How to add granular amr claims to your SAML apps in Entra ID
In my last post, I covered how Entra ID now automatically sends the amr and acr claims for Salesforce, so its phishing-resistant MFA check finally has…
Category
In my last post, I covered how Entra ID now automatically sends the amr and acr claims for Salesforce, so its phishing-resistant MFA check finally has…
I didn't know there was already a solution for this, and maybe you are looking for it too. I learned about this from the Blue Security Podcast.
I love Maester. No doubt about that. I've made several contributions to this open-source project before, but it took me a lot of effort to learn how the…
If you've been paying attention to the EEA sign-in changes over the past while, you'll know Microsoft started prompting users before reusing their Windows…
I don't have all the answers, but I promise to keep this post updated with all the details I find.
If you've been following the Salesforce phishing-resistant MFA (PRMFA) requirement story, you know the clock has been ticking. Salesforce has been pushing…
The other day, I was doing some research in my lab, and had to register a new passkey a couple of times. At some point, I stumbled upon the device code flow in…
Today, a quick post about setting up token lifetime policies in Entra ID. In some use cases, organizations require a short access token for highly privileged…
Application policies in Entra have been around for a while now to manage the use of secrets, but I don't see many folks using them. It's probably because…
Two new policies have been added to the recently introduced Application Policies in Entra ID!
Y'all know this song by the Beatles, right?