<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on JanBakker.tech</title><link>https://janbakker.tech/categories/security/</link><description>Recent content in Security on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Tue, 29 Sep 2026 07:21:25 +0000</lastBuildDate><atom:link href="https://janbakker.tech/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>How to add granular amr claims to your SAML apps in Entra ID</title><link>https://janbakker.tech/how-to-add-granular-amr-claims-to-your-saml-apps-in-entra-id/</link><pubDate>Fri, 24 Jul 2026 08:18:03 +0000</pubDate><guid>https://janbakker.tech/how-to-add-granular-amr-claims-to-your-saml-apps-in-entra-id/</guid><description>&lt;p&gt;In my &#10;&lt;a href="https://janbakker.tech/entra-id-saml-authnmethodsreferences-amr-now-supports-phishing-resistant-mfa/"&gt;last post&lt;/a&gt;, I covered how Entra ID now automatically sends the &lt;code&gt;amr&lt;/code&gt; and &lt;code&gt;acr&lt;/code&gt; claims for Salesforce, so its phishing-resistant MFA check finally has something to check. That part is automatic, no config needed.&lt;/p&gt;&#10;&lt;p&gt;Every other SAML app doesn&amp;rsquo;t get that automatically. Per Microsoft&amp;rsquo;s own &#10;&lt;a href="https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims-reference#amr-values-for-microsoft-entra-authentication-methods" rel="noopener"&gt;optional claims reference&lt;/a&gt;, the app administrator still has to add the optional &lt;code&gt;amr&lt;/code&gt; claim, with the &lt;code&gt;include_granular_amr&lt;/code&gt; additional property, before &lt;code&gt;authnmethodsreferences&lt;/code&gt; shows up in the assertion at all.&lt;/p&gt;</description></item><item><title>Lock or sign-out when Yubikey is removed from the device</title><link>https://janbakker.tech/lock-or-sign-out-when-yubikey-is-removed-from-the-device/</link><pubDate>Tue, 21 Jul 2026 13:53:20 +0000</pubDate><guid>https://janbakker.tech/lock-or-sign-out-when-yubikey-is-removed-from-the-device/</guid><description>&lt;p&gt;I didn&amp;rsquo;t know there was already a solution for this, and maybe you are looking for it too. I learned about this from the &#10;&lt;a href="https://youtu.be/eXqW3FAY_hE?t=1632" rel="noopener"&gt;Blue Security Podcast&lt;/a&gt;.&lt;/p&gt;&#10;&lt;p&gt;Meet: &#10;&lt;a href="https://www.yubico.com/works-with-yubikey/catalog/sciber/#overview" rel="noopener"&gt;YubiKey Locker | Yubico&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;With YubiKey Locker, implement a protocol-agnostic security key removal policy that seamlessly integrates across various operating systems. This is important in meeting existing smart card customer security requirements (e.g. policies for smart card removal behavior), but also enables the forward-looking customer to bridge to modern protocols like FIDO2 passkeys, while staying compliant with their existing security policies. Moreover, the capability developed by Sciber enhances overall security posture for all organizations by locking the workstation or logging off the user when a YubiKey is not present, so it&amp;rsquo;s a great capability not only for those sunsetting legacy methods or form factors.&lt;/p&gt;</description></item><item><title>Writing Maester tests using AI - From idea to Pull Request</title><link>https://janbakker.tech/writing-maester-tests-using-ai-from-idea-to-pull-request/</link><pubDate>Tue, 21 Jul 2026 09:37:48 +0000</pubDate><guid>https://janbakker.tech/writing-maester-tests-using-ai-from-idea-to-pull-request/</guid><description>&lt;p&gt;I love &#10;&lt;a href="https://maester.dev" rel="noopener"&gt;Maester&lt;/a&gt;. No doubt about that. I&amp;rsquo;ve made several contributions to this open-source project before, but it took me a lot of effort to learn how the underlying structure worked as a non-developer, and this challenge can be hard for a lot of Entra or Microsoft 365 admins out there.&lt;/p&gt;</description></item><item><title>Admin control for SSO prompts in Windows; finally, an off switch!