<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on JanBakker.tech</title><link>https://janbakker.tech/posts/</link><description>Recent content in Posts on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Tue, 29 Sep 2026 07:21:25 +0000</lastBuildDate><atom:link href="https://janbakker.tech/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Where to store your Microsoft 365 passkey?</title><link>https://janbakker.tech/where-to-store-your-microsoft-365-passkey/</link><pubDate>Fri, 25 Sep 2026 16:00:51 +0000</pubDate><guid>https://janbakker.tech/where-to-store-your-microsoft-365-passkey/</guid><description>&lt;p&gt;Microsoft 365 (Entra ID) has supported passkeys for a long time now. From auto-registered passkeys like Windows Hello to synced passkeys.&lt;/p&gt;&#10;&lt;p&gt;I&amp;rsquo;ve created this tool to quickly see the current capabilities, to use for conversations with colleagues or customers. I try to keep the page current as features will be added or change. I will also expand the subpages with relevant context, risk considerations, dependencies, limitations, user experience, and caveats.&lt;/p&gt;</description></item><item><title>Entra ID telephony providers for SMS and voice MFA: first look</title><link>https://janbakker.tech/entra-id-telephony-providers-for-sms-and-voice-mfa-first-look/</link><pubDate>Fri, 25 Sep 2026 06:58:46 +0000</pubDate><guid>https://janbakker.tech/entra-id-telephony-providers-for-sms-and-voice-mfa-first-look/</guid><description>&lt;h2 id="what-was-announced"&gt;What was announced&lt;a class="anchor" href="#what-was-announced" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Microsoft has published the first documentation for &lt;strong&gt;Choose Your Own Telephony Provider&lt;/strong&gt; in Entra ID, together with &#10;&lt;a href="https://learn.microsoft.com/en-us/entra/identity/authentication/phone-providers-faq" rel="noopener"&gt;an FAQ&lt;/a&gt; that might answer some of your questions. It is the answer to one question many of us have been asking: what happens to users who really need SMS or voice MFA once Microsoft stops delivering those messages itself?&lt;/p&gt;</description></item><item><title>Finally a smooth(er) passkey onboarding experience in Microsoft 365!</title><link>https://janbakker.tech/finally-a-smoother-passkey-onboarding-experience-in-microsoft-365/</link><pubDate>Mon, 14 Sep 2026 15:35:23 +0000</pubDate><guid>https://janbakker.tech/finally-a-smoother-passkey-onboarding-experience-in-microsoft-365/</guid><description>&lt;p&gt;Microsoft is doing a lot to enhance the onboarding of passkeys. The three major changes behind this are:&lt;/p&gt;&#10;&lt;p&gt;&#10;&lt;a href="https://mc.merill.net/message/MC1450133" rel="noopener"&gt;MC1450133 - Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;&#10;&lt;a href="https://mc.merill.net/message/MC1440968" rel="noopener"&gt;MC1440968 - Microsoft Entra ID: Optimizations for passkey registration experience&lt;/a&gt;&lt;/p&gt;</description></item><item><title>How to create a Microsoft 365 device-bound passkey on macOS</title><link>https://janbakker.tech/how-to-create-a-microsoft-365-device-bound-passkey-on-macos/</link><pubDate>Sat, 22 Aug 2026 06:36:58 +0000</pubDate><guid>https://janbakker.tech/how-to-create-a-microsoft-365-device-bound-passkey-on-macos/</guid><description>&lt;p&gt;I did a discovery today, and I want to share it, because I did not know this was an option. Up until now, I always thought that device-bound passkeys where limited to Windows Hello for Business, FIDO2 security keys, and the Microsoft Authenticator App.&lt;/p&gt;</description></item><item><title>How to add granular amr claims to your SAML apps in Entra ID</title><link>https://janbakker.tech/how-to-add-granular-amr-claims-to-your-saml-apps-in-entra-id/</link><pubDate>Fri, 24 Jul 2026 08:18:03 +0000</pubDate><guid>https://janbakker.tech/how-to-add-granular-amr-claims-to-your-saml-apps-in-entra-id/</guid><description>&lt;p&gt;In my &#10;&lt;a href="https://janbakker.tech/entra-id-saml-authnmethodsreferences-amr-now-supports-phishing-resistant-mfa/"&gt;last post&lt;/a&gt;, I covered how Entra ID now automatically sends the &lt;code&gt;amr&lt;/code&gt; and &lt;code&gt;acr&lt;/code&gt; claims for Salesforce, so its phishing-resistant MFA check finally has something to check. That part is automatic, no config needed.