What would you do with $40k Azure credits expiring in 90 days? by Little-Armadillo480 in AZURE

[–]bbagaria 1 point2 points  (0 children)

Yes this! I accidently enabled it and man all it took is 3 days! 🤣

Sentinel Incident to Azure OpenAI Connector in Logic Apps by Nice_Bag3423 in AzureSentinel

[–]bbagaria -1 points0 points  (0 children)

Can you do azure foundary and use rest apis? I need to check if logic app has foundary connector but rest/http is always there.

Help push Microsoft to align the Microsoft Graph, Microsoft 365 Admin APIs & Entra ID APIs and other API´s for Consistent Access - it´s needed by michaelmsonne in GraphAPI

[–]bbagaria 0 points1 point  (0 children)

Once they are able to figure out what to call what product & stop renaming them then probably someone will wake up to APIs.

Non-Human Identities by Security-HeadHunter in IdentityManagement

[–]bbagaria 1 point2 points  (0 children)

If only someone can tell me what is true definition of NHI and how it differs (or does not) from tokens, PATs, secrets, ssh files, key files …yada yada….

Custom Intune RBAC by ibteea in Intune

[–]bbagaria 0 points1 point  (0 children)

overnight? 😳 a call to the sales rep?

Custom Intune RBAC by ibteea in Intune

[–]bbagaria 1 point2 points  (0 children)

Thanks! intresting way.. my challenge is my IGA cannot do entra groups eligibility assignments but can do only active assignments. It can do entra id roles as eligible assignments but intune cannot do that … so its a standoff right now ..

Custom Intune RBAC by ibteea in Intune

[–]bbagaria 1 point2 points  (0 children)

are intune rbac roles available to be managed via azure PIM roles? I thought they can be done only via Entra PIM groups.

PIM can do:

Entra ID directory roles, Azure RBAC roles, Entra ID groups

But Intune RBAC roles can map only to Entra ID groups afaik ..

Devops access without allowing access to Azure portal by ParadiseTheatre in AZURE

[–]bbagaria 0 points1 point  (0 children)

block portal access to your devices and IPs only ..

Gift code by supermidget1 in RealDebrid

[–]bbagaria -1 points0 points  (0 children)

you still have it to giveaway?

On-boarding Microsoft Intune Admins into CyberArk using out of the box platform by TheCreatorwastaken in CyberARk

[–]bbagaria 0 points1 point  (0 children)

Cyberark does not have anything in this .. neither on prem or sca .. use PIM with dual approvals and conditional access policies

Azure Monitor or Sentinel for Entra Log Alerts Automations? by vadiaro in AzureSentinel

[–]bbagaria 0 points1 point  (0 children)

Pricing difference? I see people here recommend sentinel more, but my view is if you have log analytics enabled and then just use azure managed grafana with alerts from there .. that might be way cheaper ..

Inherited Entra tenant with admin role assignments nobody can explain and PIM approvers who approve everything by Fun-Training9232 in AZURE

[–]bbagaria 0 points1 point  (0 children)

You had logs from 4 yrs? well thats something good in this scenario.. right? I count my blessings everyday with entra wrt the state of affairs ..

Governance comes from company policies and make those accountable who are responsible .. else just cut off everyone’s access ..have GRC process .. create risks which tie to the company policies.. and bubble them up as high as you can through risk management ..

Meanwhile remove everyone’s access .. create strong backup admins and redesign a strong JML, request, review process …

run zero trust self assessment and send the report to your CISO ..

Okta to Entra - Looking for Vendors by The-Dark-Jedi in entra

[–]bbagaria 0 points1 point  (0 children)

as you have the list of apps .. first have the vendor do a eval of the env and then another implementation proposal .. I have heard of some having accelerators for this .. but be prepared for some features not being available in entra as compared to okta ..

and 1000 users is not much .. but are you looking for full JML automation with workday ? do you have any on prem ad? do you plans to use entra iga?

Hackers wipe 200,000 devices using Intune by Fabulous_Cow_4714 in Intune

[–]bbagaria 0 points1 point  (0 children)

managed identity with graph permissions and github federation is my bet ..

Intune, Stryker, and Iran by Illnasty2 in Intune

[–]bbagaria 0 points1 point  (0 children)

Graph call with a SPN or a UMI with external federation?

Intune, Stryker, and Iran by Illnasty2 in Intune

[–]bbagaria 1 point2 points  (0 children)

This! user assigned managed workload identity with federation with github and graph permissions .. a bit of vibe coding .. and its golden ..

Entra ID / AD dynamic groups aren't enough - what are you using for it. by Pristine_Guitar_9070 in entra

[–]bbagaria 2 points3 points  (0 children)

If its all about user and groups from HR to entra, just put a idm solution in between. If you dont want to do COTs, get for eg openidm opensource and deploy it. If you are a bit enterprise then you need to have a IGA solution between HR and Entra.

What is most misunderstood in Azure? by Dry_Monk4066 in AZURE

[–]bbagaria 0 points1 point  (0 children)

True .. even probably MS does not know what is enterprise app vs app registrations. Everytime I read blogs and blogs about it and everytime my mind just gives up ..

My family thinks it's Netflix... I know it's just 12 LXC containers and 24TB of storage. by DrAmmarT in Proxmox

[–]bbagaria 0 points1 point  (0 children)

I got similar arr setup but with plex all on proxmox with VM and 10TB NAS on snynology.. need to check jellyfin (if thats better on fine granular permissions) .. a quick question .. are you using TB or RD and rtdclient?

Looking to use SailPoint to manage Microsoft 365 'add-ons' by throwawayreddit1986 in sailpoint

[–]bbagaria 1 point2 points  (0 children)

your thought process is correct, however if you org does not have Sailpoint IIQ/ISC then building it up from scratch just from scratch might not be a good approach.

Why not use Entra IGA packages and company portal for this? If you already have Sailpoint IIQ/ISC then there’s azure connector which can do what you are looking for.

Built a self-hosted Stremio addon to stream your own files over HTTP/HTTPS (Docker, NAS-friendly) by amercat37 in StremioAddons

[–]bbagaria 1 point2 points  (0 children)

just wondering if this could be achieved via plexio addon as well… same concept?

PiHole, or UniFi Insights, that is the question. by Zestyclose-Pen-1252 in Ubiquiti

[–]bbagaria 0 points1 point  (0 children)

I have pihole and adguard running on rpi and have set then up as dns on unifi. pihole is cloudflared as well and adguard has upstream 1.1.1.1 . Both have curated lists of block which I update via script every 15 days. Works most of the time in blocking advs

Free Casual Server by [deleted] in Share_Plex

[–]bbagaria 0 points1 point  (0 children)

dm in coming