</title><link>https://janbakker.tech/admin-control-for-sso-prompts-in-windows-finally-an-off-switch/</link><pubDate>Thu, 16 Jul 2026 07:15:29 +0000</pubDate><guid>https://janbakker.tech/admin-control-for-sso-prompts-in-windows-finally-an-off-switch/</guid><description>&lt;p&gt;If you&amp;rsquo;ve been paying attention to the EEA sign-in changes over the past while, you&amp;rsquo;ll know Microsoft started prompting users before reusing their Windows credentials to sign in to other Microsoft apps and services. Good for user choice, less great if you&amp;rsquo;re an admin who just spent years getting SSO &lt;em&gt;working&lt;/em&gt; and now watches it ask permission every time.&lt;/p&gt;</description></item><item><title>Passkeys by default and retirement of Microsoft-provided SMS and voice authentication - A guide to stay calm</title><link>https://janbakker.tech/passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-a-guide-to-stay-calm/</link><pubDate>Tue, 14 Jul 2026 16:01:19 +0000</pubDate><guid>https://janbakker.tech/passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-a-guide-to-stay-calm/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;I don&amp;rsquo;t have all the answers, but I promise to keep this post updated with all the details I find.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;Microsoft dropped a bomb by announcing it will stop funding phone-based MFA, such as SMS and voice, and that passkeys will become the new standard.&lt;/p&gt;</description></item><item><title>Why Windows is the hardest passkey surface in 2026 and what Entra admins should expect</title><link>https://janbakker.tech/why-windows-is-the-hardest-passkey-surface-in-2026-and-what-entra-admins-should-expect/</link><pubDate>Mon, 06 Jul 2026 07:47:51 +0000</pubDate><guid>https://janbakker.tech/why-windows-is-the-hardest-passkey-surface-in-2026-and-what-entra-admins-should-expect/</guid><description>&lt;p&gt;&lt;em&gt;Written by: &#10;&lt;a href="https://www.corbado.com/about" rel="noopener"&gt;Corbado&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#10;&lt;p&gt;If you have rolled out passkeys to a mixed device fleet, you might have probably noticed the following pattern. Some users log in smoothly and barely create a ticket (e.g. iPhone users), while others, like Windows users, do. Behind runs the same identity provider, same policy, same relying party but the user experience with passkeys can be very different depending on the user’s setup.&lt;/p&gt;</description></item><item><title>Entra ID SAML authnmethodsreferences (AMR) now supports phishing-resistant MFA</title><link>https://janbakker.tech/entra-id-saml-authnmethodsreferences-amr-now-supports-phishing-resistant-mfa/</link><pubDate>Fri, 26 Jun 2026 14:12:37 +0000</pubDate><guid>https://janbakker.tech/entra-id-saml-authnmethodsreferences-amr-now-supports-phishing-resistant-mfa/</guid><description>&lt;p&gt;If you&amp;rsquo;ve been following the &#10;&lt;a href="https://help.salesforce.com/s/articleView?id=005321563&amp;amp;type=1" rel="noopener"&gt;Salesforce phishing-resistant MFA (PRMFA) requirement story&lt;/a&gt;, you know the clock has been ticking. Salesforce has been pushing organizations to enforce phishing-resistant MFA for Salesforce administrators. The tricky part? Until now, Microsoft Entra ID has not always sent enough information in the SAML assertion for Salesforce to verify &lt;strong&gt;how&lt;/strong&gt; the user authenticated, only that they authenticated.&lt;/p&gt;</description></item><item><title>Use Device Code Flow to register a passkey in Microsoft Authenticator App</title><link>https://janbakker.tech/use-device-code-flow-to-register-a-passkey-in-microsoft-authenticator-app/</link><pubDate>Wed, 13 May 2026 15:43:32 +0000</pubDate><guid>https://janbakker.tech/use-device-code-flow-to-register-a-passkey-in-microsoft-authenticator-app/</guid><description>&lt;p&gt;The other day, I was doing some research in my lab, and had to register a new passkey a couple of times. At some point, I stumbled upon the device code flow in the Microsoft Authenticator app. I was aware of this flow, but I suddenly realized how easy it is to create a new passkey on a rogue/remote device, using social engineering. &lt;strong&gt;One more reason to block it!