&lt;/p&gt;&#10;&lt;p&gt;Every other SAML app doesn&amp;rsquo;t get that automatically. Per Microsoft&amp;rsquo;s own &#10;&lt;a href="https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims-reference#amr-values-for-microsoft-entra-authentication-methods" rel="noopener"&gt;optional claims reference&lt;/a&gt;, the app administrator still has to add the optional &lt;code&gt;amr&lt;/code&gt; claim, with the &lt;code&gt;include_granular_amr&lt;/code&gt; additional property, before &lt;code&gt;authnmethodsreferences&lt;/code&gt; shows up in the assertion at all.&lt;/p&gt;</description></item><item><title>Lock or sign-out when Yubikey is removed from the device</title><link>https://janbakker.tech/lock-or-sign-out-when-yubikey-is-removed-from-the-device/</link><pubDate>Tue, 21 Jul 2026 13:53:20 +0000</pubDate><guid>https://janbakker.tech/lock-or-sign-out-when-yubikey-is-removed-from-the-device/</guid><description>&lt;p&gt;I didn&amp;rsquo;t know there was already a solution for this, and maybe you are looking for it too. I learned about this from the &#10;&lt;a href="https://youtu.be/eXqW3FAY_hE?t=1632" rel="noopener"&gt;Blue Security Podcast&lt;/a&gt;.&lt;/p&gt;&#10;&lt;p&gt;Meet: &#10;&lt;a href="https://www.yubico.com/works-with-yubikey/catalog/sciber/#overview" rel="noopener"&gt;YubiKey Locker | Yubico&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;With YubiKey Locker, implement a protocol-agnostic security key removal policy that seamlessly integrates across various operating systems. This is important in meeting existing smart card customer security requirements (e.g. policies for smart card removal behavior), but also enables the forward-looking customer to bridge to modern protocols like FIDO2 passkeys, while staying compliant with their existing security policies. Moreover, the capability developed by Sciber enhances overall security posture for all organizations by locking the workstation or logging off the user when a YubiKey is not present, so it&amp;rsquo;s a great capability not only for those sunsetting legacy methods or form factors.&lt;/p&gt;</description></item><item><title>Writing Maester tests using AI - From idea to Pull Request</title><link>https://janbakker.tech/writing-maester-tests-using-ai-from-idea-to-pull-request/</link><pubDate>Tue, 21 Jul 2026 09:37:48 +0000</pubDate><guid>https://janbakker.tech/writing-maester-tests-using-ai-from-idea-to-pull-request/</guid><description>&lt;p&gt;I love &#10;&lt;a href="https://maester.dev" rel="noopener"&gt;Maester&lt;/a&gt;. No doubt about that. I&amp;rsquo;ve made several contributions to this open-source project before, but it took me a lot of effort to learn how the underlying structure worked as a non-developer, and this challenge can be hard for a lot of Entra or Microsoft 365 admins out there.&lt;/p&gt;</description></item><item><title>Admin control for SSO prompts in Windows; finally, an off switch!</title><link>https://janbakker.tech/admin-control-for-sso-prompts-in-windows-finally-an-off-switch/</link><pubDate>Thu, 16 Jul 2026 07:15:29 +0000</pubDate><guid>https://janbakker.tech/admin-control-for-sso-prompts-in-windows-finally-an-off-switch/</guid><description>&lt;p&gt;If you&amp;rsquo;ve been paying attention to the EEA sign-in changes over the past while, you&amp;rsquo;ll know Microsoft started prompting users before reusing their Windows credentials to sign in to other Microsoft apps and services. Good for user choice, less great if you&amp;rsquo;re an admin who just spent years getting SSO &lt;em&gt;working&lt;/em&gt; and now watches it ask permission every time.