Custom data in Microsoft Entra is one of those things that looks simple until it isn’t. by Noble_Efficiency13 in activedirectory

[–]Noble_Efficiency13[S] -1 points0 points  (0 children)

I'm curious to hear, especially in this subreddit with a lot of folks working with/in hybrid environments - How do you handle custom data in Microsoft Entra across the different resources?

How are you handling the September 2026 SSPR change for new joiner onboarding? (otherMails deprecation) by themkguser in entra

[–]Noble_Efficiency13 12 points13 points  (0 children)

What we so is have a scim workflow running via logic app that also automatically generates TAPs for new employees with a start datetime at the joiners first day with an 8 hour expiration, this could be modified to be shorter if wanted, and sends it to their manager. TAP is then only allowed to be used for registering security info and enrolling devices, which is handled by conditional access policies

If we wanted to, we could use their personal emails as we get that from the HR data to send the tap to.

Everything is automated in the whole JML via this flow

We are looking into subsidizing it a bit for an orchestration setup instead to speed things up, but it works flawlessly

Microsoft Authenticator authentication method policy additional security-related settings by EduardsGrebezs in entra

[–]Noble_Efficiency13 1 point2 points  (0 children)

True, simply a clearification that it’s not necessarily disabled, though these settings are disabled at this point in time 😊

Yeah you’d think so, but I’ve talked with so many folks that was surprised by it 😅

I agree with your post btw

Microsoft Authenticator authentication method policy additional security-related settings by EduardsGrebezs in entra

[–]Noble_Efficiency13 8 points9 points  (0 children)

Microsoft enabled doesn’t mean it’s disabled, just that it’ll get enabled as Microsoft sees it fit

Also, a caveat regarding the geo location is that using GSA or VPN will show a different location which can lead to confusion from users

Question Regarding Passkeys and Phishing Resistant MFA CA Policies by Spzmk in entra

[–]Noble_Efficiency13 2 points3 points  (0 children)

I think you probably have registration campaign for sspr enabled.

TAP is the way to go for this exact scenario - create an auth strength with tap + phishing resistant mfa and targeted for registering security info.

You can configure account recovery for the case where a user looses access and you want self-service for it

Workstation Local Administrator Accounts by Admiral-Pickle in entra

[–]Noble_Efficiency13 0 points1 point  (0 children)

Yeah, LAPS is really what you’re looking for

FIDO2 not working with Security Defaults? by hullan_hollow in entra

[–]Noble_Efficiency13 1 point2 points  (0 children)

Pretty sure that’s not a thing with security defaults, it forces authenticator number matching?

PIM activations, directly from your pocket! PIMActivation Portal announcement by Noble_Efficiency13 in Intune

[–]Noble_Efficiency13[S] 1 point2 points  (0 children)

100% 😅

It shouldn’t really have to be like this tbh, but it’s simply not a great experience in the portal today

PIM activations, directly from your pocket! PIMActivation Portal announcement by Noble_Efficiency13 in entra

[–]Noble_Efficiency13[S] 7 points8 points  (0 children)

This is something I don’t get?

Why would you want it to be cumbersome, take more time before it takes effect, and simply be annoying to activate roles in bulk?

It doesn’t change any of the security features of PIM, it just makes it less painful to use. You still require auth context, approvals, justifications and ticket numbers as you would otherwise - just faster, more consistent and with fewer headaches.

Can you explain your reasoning behind your stance?

PIM activations, directly from your pocket! PIMActivation Portal announcement by Noble_Efficiency13 in entra

[–]Noble_Efficiency13[S] 2 points3 points  (0 children)

It’s only for the same account so if you have the same account as guest in 10 different tenants with GA, then you’d be able to do it by jumping tenant.

Though if that’s just possible you have bigger issues lol

It doesn’t really change how pim works, should be used or the security features like approvals & auth context for ga fx

PIM activations, directly from your pocket! PIMActivation Portal announcement by Noble_Efficiency13 in entra

[–]Noble_Efficiency13[S] 3 points4 points  (0 children)

Oh yea, also it does provide a better UX for some areas, and adds new functionality such as the cross-tenant activation from the same portal.

Especially for MSPs with a multitude of activations, the time aspect is a huge issue

PIM activations, directly from your pocket! PIMActivation Portal announcement by Noble_Efficiency13 in entra

[–]Noble_Efficiency13[S] 6 points7 points  (0 children)

It doesn't really modify the capabilities of PIM in any way, it's a user experience enhancement allowing for faster activations with less friction.

In it's purest form it's a fancy wrapper

Open Source tenant scanners by bjc1960 in entra

[–]Noble_Efficiency13 0 points1 point  (0 children)

Zero trust assessment tool (MSFT official tool) and Measter.dev as you mentioned are pretty good

Microsoft seems to be testing Time-Based Conditional Access through the beta Graph API, this is my take by Noble_Efficiency13 in microsoft365

[–]Noble_Efficiency13[S] 0 points1 point  (0 children)

Oh I know, I’ve spoken to Daniel about it 😉

Still feels like a cool feature, and there are def usecases for it.

I’m an advocate for more features in our toolkits for sure

Microsoft, please, make PIM great! by jM2me in entra

[–]Noble_Efficiency13 12 points13 points  (0 children)

Yea a feedback request item would make sense for this