<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Azure Ad on JanBakker.tech</title><link>https://janbakker.tech/tags/azure-ad/</link><description>Recent content in Azure Ad on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Wed, 21 Jun 2023 18:32:01 +0000</lastBuildDate><atom:link href="https://janbakker.tech/tags/azure-ad/index.xml" rel="self" type="application/rss+xml"/><item><title>Company branding and custom CSS in Azure Active Directory</title><link>https://janbakker.tech/company-branding-and-custom-css-in-azure-active-directory/</link><pubDate>Wed, 21 Jun 2023 18:32:01 +0000</pubDate><guid>https://janbakker.tech/company-branding-and-custom-css-in-azure-active-directory/</guid><description>&lt;p&gt;Company branding in Azure AD is a nice feature that allows administrators to prettify the sign-in experience for their end-users. It also comes with the possibility of ingesting custom CSS code.&lt;/p&gt;&#10;&lt;p&gt;A client recently moved from ADFS to Azure AD, and they wanted to update the sign-in screen to look more like the good old ADFS theme. Now, this is pretty easy to do, but by default, the background image comes with an overlay to improve contrast and legibility.&lt;/p&gt;</description></item><item><title>Send an email on a new Azure MFA method registration</title><link>https://janbakker.tech/send-an-email-on-a-new-azure-mfa-method-registration/</link><pubDate>Fri, 02 Jun 2023 09:50:08 +0000</pubDate><guid>https://janbakker.tech/send-an-email-on-a-new-azure-mfa-method-registration/</guid><description>&lt;p&gt;I&amp;rsquo;ve done quite some Azure MFA projects over time (and counting), and as we mainly focus on the technical side, there are also practical sides to consider. Every project has its own approach and challenges, and more importantly: the user is impacted more or less, and that asks for some guidance.&lt;/p&gt;</description></item><item><title>Authenticator Lite - Approve Azure MFA prompts with the Outlook app</title><link>https://janbakker.tech/authenticator-lite-approve-azure-mfa-prompts-with-the-outlook-app/</link><pubDate>Tue, 14 Mar 2023 12:28:09 +0000</pubDate><guid>https://janbakker.tech/authenticator-lite-approve-azure-mfa-prompts-with-the-outlook-app/</guid><description>&lt;p&gt;Microsoft &#10;&lt;a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&amp;amp;searchterms=122289" rel="noopener"&gt;released&lt;/a&gt; a new feature where the Outlook mobile app now has some of the Microsoft Authenticator App features onboard. Users can now enroll for Azure MFA using just their Outlook mobile app. No additional installation of the Microsoft Authenticator app is needed. This preview brings both push notifications and TOTP to the Outlook mobile app. Users are prompted for enrollment or can manually register their app to work with a Microsoft 365 account once this feature is enabled.&lt;/p&gt;</description></item><item><title>System-preferred multifactor authentication in Azure AD. Don't settle for less.</title><link>https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/</link><pubDate>Fri, 03 Mar 2023 14:39:38 +0000</pubDate><guid>https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/</guid><description>&lt;p&gt;A new feature has popped up in Azure AD: &lt;strong&gt;System-preferred multifactor authentication (MFA)&lt;/strong&gt;. This will allow administrators to enforce the most secure method for Azure MFA. For example, if a user has multiple methods registered, the most secure method will be prompted first. How do I know what method is the strongest, you may ask? Here is the current order from most to least secure methods, currently supported in Azure Active Directory:&lt;/p&gt;</description></item><item><title>Azure Active Directory Identity Governance – Azure AD Entitlement Management</title><link>https://janbakker.tech/azure-active-directory-identity-governance-azure-ad-entitlement-management/</link><pubDate>Sun, 20 Dec 2020 18:34:00 +0000</pubDate><guid>https://janbakker.tech/azure-active-directory-identity-governance-azure-ad-entitlement-management/</guid><description>&lt;p&gt;In this series, we take a look at Azure Active Directory Identity Governance. This premium feature provides you with all the tools that you need to take and keep control over your (external) identities and access to roles, resources, applications, and groups. In short, Identity Governance gives you three ways to do this:&lt;/p&gt;</description></item><item><title>Azure Active Directory Identity Governance – Privileged Identity Management</title><link>https://janbakker.tech/active-directory-identity-governance-privileged-identity-management/</link><pubDate>Wed, 09 Dec 2020 19:46:30 +0000</pubDate><guid>https://janbakker.tech/active-directory-identity-governance-privileged-identity-management/</guid><description>&lt;p&gt;In this series, we take a look at Azure Active Directory Identity Governance. This premium feature provides you with all the tools that you need to take and keep control over your (external) identities and access to roles, resources, applications, and groups. In short, Identity Governance gives you three ways to do this:&lt;/p&gt;</description></item><item><title>Azure Active Directory Identity Governance - Access Reviews</title><link>https://janbakker.tech/active-directory-identity-governance-access-reviews/</link><pubDate>Mon, 