&lt;/p&gt;</description></item><item><title>Passkeys by default and retirement of Microsoft-provided SMS and voice authentication - A guide to stay calm</title><link>https://janbakker.tech/passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-a-guide-to-stay-calm/</link><pubDate>Tue, 14 Jul 2026 16:01:19 +0000</pubDate><guid>https://janbakker.tech/passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-a-guide-to-stay-calm/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;I don&amp;rsquo;t have all the answers, but I promise to keep this post updated with all the details I find.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;Microsoft dropped a bomb by announcing it will stop funding phone-based MFA, such as SMS and voice, and that passkeys will become the new standard.&lt;/p&gt;</description></item><item><title>KB - employeeLeaveDateTime show empty (null)</title><link>https://janbakker.tech/kb-employeeleavedatetime-show-empty-null/</link><pubDate>Mon, 06 Jul 2026 09:41:25 +0000</pubDate><guid>https://janbakker.tech/kb-employeeleavedatetime-show-empty-null/</guid><description>&lt;p&gt;This is a knowledge base item. I hope it will help you someday.&lt;/p&gt;&#10;&lt;h2 id="the-issue"&gt;The issue&lt;a class="anchor" href="#the-issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;When syncing the employeeLeaveDateTime attribute to Entra ID, the value shows &lt;strong&gt;null&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;In this example, I use Graph Explorer to check the value.&lt;/p&gt;</description></item><item><title>Why Windows is the hardest passkey surface in 2026 and what Entra admins should expect</title><link>https://janbakker.tech/why-windows-is-the-hardest-passkey-surface-in-2026-and-what-entra-admins-should-expect/</link><pubDate>Mon, 06 Jul 2026 07:47:51 +0000</pubDate><guid>https://janbakker.tech/why-windows-is-the-hardest-passkey-surface-in-2026-and-what-entra-admins-should-expect/</guid><description>&lt;p&gt;&lt;em&gt;Written by: &#10;&lt;a href="https://www.corbado.com/about" rel="noopener"&gt;Corbado&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&#10;&lt;p&gt;If you have rolled out passkeys to a mixed device fleet, you might have probably noticed the following pattern. Some users log in smoothly and barely create a ticket (e.g. iPhone users), while others, like Windows users, do. Behind runs the same identity provider, same policy, same relying party but the user experience with passkeys can be very different depending on the user’s setup.&lt;/p&gt;</description></item><item><title>Entra ID SAML authnmethodsreferences (AMR) now supports phishing-resistant MFA</title><link>https://janbakker.tech/entra-id-saml-authnmethodsreferences-amr-now-supports-phishing-resistant-mfa/</link><pubDate>Fri, 26 Jun 2026 14:12:37 +0000</pubDate><guid>https://janbakker.tech/entra-id-saml-authnmethodsreferences-amr-now-supports-phishing-resistant-mfa/</guid><description>&lt;p&gt;If you&amp;rsquo;ve been following the &#10;&lt;a href="https://help.salesforce.com/s/articleView?id=005321563&amp;amp;type=1" rel="noopener"&gt;Salesforce phishing-resistant MFA (PRMFA) requirement story&lt;/a&gt;, you know the clock has been ticking. Salesforce has been pushing organizations to enforce phishing-resistant MFA for Salesforce administrators. The tricky part? Until now, Microsoft Entra ID has not always sent enough information in the SAML assertion for Salesforce to verify &lt;strong&gt;how&lt;/strong&gt; the user authenticated, only that they authenticated.&lt;/p&gt;</description></item><item><title>Domainless SAML federation in Microsoft Entra External ID</title><link>https://janbakker.tech/domainless-saml-federation-in-microsoft-entra-external-id/</link><pubDate>Tue, 19 May 2026 06:42:09 +0000</pubDate><guid>https://janbakker.tech/domainless-saml-federation-in-microsoft-entra-external-id/</guid><description>&lt;p&gt;If you&amp;rsquo;ve ever set up direct federation with a SAML Identity Provider in Microsoft Entra External ID, you&amp;rsquo;ll know the pain. You configure everything correctly, invite a guest user, and then they hit a cryptic error at sign-in:&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;AADSTS5000819&lt;/strong&gt;: SAML Assertion is invalid. Email address claim is missing or does not match domain from an external realm.