&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Configurable token lifetimes in Entra ID</title><link>https://janbakker.tech/configurable-token-lifetimes-in-entra-id/</link><pubDate>Mon, 04 May 2026 14:01:00 +0000</pubDate><guid>https://janbakker.tech/configurable-token-lifetimes-in-entra-id/</guid><description>&lt;p&gt;Today, a quick post about setting up token lifetime policies in Entra ID. In some use cases, organizations require a short access token for highly privileged apps or resources. That said, this is probably &lt;strong&gt;NOT&lt;/strong&gt; needed for the typical apps we all use day-to-day.&lt;/p&gt;</description></item><item><title>Your service principals probably don't need secrets</title><link>https://janbakker.tech/your-service-principals-probably-dont-need-secrets/</link><pubDate>Mon, 20 Apr 2026 11:59:25 +0000</pubDate><guid>https://janbakker.tech/your-service-principals-probably-dont-need-secrets/</guid><description>&lt;p&gt;&#10;&lt;a href="https://janbakker.tech/no-your-nhis-cant-use-passwords-either/"&gt;Application policies&lt;/a&gt; in Entra have been around for a while now to manage the use of secrets, but I don&amp;rsquo;t see many folks using them. It&amp;rsquo;s probably because secrets are still widely used, and an unlimited lifetime for secrets results in less yelling from developers. Everyone&amp;rsquo;s happy. &lt;br&gt;&#10;&lt;br&gt;&#10;Yet, attackers love secrets and use them all the time. In obvious places, like app registrations, but &#10;&lt;a href="https://dirkjanm.io/azure-ad-privilege-escalation-application-admin/" rel="noopener"&gt;also on service principals&lt;/a&gt;, where you don&amp;rsquo;t expect them. You cannot see or add them in the UX, but they can be added via the Graph API.&lt;/p&gt;</description></item><item><title>Block or limit multi-tenant and consumer applications in Entra ID</title><link>https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/</link><pubDate>Wed, 15 Apr 2026 10:02:16 +0000</pubDate><guid>https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/</guid><description>&lt;p&gt;Two new policies have been added to the &#10;&lt;a href="https://janbakker.tech/no-your-nhis-cant-use-passwords-either/"&gt;recently introduced Application Policies&lt;/a&gt; in Entra ID!&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6.png"&gt;&#10; &lt;img src="https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6_hu_9bef35f8daf40e06.webp" srcset="https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6_hu_78ef44c695c45ff1.webp 720w, https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6_hu_9bef35f8daf40e06.webp 1400w" sizes="(max-width: 820px) 100vw, 780px" width="1400" height="821" alt="Screenshot from the article" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;&#10;&lt;p&gt;Admins can now restrict or block multi-tenant applications, and applications that support consumer sign-in (personal Microsoft accounts)&lt;/p&gt;</description></item><item><title>Conditional Access Optimization Agent knowledge base</title><link>https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/</link><pubDate>Sun, 15 Mar 2026 06:57:10 +0000</pubDate><guid>https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/</guid><description>&lt;p&gt;Y&amp;rsquo;all know this song by the Beatles, right?&lt;/p&gt;&#10;&lt;p&gt;&lt;em&gt;What would you think if I sang out of tune?&lt;br&gt;&#10;Would you stand up and walk out on me?&lt;br&gt;&#10;Lend me your ears, and I&amp;rsquo;ll sing you a song&lt;br&gt;&#10;And I&amp;rsquo;ll try not to sing out of key&lt;br&gt;&#10;&lt;br&gt;&#10;Oh, I get by with a little help from my friends&lt;br&gt;&#10;Mmm, I get high with a little help from my friends&lt;br&gt;&#10;Ooh, I&amp;rsquo;m gonna try with a little help from my friends&lt;/em&gt;&lt;/p&gt;</description></item><item><title>How to find unattested device-bound passkeys in Entra ID</title><link>https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/</link><pubDate>Mon, 09 Feb 2026 08:47:15 +0000</pubDate><guid>https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/</guid><description>&lt;p&gt;Attestation is an important topic in the context of device-bound passkeys. Seeing the creative work from &#10;&lt;a href="https://github.com/nathanmcnulty/nathanmcnulty/tree/main/Entra/passkeys/keyvault" rel="noopener"&gt;Nathan&lt;/a&gt;, &#10;&lt;a href="https://github.com/f-bader/TokenTacticsV2" rel="noopener"&gt;Fabian&lt;/a&gt;, and &#10;&lt;a href="https://lieben.nu/liebensraum/2026/02/silent-provisioning-of-fido-key-to-use-for-headless-requests-against-hidden-apis/" rel="noopener"&gt;Jos&lt;/a&gt; coming together, you might want to keep an eye on non-attested, device-bound passkeys in Entra ID.