23 Nov 2020 18:53:14 +0000</pubDate><guid>https://janbakker.tech/active-directory-identity-governance-access-reviews/</guid><description>&lt;p&gt;In this series, we take a look at Azure Active Directory Identity Governance. This premium feature provides you with all the tools that you need to take and keep control over your (external) identities and access to roles, resources, applications, and groups. In short, Identity Governance gives you three ways to do this:&lt;/p&gt;</description></item><item><title>License on-demand with Power Automate and Azure AD</title><link>https://janbakker.tech/license-on-demand-with-power-automate-and-azure-ad/</link><pubDate>Sun, 18 Oct 2020 15:49:41 +0000</pubDate><guid>https://janbakker.tech/license-on-demand-with-power-automate-and-azure-ad/</guid><description>&lt;p&gt;Most organizations are using &#10;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-licensing-whatis-azure-portal" rel="noopener"&gt;group-based&lt;/a&gt; licensing in Azure Active Directory. This is often integrated with the onboarding process of the users. But there are some use cases where you have some non-standard licenses attached to your tenant that you hand out on demand. You could still use group-based licensing, but users are added manually to the group.&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 15 – Do not expire passwords</title><link>https://janbakker.tech/microsoft-secure-score-series-15-do-not-expire-passwords/</link><pubDate>Sun, 06 Sep 2020 18:13:53 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-15-do-not-expire-passwords/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>Use Power Automate or Logic Apps to keep an eye on your licenses</title><link>https://janbakker.tech/use-power-automate-or-logic-apps-to-keep-an-eye-on-your-licenses/</link><pubDate>Sat, 27 Jun 2020 18:37:43 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-or-logic-apps-to-keep-an-eye-on-your-licenses/</guid><description>&lt;p&gt;I guess we&amp;rsquo;ve all been there; you ran out of licenses in your Azure AD or Office 365 tenant. Despite you hang out in your admin portal every day, you were still taken by surprise when you discover an issue, caused by a license shortage. More often this is caused by the fact that the people who are responsible to buy these licenses, are not always IT admins. So it&amp;rsquo;s easy to run out of licenses. Time to get this fixed.&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 09 – Do not allow users to grant consent to unmanaged applications</title><link>https://janbakker.tech/microsoft-secure-score-series-09-do-not-allow-users-to-grant-consent-to-unmanaged-applications/</link><pubDate>Sat, 30 May 2020 19:30:39 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-09-do-not-allow-users-to-grant-consent-to-unmanaged-applications/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>Use Graph API data in Power BI using Logic Apps</title><link>https://janbakker.tech/use-graph-api-data-in-power-bi-using-logicapps/</link><pubDate>Sat, 09 May 2020 12:50:34 +0000</pubDate><guid>https://janbakker.tech/use-graph-api-data-in-power-bi-using-logicapps/</guid><description>&lt;p&gt;Some things in the modern connected world seem so common that you just assume it&amp;rsquo;s possible by nature. Getting your Microsoft Graph API data into Microsoft Power BI for example. That must be easy peasy right? Well&amp;hellip;.&lt;/p&gt;&#10;&lt;p&gt;When I start looking for ways to do this, I assumed there was a builtin connector available in Power BI that I could use. Guess what? There is not (yet). There is a connector for the &lt;strong&gt;Microsoft Security Graph&lt;/strong&gt;, but that one &amp;ldquo;only&amp;rdquo; gives back the data from the security products. Just good to know that it&amp;rsquo;s out there, but that&amp;rsquo;s not what we&amp;rsquo;re looking for.&lt;/p&gt;</description></item><item><title>What admins should know about the combined registration portal for Azure MFA and Self Service Password Reset</title><link>https://janbakker.tech/what-admins-should-know-about-the-combined-registration-portal-for-azure-mfa-and-self-service-password-reset/</link><pubDate>Sat, 02 May 2020 12:06:20 +0000</pubDate><guid>https://janbakker.tech/what-admins-should-know-about-the-combined-registration-portal-for-azure-mfa-and-self-service-password-reset/</guid><description>&lt;h4 id="this-post-is-outdated-there-is-a-new-way-to-manage-authentication-methods"&gt;&lt;strong&gt;This post is outdated.&lt;/strong&gt; There is a &#10;&lt;a href="https://janbakker.tech/goodbye-legacy-sspr-and-mfa-settings-hello-authentication-methods-policies/"&gt;new way&lt;/a&gt; to manage authentication methods&lt;a class="anchor" href="#this-post-is-outdated-there-is-a-new-way-to-manage-authentication-methods" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h4&gt;&#10;&lt;p&gt;&#10;&lt;a href="https://janbakker.tech/goodbye-legacy-sspr-and-mfa-settings-hello-authentication-methods-policies/"&gt;Learn more&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;The (long) title pretty much reveals the purpose of this blog post. This one was on my to-do list for a while now, and now the &#10;&lt;a href="https://techcommunity.microsoft.com/t5/azure-active-directory-identity/combined-mfa-and-password-reset-registration-is-now-generally/ba-p/1257355" rel="noopener"&gt;combined registration portal is General Available&lt;/a&gt;, the time was there. In my previous MFA-related blogs, I always encouraged my readers to turn on the combined registration portal, even when it was in public preview. But if you start using this portal, there are quite some settings that can change the user experience of the registration. And that&amp;rsquo;s mainly what this blog post is about. Let&amp;rsquo;s see how each setting reflects to the end user.