&lt;/p&gt;</description></item><item><title>Use Device Code Flow to register a passkey in Microsoft Authenticator App</title><link>https://janbakker.tech/use-device-code-flow-to-register-a-passkey-in-microsoft-authenticator-app/</link><pubDate>Wed, 13 May 2026 15:43:32 +0000</pubDate><guid>https://janbakker.tech/use-device-code-flow-to-register-a-passkey-in-microsoft-authenticator-app/</guid><description>&lt;p&gt;The other day, I was doing some research in my lab, and had to register a new passkey a couple of times. At some point, I stumbled upon the device code flow in the Microsoft Authenticator app. I was aware of this flow, but I suddenly realized how easy it is to create a new passkey on a rogue/remote device, using social engineering. &lt;strong&gt;One more reason to block it!&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Entra ID Governance - View approver information for pending requests</title><link>https://janbakker.tech/entra-id-governance-view-approver-information-for-pending-requests/</link><pubDate>Mon, 04 May 2026 14:26:11 +0000</pubDate><guid>https://janbakker.tech/entra-id-governance-view-approver-information-for-pending-requests/</guid><description>&lt;p&gt;A new feature in Entra ID Governance was introduced and enabled by default.&lt;/p&gt;&#10;&lt;p&gt;When users request an access package and approval is needed, they can now see the name and email of the approver.&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/entra-id-governance-view-approver-information-for-pending-requests/image-4.png"&gt;&#10; &lt;img src="https://janbakker.tech/entra-id-governance-view-approver-information-for-pending-requests/image-4_hu_bed1cbb80d4654f8.webp" srcset="https://janbakker.tech/entra-id-governance-view-approver-information-for-pending-requests/image-4_hu_fd339c8e5e2ce6f5.webp 720w, https://janbakker.tech/entra-id-governance-view-approver-information-for-pending-requests/image-4_hu_bed1cbb80d4654f8.webp 1400w" sizes="(max-width: 820px) 100vw, 780px" width="1400" height="823" alt="Screenshot from the article" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;</description></item><item><title>Configurable token lifetimes in Entra ID</title><link>https://janbakker.tech/configurable-token-lifetimes-in-entra-id/</link><pubDate>Mon, 04 May 2026 14:01:00 +0000</pubDate><guid>https://janbakker.tech/configurable-token-lifetimes-in-entra-id/</guid><description>&lt;p&gt;Today, a quick post about setting up token lifetime policies in Entra ID. In some use cases, organizations require a short access token for highly privileged apps or resources. That said, this is probably &lt;strong&gt;NOT&lt;/strong&gt; needed for the typical apps we all use day-to-day.&lt;/p&gt;</description></item><item><title>Your service principals probably don't need secrets</title><link>https://janbakker.tech/your-service-principals-probably-dont-need-secrets/</link><pubDate>Mon, 20 Apr 2026 11:59:25 +0000</pubDate><guid>https://janbakker.tech/your-service-principals-probably-dont-need-secrets/</guid><description>&lt;p&gt;&#10;&lt;a href="https://janbakker.tech/no-your-nhis-cant-use-passwords-either/"&gt;Application policies&lt;/a&gt; in Entra have been around for a while now to manage the use of secrets, but I don&amp;rsquo;t see many folks using them. It&amp;rsquo;s probably because secrets are still widely used, and an unlimited lifetime for secrets results in less yelling from developers. Everyone&amp;rsquo;s happy. &lt;br&gt;&#10;&lt;br&gt;&#10;Yet, attackers love secrets and use them all the time. In obvious places, like app registrations, but &#10;&lt;a href="https://dirkjanm.io/azure-ad-privilege-escalation-application-admin/" rel="noopener"&gt;also on service principals&lt;/a&gt;, where you don&amp;rsquo;t expect them. You cannot see or add them in the UX, but they can be added via the Graph API.&lt;/p&gt;</description></item><item><title>Block or limit multi-tenant and consumer applications in Entra ID</title><link>https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/</link><pubDate>Wed, 15 Apr 2026 10:02:16 +0000</pubDate><guid>https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/</guid><description>&lt;p&gt;Two new policies have been added to the &#10;&lt;a href="https://janbakker.tech/no-your-nhis-cant-use-passwords-either/"&gt;recently introduced Application Policies&lt;/a&gt; in Entra ID!