&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7.png"&gt;&#10; &lt;img src="https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7_hu_d40c6c6fcebbb7dd.webp" srcset="https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7_hu_e9ac3fd7834c84f3.webp 720w, https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7_hu_d40c6c6fcebbb7dd.webp 1400w" sizes="(max-width: 820px) 100vw, 780px" width="1400" height="695" alt="Screenshot showing the passkey attestation report" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;</description></item><item><title>The hidden risk of using aka.ms shortURLs for Microsoft portals</title><link>https://janbakker.tech/the-hidden-risk-of-using-aka-ms-shorturls-for-microsoft-portals/</link><pubDate>Fri, 06 Feb 2026 13:17:52 +0000</pubDate><guid>https://janbakker.tech/the-hidden-risk-of-using-aka-ms-shorturls-for-microsoft-portals/</guid><description>&lt;p&gt;We all love them: Microsoft&amp;rsquo;s short URLs at aka.ms. The &lt;strong&gt;aka.ms&lt;/strong&gt; domain is owned by Microsoft and is used to shorten URLs for many purposes. I even &#10;&lt;a href="https://aka.ms/janbakker" rel="noopener"&gt;got one&lt;/a&gt; myself that points to my MVP profile. They are usually pointing to &lt;em&gt;&lt;strong&gt;documentation&lt;/strong&gt;&lt;/em&gt;, which is fine, but they are also used for Entra or Microsoft 365-integrated portals. Just to name a few examples:&lt;/p&gt;</description></item><item><title>Jan's resource catalog to learn all about agents (from an Entra ID perspective)</title><link>https://janbakker.tech/jans-resource-catalog-to-learn-all-about-agents/</link><pubDate>Fri, 30 Jan 2026 07:35:22 +0000</pubDate><guid>https://janbakker.tech/jans-resource-catalog-to-learn-all-about-agents/</guid><description>&lt;p&gt;I&amp;rsquo;ve been digging into agents lately, especially the identity and security aspects. As this whole concept is quite new to all of us, it&amp;rsquo;s always hard to know where to start. Who got this thing figured out already? Who to follow? Who to ask questions?&lt;/p&gt;</description></item><item><title>Least privilege for Temporary Access Pass creation</title><link>https://janbakker.tech/least-privilege-for-temporary-access-pass-creation/</link><pubDate>Sun, 25 Jan 2026 14:15:32 +0000</pubDate><guid>https://janbakker.tech/least-privilege-for-temporary-access-pass-creation/</guid><description>&lt;p&gt;Today, giving out Temporary Access Passes for Microsoft 365 is a very common task. And attackers love them as well, since they bypass some security policies, including MFA. With Zero Trust in mind, we should always strive to use &amp;lsquo;&lt;em&gt;just-in-time&lt;/em&gt;&amp;rsquo; and &amp;lsquo;&lt;em&gt;just-enough&lt;/em&gt;&amp;rsquo; permissions. So whether you do this task manually or have it fully automated, both scenarios need to follow least privilege.&lt;/p&gt;</description></item><item><title>Access Azure Virtual Desktop and Windows 365 Cloud PC from non-managed devices</title><link>https://janbakker.tech/access-azure-virtual-desktop-and-windows-365-cloud-pc-from-non-managed-devices/</link><pubDate>Mon, 12 Jan 2026 13:10:56 +0000</pubDate><guid>https://janbakker.tech/access-azure-virtual-desktop-and-windows-365-cloud-pc-from-non-managed-devices/</guid><description>&lt;p&gt;Many organizations use Azure Virtual Desktop or Windows 365 Cloud PC. But how do we secure access to those resources? A very common use case is to connect from a non-managed device (BYOD). Then, from there, a user would have access to other resources, such as applications, email, and documents. The virtual workspace is managed, well-secured, and controlled by the organization, with end-users&amp;rsquo; (BYO) devices used as stepping stones.