&lt;/p&gt;</description></item><item><title>Use Power Automate for your custom "dynamic" groups</title><link>https://janbakker.tech/use-power-automate-for-your-custom-dynamic-groups/</link><pubDate>Wed, 01 Apr 2020 19:52:46 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-for-your-custom-dynamic-groups/</guid><description>&lt;h2 id="azure-ad-dynamic-groups"&gt;Azure AD Dynamic Groups&lt;a class="anchor" href="#azure-ad-dynamic-groups" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Dynamic groups in Azure AD are awesome. I use them a lot. Dynamic groups can create groups based on attributes. For example, you can create a group that includes all the users from the Sales Team. The query for the group would look like this:&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 04 – Ensure all users can complete multi-factor authentication for secure access</title><link>https://janbakker.tech/microsoft-secure-score-series-04-ensure-all-users-can-complete-multi-factor-authentication-for-secure-access/</link><pubDate>Fri, 27 Mar 2020 21:19:07 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-04-ensure-all-users-can-complete-multi-factor-authentication-for-secure-access/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>How to publish on-premises applications and protect them with MFA</title><link>https://janbakker.tech/how-to-publish-on-premises-applications-and-protect-them-with-mfa/</link><pubDate>Fri, 13 Mar 2020 18:56:31 +0000</pubDate><guid>https://janbakker.tech/how-to-publish-on-premises-applications-and-protect-them-with-mfa/</guid><description>&lt;p&gt;Using Azure Application Proxy you can publish your on-premises web applications in a secure way. Combining this with Conditional Access, you can configure MFA for example. Now Coronavirus is hitting us hard, you might have to take a look at this feature.&lt;/p&gt;</description></item><item><title>Microsoft Secure Score Series – 02 – Require MFA for administrative roles</title><link>https://janbakker.tech/microsoft-secure-score-series-02-require-mfa-for-administrative-roles/</link><pubDate>Wed, 11 Mar 2020 20:25:28 +0000</pubDate><guid>https://janbakker.tech/microsoft-secure-score-series-02-require-mfa-for-administrative-roles/</guid><description>&lt;p&gt;In this series, I&amp;rsquo;ll be covering the Microsoft Secure Score improvement actions. Although Microsoft does a great job on telling you what to do, some actions have a much bigger impact and need to be balanced against business needs. Some actions might not even have value for your organization. In the end, Microsoft Secure Score is meant to strengthen your security, not a contest to reach the highest score possible. In this series, I&amp;rsquo;ll pick out random actions and try to make it as simple as possible, backed with notes from the field.&lt;/p&gt;</description></item><item><title>Azure AD tenant branding; size does matter!</title><link>https://janbakker.tech/azure-ad-tenant-branding-size-does-matter/</link><pubDate>Wed, 26 Feb 2020 19:39:57 +0000</pubDate><guid>https://janbakker.tech/azure-ad-tenant-branding-size-does-matter/</guid><description>&lt;p&gt;Earlier today, I read this article from Alex Simons about the &#10;&lt;a href="https://techcommunity.microsoft.com/t5/azure-active-directory-identity/upcoming-changes-to-the-azure-ad-sign-in-experience/ba-p/1185161" rel="noopener"&gt;change that is coming to the Azure AD sign-in experience&lt;/a&gt;. In this change the background image of the login screen is being replaced for a smaller one, so the page loads faster. Good news for the low bandwidth offices out there! The article states: &lt;em&gt;If you’ve configured a custom background image in Company Branding for your tenant there is no change to your users.&lt;/em&gt; That got me thinking.&lt;/p&gt;</description></item><item><title>Require trusted location for MFA and SSPR registration</title><link>https://janbakker.tech/require-trusted-location-for-mfa-and-sspr-registration/</link><pubDate>Sat, 22 Feb 2020 20:02:48 +0000</pubDate><guid>https://janbakker.tech/require-trusted-location-for-mfa-and-sspr-registration/</guid><description>&lt;p&gt;This article shows how you can block MFA and SSPR registrations from untrusted locations using Azure AD Conditional Acces.&lt;/p&gt;&#10;&lt;p&gt;When you want to enable MultiFactor Authentication and Self Service Password Reset for your users, they need to register their security settings first. Since the &#10;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-registration-mfa-sspr-combined" rel="noopener"&gt;combined portal&lt;/a&gt; arrived, users can do this easily in just one place. Using this combined portal is also a requirement in order to make this possible. Although this portal is still in preview, it has great user experience and wizards run smoothly.&lt;/p&gt;</description></item></channel></rss>