&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6.png"&gt;&#10; &lt;img src="https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6_hu_9bef35f8daf40e06.webp" srcset="https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6_hu_78ef44c695c45ff1.webp 720w, https://janbakker.tech/block-or-limit-multi-tenant-and-consumer-applications-in-entra-id/image-6_hu_9bef35f8daf40e06.webp 1400w" sizes="(max-width: 820px) 100vw, 780px" width="1400" height="821" alt="Screenshot from the article" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;&#10;&lt;p&gt;Admins can now restrict or block multi-tenant applications, and applications that support consumer sign-in (personal Microsoft accounts)&lt;/p&gt;</description></item><item><title>KB - Entra Private Access Session persistence</title><link>https://janbakker.tech/kb-entra-private-access-session-persistence/</link><pubDate>Wed, 08 Apr 2026 13:21:31 +0000</pubDate><guid>https://janbakker.tech/kb-entra-private-access-session-persistence/</guid><description>&lt;p&gt;This is a knowledge base item. I hope it will help you someday.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;p&gt;**Update:**This setting can also be set from the Entra admin center now.&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/kb-entra-private-access-session-persistence/image-22.png"&gt;&#10; &lt;img src="https://janbakker.tech/kb-entra-private-access-session-persistence/image-22_hu_987a4e9d137bbbe6.webp" srcset="https://janbakker.tech/kb-entra-private-access-session-persistence/image-22_hu_9ec4d6e944da1352.webp 720w, https://janbakker.tech/kb-entra-private-access-session-persistence/image-22_hu_987a4e9d137bbbe6.webp 1042w" sizes="(max-width: 820px) 100vw, 780px" width="1042" height="263" alt="Screenshot from the article" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;&#10;&lt;p&gt;It can be set under the Network access properties of the Enterprise Application.&lt;/p&gt;</description></item><item><title>Conditional Access Optimization Agent knowledge base</title><link>https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/</link><pubDate>Sun, 15 Mar 2026 06:57:10 +0000</pubDate><guid>https://janbakker.tech/conditional-access-optimization-agent-knowledge-base/</guid><description>&lt;p&gt;Y&amp;rsquo;all know this song by the Beatles, right?&lt;/p&gt;&#10;&lt;p&gt;&lt;em&gt;What would you think if I sang out of tune?&lt;br&gt;&#10;Would you stand up and walk out on me?&lt;br&gt;&#10;Lend me your ears, and I&amp;rsquo;ll sing you a song&lt;br&gt;&#10;And I&amp;rsquo;ll try not to sing out of key&lt;br&gt;&#10;&lt;br&gt;&#10;Oh, I get by with a little help from my friends&lt;br&gt;&#10;Mmm, I get high with a little help from my friends&lt;br&gt;&#10;Ooh, I&amp;rsquo;m gonna try with a little help from my friends&lt;/em&gt;&lt;/p&gt;</description></item><item><title>How to get better with Graph API - Part one</title><link>https://janbakker.tech/how-to-get-better-with-graph-api-part-one/</link><pubDate>Fri, 06 Mar 2026 19:28:30 +0000</pubDate><guid>https://janbakker.tech/how-to-get-better-with-graph-api-part-one/</guid><description>&lt;p&gt;As you might know, Graph API is an important part of Microsoft 365. Everything (or most) of the things you see in the Entra admin center or Microsoft Admin portal is pulled from the Graph API. Every button you click pulls data &lt;strong&gt;from&lt;/strong&gt; or pushes data &lt;strong&gt;to&lt;/strong&gt; the Graph API.