&lt;/p&gt;</description></item><item><title>How to enable passkeys for guest users in Entra ID</title><link>https://janbakker.tech/how-to-enable-passkeys-for-guest-users-in-entra-id/</link><pubDate>Fri, 19 Dec 2025 14:12:23 +0000</pubDate><guid>https://janbakker.tech/how-to-enable-passkeys-for-guest-users-in-entra-id/</guid><description>&lt;p&gt;Passkeys like FIDO security keys, synced passkeys, and passkeys in Microsoft Authenticator are secure and convenient authentication methods for your end users. They are phishing-resistant, passwordless, and enable fast sign-in to Microsoft 365 or other Entra ID-integrated apps.&lt;/p&gt;&#10;&lt;h2 id="the-issue"&gt;The issue&lt;a class="anchor" href="#the-issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Unfortunately, guest users who access your (resource) tenant with MFA enforced are unable to register a passkey, despite having it enabled or registered in their home tenant. This is also stated on &#10;&lt;a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2#guest-users" rel="noopener"&gt;Microsoft Learn&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Store your Microsoft 365 passkeys in 1Password</title><link>https://janbakker.tech/store-your-microsoft-365-passkeys-in-1password/</link><pubDate>Mon, 24 Nov 2025 20:04:37 +0000</pubDate><guid>https://janbakker.tech/store-your-microsoft-365-passkeys-in-1password/</guid><description>&lt;p&gt;Syncable passkeys in Microsoft 365 and Entra ID are here, so we are no longer limited to the Authenticator app and FIDO2 keys for storing passkeys. Passkeys can now be synced up &amp;ldquo;into the cloud&amp;rdquo;, so we can enjoy them on all our devices without the hassle of recovering each time we get a new phone or lose our YubiKey.&lt;/p&gt;</description></item><item><title>KB - Enable Single Sign On for Windows 365 Cloud PC</title><link>https://janbakker.tech/kb-enable-single-sign-on-for-windows-365-cloud-pc/</link><pubDate>Tue, 28 Oct 2025 20:00:18 +0000</pubDate><guid>https://janbakker.tech/kb-enable-single-sign-on-for-windows-365-cloud-pc/</guid><description>&lt;p&gt;This short tutorial explains how to enable Single Sign-On for Windows 365 Cloud PC using the Graph Explorer.&lt;/p&gt;&#10;&lt;p&gt;On Microsoft Learn, we can already find &#10;&lt;a href="https://learn.microsoft.com/en-us/windows-365/business/configure-single-sign-on" rel="noopener"&gt;instructions&lt;/a&gt; for using PowerShell, but I&amp;rsquo;m a big fan of using the Graph API and Graph Explorer.&lt;/p&gt;</description></item><item><title>Dynamic Conditional Access policies using custom security attributes</title><link>https://janbakker.tech/dynamic-conditional-access-policies-using-custom-security-attributes/</link><pubDate>Sun, 26 Oct 2025 15:17:48 +0000</pubDate><guid>https://janbakker.tech/dynamic-conditional-access-policies-using-custom-security-attributes/</guid><description>&lt;p&gt;Conditional Access policies can become very complex and quickly grow out of control. Custom requirements, exceptions, and edge cases often cause policy drift. In this blog post, I want to introduce a dynamic way to manage custom requirements for applications and resources that provides a flexible way to set access requirements without creating a Conditional Access policy per application or resource.&lt;/p&gt;</description></item><item><title>A public bug report for Entra ID application policies</title><link>https://janbakker.tech/a-public-bug-report-for-entra-id-application-policies/</link><pubDate>Mon, 20 Oct 2025 17:18:23 +0000</pubDate><guid>https://janbakker.tech/a-public-bug-report-for-entra-id-application-policies/</guid><description>&lt;p&gt;I&amp;rsquo;ve spent the last couple of nights trying out this new feature in Entra ID: application policies. I&amp;rsquo;ve already written two (&#10;&lt;a href="https://janbakker.tech/no-your-nhis-cant-use-passwords-either/"&gt;1&lt;/a&gt;,&#10;&lt;a href="https://janbakker.tech/a-closer-look-at-entra-application-policies-to-govern-secrets-and-certificates/"&gt;2&lt;/a&gt;) blog posts about it, but just when I thought I was done, here&amp;rsquo;s another finding that really blows my mind. Hear me out.