<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Knowledgebase on JanBakker.tech</title><link>https://janbakker.tech/categories/knowledgebase/</link><description>Recent content in Knowledgebase on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Tue, 01 Sep 2026 07:01:49 +0000</lastBuildDate><atom:link href="https://janbakker.tech/categories/knowledgebase/index.xml" rel="self" type="application/rss+xml"/><item><title>KB - employeeLeaveDateTime show empty (null)</title><link>https://janbakker.tech/kb-employeeleavedatetime-show-empty-null/</link><pubDate>Mon, 06 Jul 2026 09:41:25 +0000</pubDate><guid>https://janbakker.tech/kb-employeeleavedatetime-show-empty-null/</guid><description>&lt;p&gt;This is a knowledge base item. I hope it will help you someday.&lt;/p&gt;&#10;&lt;h2 id="the-issue"&gt;The issue&lt;a class="anchor" href="#the-issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;When syncing the employeeLeaveDateTime attribute to Entra ID, the value shows &lt;strong&gt;null&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;In this example, I use Graph Explorer to check the value.&lt;/p&gt;</description></item><item><title>KB - Entra Private Access Session persistence</title><link>https://janbakker.tech/kb-entra-private-access-session-persistence/</link><pubDate>Wed, 08 Apr 2026 13:21:31 +0000</pubDate><guid>https://janbakker.tech/kb-entra-private-access-session-persistence/</guid><description>&lt;p&gt;This is a knowledge base item. I hope it will help you someday.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;p&gt;**Update:**This setting can also be set from the Entra admin center now.&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/kb-entra-private-access-session-persistence/image-22.png"&gt;&#10; &lt;img src="https://janbakker.tech/kb-entra-private-access-session-persistence/image-22_hu_987a4e9d137bbbe6.webp" srcset="https://janbakker.tech/kb-entra-private-access-session-persistence/image-22_hu_9ec4d6e944da1352.webp 720w, https://janbakker.tech/kb-entra-private-access-session-persistence/image-22_hu_987a4e9d137bbbe6.webp 1042w" sizes="(max-width: 820px) 100vw, 780px" width="1042" height="263" alt="Screenshot from the article" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;&#10;&lt;p&gt;It can be set under the Network access properties of the Enterprise Application.&lt;/p&gt;</description></item><item><title>Conditional Access Optimization Agent knowledge base</title><link>https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/</link><pubDate>Sun, 15 Mar 2026 06:57:10 +0000</pubDate><guid>https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/</guid><description>&lt;p&gt;Y&amp;rsquo;all know this song by the Beatles, right?&lt;/p&gt;&#10;&lt;p&gt;&lt;em&gt;What would you think if I sang out of tune?&lt;br&gt;&#10;Would you stand up and walk out on me?&lt;br&gt;&#10;Lend me your ears, and I&amp;rsquo;ll sing you a song&lt;br&gt;&#10;And I&amp;rsquo;ll try not to sing out of key&lt;br&gt;&#10;&lt;br&gt;&#10;Oh, I get by with a little help from my friends&lt;br&gt;&#10;Mmm, I get high with a little help from my friends&lt;br&gt;&#10;Ooh, I&amp;rsquo;m gonna try with a little help from my friends&lt;/em&gt;&lt;/p&gt;</description></item><item><title>KB - Enable Single Sign On for Windows 365 Cloud PC</title><link>https://janbakker.tech/kb-enable-single-sign-on-for-windows-365-cloud-pc/</link><pubDate>Tue, 28 Oct 2025 20:00:18 +0000</pubDate><guid>https://janbakker.tech/kb-enable-single-sign-on-for-windows-365-cloud-pc/</guid><description>&lt;p&gt;This short tutorial explains how to enable Single Sign-On for Windows 365 Cloud PC using the Graph Explorer.&lt;/p&gt;&#10;&lt;p&gt;On Microsoft Learn, we can already find &#10;&lt;a href="https://learn.microsoft.com/en-us/windows-365/business/configure-single-sign-on" rel="noopener"&gt;instructions&lt;/a&gt; for using PowerShell, but I&amp;rsquo;m a big fan of using the Graph API and Graph Explorer.&lt;/p&gt;</description></item><item><title>KB - Failed to verify domain name - Entra ID</title><link>https://janbakker.tech/kb-failed-to-verify-domain-name-entra-id/</link><pubDate>Sat, 11 Oct 2025 06:54:50 +0000</pubDate><guid>https://janbakker.tech/kb-failed-to-verify-domain-name-entra-id/</guid><description>&lt;p&gt;This is a knowledge base item. Hope it will help you someday.&lt;/p&gt;&#10;&lt;h2 id="the-issue"&gt;The issue&lt;a class="anchor" href="#the-issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;When adding a custom domain to Entra ID, you are unable to get it verified. The error:&lt;/p&gt;&#10;&lt;p&gt;&lt;em&gt;Unable to verify domain name. Ensure you have added the record above at the registrar for &amp;lsquo;yourdomain.com&amp;rsquo;, and try again in a little while. Click here for more information.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Security Info Registration. Entra ID's rabbit hole.</title><link>https://janbakker.tech/security-info-registration-entra-ids-rabbit-hole/</link><pubDate>Fri, 29 Aug 2025 14:01:26 +0000</pubDate><guid>https://janbakker.tech/security-info-registration-entra-ids-rabbit-hole/</guid><description>&lt;p&gt;This blog post needs a brief introduction. Bear with me.&lt;/p&gt;&#10;&lt;p&gt;Five years ago, I spent a significant amount of time creating a blog post about the Combined Registration Wizard in Entra ID. It took many hours to capture the screenshots, as every change in the settings took 20 minutes to take effect. However, I&amp;rsquo;m glad I took that effort, because it has helped me to this very day.&lt;/p&gt;</description></item><item><title>Viewing changes to Conditional Access policies just became easier!