&lt;/p&gt;</description></item><item><title>What admins can learn from the new Entra ID Groups Insights blade</title><link>https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/</link><pubDate>Wed, 18 Feb 2026 14:54:06 +0000</pubDate><guid>https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/</guid><description>&lt;p&gt;Microsoft released a new overview in Entra ID: &lt;strong&gt;Entra ID Groups Insights&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/image-11.png"&gt;&#10; &lt;img src="https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/image-11_hu_1c7f16e8c8e7a4b9.webp" srcset="https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/image-11_hu_49601cdee4b13443.webp 720w, https://janbakker.tech/what-admins-can-learn-from-the-new-entra-id-groups-insights-blade/image-11_hu_1c7f16e8c8e7a4b9.webp 1400w" sizes="(max-width: 820px) 100vw, 780px" width="1400" height="998" alt="Screenshot from the article" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;&#10;&lt;p&gt;Currently in preview, it has some limitations, but what caught my attention is the new Graph API endpoint that this report is using: &lt;code&gt;beta/reports/identityAnalytics/groups&lt;/code&gt;&lt;/p&gt;</description></item><item><title>How to find unattested device-bound passkeys in Entra ID</title><link>https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/</link><pubDate>Mon, 09 Feb 2026 08:47:15 +0000</pubDate><guid>https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/</guid><description>&lt;p&gt;Attestation is an important topic in the context of device-bound passkeys. Seeing the creative work from &#10;&lt;a href="https://github.com/nathanmcnulty/nathanmcnulty/tree/main/Entra/passkeys/keyvault" rel="noopener"&gt;Nathan&lt;/a&gt;, &#10;&lt;a href="https://github.com/f-bader/TokenTacticsV2" rel="noopener"&gt;Fabian&lt;/a&gt;, and &#10;&lt;a href="https://lieben.nu/liebensraum/2026/02/silent-provisioning-of-fido-key-to-use-for-headless-requests-against-hidden-apis/" rel="noopener"&gt;Jos&lt;/a&gt; coming together, you might want to keep an eye on non-attested, device-bound passkeys in Entra ID.&lt;/p&gt;&#10;&lt;p&gt;&#10; &lt;a class="img-link" href="https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7.png"&gt;&#10; &lt;img src="https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7_hu_d40c6c6fcebbb7dd.webp" srcset="https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7_hu_e9ac3fd7834c84f3.webp 720w, https://janbakker.tech/how-to-find-unattested-device-bound-passkeys-in-entra-id/image-7_hu_d40c6c6fcebbb7dd.webp 1400w" sizes="(max-width: 820px) 100vw, 780px" width="1400" height="695" alt="Screenshot showing the passkey attestation report" loading="lazy" decoding="async"&gt;&#10; &lt;/a&gt;&#10;&lt;/p&gt;</description></item><item><title>The hidden risk of using aka.ms shortURLs for Microsoft portals</title><link>https://janbakker.tech/the-hidden-risk-of-using-aka-ms-shorturls-for-microsoft-portals/</link><pubDate>Fri, 06 Feb 2026 13:17:52 +0000</pubDate><guid>https://janbakker.tech/the-hidden-risk-of-using-aka-ms-shorturls-for-microsoft-portals/</guid><description>&lt;p&gt;We all love them: Microsoft&amp;rsquo;s short URLs at aka.ms. The &lt;strong&gt;aka.ms&lt;/strong&gt; domain is owned by Microsoft and is used to shorten URLs for many purposes. I even &#10;&lt;a href="https://aka.ms/janbakker" rel="noopener"&gt;got one&lt;/a&gt; myself that points to my MVP profile. They are usually pointing to &lt;em&gt;&lt;strong&gt;documentation&lt;/strong&gt;&lt;/em&gt;, which is fine, but they are also used for Entra or Microsoft 365-integrated portals. Just to name a few examples:&lt;/p&gt;</description></item><item><title>Jan's resource catalog to learn all about agents (from an Entra ID perspective)</title><link>https://janbakker.tech/jans-resource-catalog-to-learn-all-about-agents/</link><pubDate>Fri, 30 Jan 2026 07:35:22 +0000</pubDate><guid>https://janbakker.tech/jans-resource-catalog-to-learn-all-about-agents/</guid><description>&lt;p&gt;I&amp;rsquo;ve been digging into agents lately, especially the identity and security aspects. As this whole concept is quite new to all of us, it&amp;rsquo;s always hard to know where to start. Who got this thing figured out already? Who to follow? Who to ask questions?