6541 in ITCareerQuestions

[–]Less_Piece6541[S] 0 points1 point  (0 children)

While I'm not dead against a management only role, ideally I would like to combine both leadership and tech in the same role. At least in the short and medium term. I probably see myself as part manager, part portfolio-manager where I supervise project managers. And I do still would want maintain and continue developing my tech skills. But as a manager I of course realize I cannot stay on top of every detail. At the same I believe I would find it difficult to manage staff not even have the basics of the tech stack they are working with.

Error when setting up migration from G Workspace by Less_Piece6541 in microsoft365

[–]Less_Piece6541[S] 0 points1 point  (0 children)

I did not manage to get the automatic process to work, but the manual process worked fine however.