&lt;/p&gt;</description></item><item><title>A closer look at Entra Application policies to govern secrets and certificates</title><link>https://janbakker.tech/a-closer-look-at-entra-application-policies-to-govern-secrets-and-certificates/</link><pubDate>Sat, 18 Oct 2025 08:12:33 +0000</pubDate><guid>https://janbakker.tech/a-closer-look-at-entra-application-policies-to-govern-secrets-and-certificates/</guid><description>&lt;p&gt;My &#10;&lt;a href="https://janbakker.tech/no-your-nhis-cant-use-passwords-either/"&gt;latest post&lt;/a&gt; on this topic introduced the new admin interface on Application Policies in Entra ID. Although the APIs had been around for a while, I personally didn&amp;rsquo;t see them being implemented at all. I believe the reason for that is the complexity of the API, in combination with the topic itself. Making sense of enterprise apps and app registrations is a complicated topic on its own. Add authentication and authorization into the mix, and you&amp;rsquo;ve got yourself a hot potato that nobody dares to keep in their hands for long.&lt;/p&gt;</description></item><item><title>Trigger Logic App on group membership changes in Entra ID</title><link>https://janbakker.tech/trigger-logic-app-on-group-membership-changes-in-entra-id/</link><pubDate>Sat, 11 Oct 2025 10:14:26 +0000</pubDate><guid>https://janbakker.tech/trigger-logic-app-on-group-membership-changes-in-entra-id/</guid><description>&lt;p&gt;A couple of years ago, I stumbled upon a neat Logic App / Power Automate connector that can respond to changes in group membership. &#10;&lt;a href="https://janbakker.tech/act-on-group-membership-changes-in-azure-active-directory/"&gt;Act on group membership changes in Azure Active Directory - JanBakker.tech&lt;/a&gt;&lt;br&gt;&#10;&lt;br&gt;&#10;Today, I&amp;rsquo;d like to give it some more love, since this is a very powerful, but underrated and probably also unknown piece of magic that will help you in a lot of automation scenarios. Especially when you are responsible for IAM Governance and lifecycle, but probably for a ton of other use cases.&lt;/p&gt;</description></item><item><title>No, your NHIs can't use passwords either!</title><link>https://janbakker.tech/no-your-nhis-cant-use-passwords-either/</link><pubDate>Mon, 22 Sep 2025 20:40:48 +0000</pubDate><guid>https://janbakker.tech/no-your-nhis-cant-use-passwords-either/</guid><description>&lt;p&gt;For human identities, going passwordless is becoming pretty standard these days. It looks like passkeys are getting some good traction, and more and more organisations are moving towards passwordless solutions for their workforce. &lt;br&gt;&#10;&lt;br&gt;&#10;But with the rise of NHI (non-human identities), it&amp;rsquo;s time to fight the battle of passwords in this corner of the field. If we look at Entra ID, a lot of applications and service principals are still relying on passwords, while other alternatives are left aside.&lt;/p&gt;</description></item><item><title>You shall not pass(key)! (updated)</title><link>https://janbakker.tech/you-shall-not-passkey-updated/</link><pubDate>Tue, 09 Sep 2025 12:19:56 +0000</pubDate><guid>https://janbakker.tech/you-shall-not-passkey-updated/</guid><description>&lt;p&gt;In a &#10;&lt;a href="https://janbakker.tech/things-you-should-know-before-rolling-out-device-bound-passkeys-in-microsoft-authenticator-app/"&gt;previous blog post&lt;/a&gt;, I briefly touched on all the current caveats involved with passkeys in Entra ID. One of the most raised questions is around the &lt;strong&gt;onboarding and recovery&lt;/strong&gt; of passkeys. So, in this blog post, we will dive deeper into the chicken-egg situation where you want to enforce passkeys for all resources, but none of your users have one registered. Here is where the &amp;ldquo;fun&amp;rdquo; begins.&lt;/p&gt;</description></item><item><title>Security Info Registration. Entra ID's rabbit hole.</title><link>https://janbakker.tech/security-info-registration-entra-ids-rabbit-hole/</link><pubDate>Fri, 29 Aug 2025 14:01:26 +0000</pubDate><guid>https://janbakker.tech/security-info-registration-entra-ids-rabbit-hole/</guid><description>&lt;p&gt;This blog post needs a brief introduction. Bear with me.&lt;/p&gt;&#10;&lt;p&gt;Five years ago, I spent a significant amount of time creating a blog post about the Combined Registration Wizard in Entra ID. It took many hours to capture the screenshots, as every change in the settings took 20 minutes to take effect. However, I&amp;rsquo;m glad I took that effort, because it has helped me to this very day.