&lt;/p&gt;</description></item><item><title>Least privilege for Temporary Access Pass creation</title><link>https://janbakker.tech/least-privilege-for-temporary-access-pass-creation/</link><pubDate>Sun, 25 Jan 2026 14:15:32 +0000</pubDate><guid>https://janbakker.tech/least-privilege-for-temporary-access-pass-creation/</guid><description>&lt;p&gt;Today, giving out Temporary Access Passes for Microsoft 365 is a very common task. And attackers love them as well, since they bypass some security policies, including MFA. With Zero Trust in mind, we should always strive to use &amp;lsquo;&lt;em&gt;just-in-time&lt;/em&gt;&amp;rsquo; and &amp;lsquo;&lt;em&gt;just-enough&lt;/em&gt;&amp;rsquo; permissions. So whether you do this task manually or have it fully automated, both scenarios need to follow least privilege.&lt;/p&gt;</description></item><item><title>Access Azure Virtual Desktop and Windows 365 Cloud PC from non-managed devices</title><link>https://janbakker.tech/access-azure-virtual-desktop-and-windows-365-cloud-pc-from-non-managed-devices/</link><pubDate>Mon, 12 Jan 2026 13:10:56 +0000</pubDate><guid>https://janbakker.tech/access-azure-virtual-desktop-and-windows-365-cloud-pc-from-non-managed-devices/</guid><description>&lt;p&gt;Many organizations use Azure Virtual Desktop or Windows 365 Cloud PC. But how do we secure access to those resources? A very common use case is to connect from a non-managed device (BYOD). Then, from there, a user would have access to other resources, such as applications, email, and documents. The virtual workspace is managed, well-secured, and controlled by the organization, with end-users&amp;rsquo; (BYO) devices used as stepping stones.&lt;/p&gt;</description></item><item><title>Useful search filters in Entra ID you might not know (yet)</title><link>https://janbakker.tech/useful-search-filters-in-entra-id-you-might-not-know-yet/</link><pubDate>Thu, 08 Jan 2026 20:05:18 +0000</pubDate><guid>https://janbakker.tech/useful-search-filters-in-entra-id-you-might-not-know-yet/</guid><description>&lt;p&gt;I learn new stuff every day. And so do you by reading this post.&lt;/p&gt;&#10;&lt;p&gt;The other day, I was scrolling through the Entra admin center and discovered some useful search filters in the Users section that I had not seen before. That could just be my ignorance, but since I did not know about them, I figured more folks should be enlightened. Hence, this short, informative post. I was surprised that such a handy filter was available by the click of a button. No fancy PowerShell scripts or MCP servers, just plain UI stuff today!&lt;/p&gt;</description></item><item><title>How to enable passkeys for guest users in Entra ID</title><link>https://janbakker.tech/how-to-enable-passkeys-for-guest-users-in-entra-id/</link><pubDate>Fri, 19 Dec 2025 14:12:23 +0000</pubDate><guid>https://janbakker.tech/how-to-enable-passkeys-for-guest-users-in-entra-id/</guid><description>&lt;p&gt;Passkeys like FIDO security keys, synced passkeys, and passkeys in Microsoft Authenticator are secure and convenient authentication methods for your end users. They are phishing-resistant, passwordless, and enable fast sign-in to Microsoft 365 or other Entra ID-integrated apps.&lt;/p&gt;&#10;&lt;h2 id="the-issue"&gt;The issue&lt;a class="anchor" href="#the-issue" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Unfortunately, guest users who access your (resource) tenant with MFA enforced are unable to register a passkey, despite having it enabled or registered in their home tenant. This is also stated on &#10;&lt;a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2#guest-users" rel="noopener"&gt;Microsoft Learn&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Store your Microsoft 365 passkeys in 1Password</title><link>https://janbakker.tech/store-your-microsoft-365-passkeys-in-1password/</link><pubDate>Mon, 24 Nov 2025 20:04:37 +0000</pubDate><guid>https://janbakker.tech/store-your-microsoft-365-passkeys-in-1password/</guid><description>&lt;p&gt;Syncable passkeys in Microsoft 365 and Entra ID are here, so we are no longer limited to the Authenticator app and FIDO2 keys for storing passkeys. Passkeys can now be synced up &amp;ldquo;into the cloud&amp;rdquo;, so we can enjoy them on all our devices without the hassle of recovering each time we get a new phone or lose our YubiKey.&lt;/p&gt;</description></item></channel></rss>