</title><link>https://janbakker.tech/viewing-changes-to-conditional-access-policies-just-became-easier/</link><pubDate>Mon, 12 Feb 2024 15:40:55 +0000</pubDate><guid>https://janbakker.tech/viewing-changes-to-conditional-access-policies-just-became-easier/</guid><description>&lt;p&gt;Today, a quick tip for all Entra admins out there. Conditional Access policies can be subject to change. When a policy is changed, its not very easy to see what changed. From the audit logs, this is how it looks:&lt;/p&gt;</description></item><item><title>Microsoft icons</title><link>https://janbakker.tech/microsoft-icons/</link><pubDate>Fri, 19 May 2023 08:26:07 +0000</pubDate><guid>https://janbakker.tech/microsoft-icons/</guid><description>&lt;p&gt;That&amp;rsquo;s the post for today. Just a bunch of sources with icons from Microsoft 365, Azure, Azure AD, and other Microsoft-related services. This can be super handy if you need high-quality images for your excellent slides and documentation. Enjoy!&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Do you have a source to add? Drop me an email! Happy to keep this list going.&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>KB - Write requests (excluding DELETE) must contain the Content-Type header declaration.</title><link>https://janbakker.tech/kb-write-requests-excluding-delete-must-contain-the-content-type-header-declaration/</link><pubDate>Wed, 21 Sep 2022 18:32:41 +0000</pubDate><guid>https://janbakker.tech/kb-write-requests-excluding-delete-must-contain-the-content-type-header-declaration/</guid><description>&lt;p&gt;This is a knowledgebase item. I hope it helps you out someday.&lt;/p&gt;&#10;&lt;h2 id="the-issue"&gt;The issue&lt;a class="anchor" href="#the-issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;When using the HTTP action in Power Automate or Logic Apps in combination with Graph API, you get the following error:&lt;/p&gt;&#10;&lt;p&gt;&lt;em&gt;Write requests (excluding DELETE) must contain the Content-Type header declaration.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>KB - mobile phone number not in sync Azure AD Connect</title><link>https://janbakker.tech/kb-mobile-phone-number-not-in-sync-azure-ad-connect/</link><pubDate>Sun, 01 May 2022 15:47:20 +0000</pubDate><guid>https://janbakker.tech/kb-mobile-phone-number-not-in-sync-azure-ad-connect/</guid><description>&lt;p&gt;This is a knowledgebase item. Hope it helps you out someday.&lt;/p&gt;&#10;&lt;h2 id="the-issue"&gt;The issue&lt;a class="anchor" href="#the-issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Some users reported that the mobile phone number in Azure Active Directory / Office 365 was different from the number in on-prem Active Directory. Even though these users were synced with Azure AD Connect, the mobile phone attribute was no longer in sync.&lt;/p&gt;</description></item><item><title>KB - SelfServicePasswordReset write-back problem - error hr=80230818</title><link>https://janbakker.tech/kb-selfservicepasswordreset-write-back-problem-error-hr80230818/</link><pubDate>Mon, 21 Feb 2022 14:06:19 +0000</pubDate><guid>https://janbakker.tech/kb-selfservicepasswordreset-write-back-problem-error-hr80230818/</guid><description>&lt;p&gt;This is a knowledgebase item. Hope it helps you out someday.&lt;/p&gt;&#10;&lt;p&gt;Now, since you landed on this page, I assume you&amp;rsquo;ve got the following issue:&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;Azure AD SelfService Password Reset worked like a charm for quite some time.&lt;/li&gt;&#10;&lt;li&gt;All of the sudden it stopped working, and you have no idea why. You have checked the permissions on the service account, and all looks good.&lt;/li&gt;&#10;&lt;li&gt;You are in a hybrid setup, and use password write back. All checkmarks are green.&lt;/li&gt;&#10;&lt;li&gt;Azure AD audit logs contain OnPremisesAdminActionRequired or ADAdminActionRequired as failure.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;Your users are prompted with this error when trying to do a password reset using Azure AD Self Service Password Reset Portal.&lt;/p&gt;</description></item><item><title>ADMX ingestion for Centero Agent and Carillon Client using Intune</title><link>https://janbakker.tech/admx-ingestion-for-centero-agent-and-carillon-client-using-intune/</link><pubDate>Sun, 20 Feb 2022 20:29:23 +0000</pubDate><guid>https://janbakker.tech/admx-ingestion-for-centero-agent-and-carillon-client-using-intune/</guid><description>&lt;p&gt;This article is about the ADMX templates for Centero Agent and Carillon client, that you can use to configure the settings on your endpoints. Microsoft Endpoint Manager (Intune) is capable of ADMX ingestion, but this process can be complex sometimes. This article will explain the ADMX ingestion and has a couple of examples, on how to handle various settings.&lt;/p&gt;</description></item><item><title>KB - Add account operation is blocked by policy on the device</title><link>https://janbakker.tech/kb-add-account-operation-is-blocked-by-policy-on-the-device/</link><pubDate>Sat, 02 Oct 2021 05:35:28 +0000</pubDate><guid>https://janbakker.tech/kb-add-account-operation-is-blocked-by-policy-on-the-device/</guid><description>&lt;p&gt;This is a knowledgebase item. Hope it helps you out someday.&lt;/p&gt;&#10;&lt;h2 id="error"&gt;Error&lt;a class="anchor" href="#error" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Add work or school account in Windows 10 or 11 fails with this message: &amp;ldquo;add account operation is blocked by policy on the device&amp;rdquo;. Error code: CAA50101&lt;/p&gt;</description></item></channel></rss>