&lt;/p&gt;</description></item><item><title>KB - We detected that this particular key type has been blocked by your organization</title><link>https://janbakker.tech/kb-we-detected-that-this-particular-key-type-has-been-blocked-by-your-organization/</link><pubDate>Fri, 04 Jul 2025 13:12:13 +0000</pubDate><guid>https://janbakker.tech/kb-we-detected-that-this-particular-key-type-has-been-blocked-by-your-organization/</guid><description>&lt;p&gt;This is a knowledge base item. Hope it will help you someday.&lt;/p&gt;&#10;&lt;h2 id="issue"&gt;Issue&lt;a class="anchor" href="#issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;When you register a new passkey to Entra ID or Microsoft 365, an error is thrown:&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/kb-we-detected-that-this-particular-key-type-has-been-blocked-by-your-organization/image.png"&gt;&#10; &lt;img src="https://janbakker.tech/kb-we-detected-that-this-particular-key-type-has-been-blocked-by-your-organization/image_hu_f6ad5ac6ff0b4e2e.webp" srcset="https://janbakker.tech/kb-we-detected-that-this-particular-key-type-has-been-blocked-by-your-organization/image_hu_f6ad5ac6ff0b4e2e.webp 711w, https://janbakker.tech/kb-we-detected-that-this-particular-key-type-has-been-blocked-by-your-organization/image_hu_f6ad5ac6ff0b4e2e.webp 711w" sizes="(max-width: 820px) 100vw, 780px" width="711" height="325" alt="Screenshot 1 from KB - We detected that this particular key type has been blocked by your organization" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;</description></item><item><title>Poor man’s IGA: Generate Temporary Access Pass for joiners</title><link>https://janbakker.tech/poor-mans-iga-generate-temporary-access-pass-for-joiners/</link><pubDate>Tue, 10 Jun 2025 18:31:40 +0000</pubDate><guid>https://janbakker.tech/poor-mans-iga-generate-temporary-access-pass-for-joiners/</guid><description>&lt;p&gt;This post is part of the &amp;ldquo;Poor Man&amp;rsquo;s IGA&amp;rdquo; series. The idea is simple: we pick one feature from the &#10;&lt;a href="https://m365maps.com/files/Entra-ID-Governance.htm" rel="noopener"&gt;Entra ID Governance&lt;/a&gt; stack, and think of an alternative, cheap(er) way to get it done. Why?&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Every organization deserves proper IAM tools.&lt;/li&gt;&#10;&lt;li&gt;Entra ID Governance is excellent, but too expensive for most organisations.&lt;/li&gt;&#10;&lt;li&gt;Get the most out of your existing license and built-in features.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Most of all, making solutions as outlined in the post is like playing with LEGO. You will have different building blocks that can also be (re)used in other processes. Working with Logic Apps, managed identities, and Graph API will give you great flexibility to create your own creative solutions.&lt;/p&gt;</description></item><item><title>Poor man's IGA: Revoke all refresh tokens for user</title><link>https://janbakker.tech/poor-mans-iga-revoke-all-refresh-tokens-for-user/</link><pubDate>Wed, 04 Jun 2025 15:46:43 +0000</pubDate><guid>https://janbakker.tech/poor-mans-iga-revoke-all-refresh-tokens-for-user/</guid><description>&lt;p&gt;This post is part of the &amp;ldquo;Poor Man&amp;rsquo;s IGA&amp;rdquo; series. The idea is simple: we pick one feature from the &#10;&lt;a href="https://m365maps.com/files/Entra-ID-Governance.htm" rel="noopener"&gt;Entra ID Governance&lt;/a&gt; stack, and think of an alternative, cheap(er) way to get it done. Why?&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Every organization deserves proper IAM tools.&lt;/li&gt;&#10;&lt;li&gt;Entra ID Governance is excellent, but too expensive for most organisations.&lt;/li&gt;&#10;&lt;li&gt;Get the most out of your existing license and built-in features.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Most of all, making solutions as outlined in the post is like playing with LEGO. You will have different building blocks that can also be (re)used in other processes. Working with Logic Apps, managed identities, and Graph API will give you great flexibility to create your own creative solutions.&lt;/p&gt;</description></item></channel></rss>