Entra
Things and stuff about Entra
-
Token Protection for Web Apps First Look and Wackiness
Remember the asterisk back in Part 1? Token Protection earned one in the mitigation table, right next to a note that it doesn’t do much for you in…
-
Agent Identities Are Not Service Principals
Head on over to your audit logs and filter the last 30 days on “Add service principal.” Some of those are not service principals. Microsoft Entra ID logs…
-
Breaking Up with Your IdP: A Practical Guide to De-Federating from Third-Party Identity Providers
It seems like weekly now, I’m being pulled into conversations with customers who want to “break up” with their third-party identity provider (IdP). And honestly? I don’t blame…
-
Conditional Access Boot Camp
Conditional Access is one of the best tools in your Microsoft environment for securing access. With it, you can control who, what, where, when, someone or something tries…
-
AiTM attack mitigation in M365 – Part 1
AiTM attacks have always been that annoying mosquito that just won’t go away. In 2025 and into 2026, that mosquito got a lot bigger. AiTM phishing attacks grew…
-
Why Scoping Phishing-Resistant MFA to the Admin Portal Isn’t Enough
Woohoo! You implemented phishing-resistant MFA for access to the admin portal. That’s great! But… did you actually improve your situation at all? It depends. Do you still have…
-
Guest Access in Entra ID: The Tenant’s Junk Drawer
Have you ever looked at your tenant, seen all the guest accounts, and had this reaction? Well, it’s not your fault…. Mostly. There are some default settings within…
-
Token Protection Conditional Access Won’t Save You From AiTM
A while back, Microsoft released a feature called Token Protection in Microsoft Entra ID. It’s a Conditional Access policy designed to help reduce token theft replay attacks, and…