r/entra • u/Limp_Substance4433 • 1h ago
r/entra • u/Sufficient-Pace7542 • 8h ago
SMS/Voice Retirement and Passkeys
With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.
I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.
Any insights would be greatly appreciated.
r/entra • u/NathanSecurity • 14h ago
ID Protection What are you using to monitor and manage Entra ID security posture?
Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.
Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.
I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?
Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?
r/entra • u/WeirdoInTheShadow • 10h ago
Entra ID Entra ID connect implementation
How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.
Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?
Any gotchas / tips?
Many thanks
r/entra • u/Difficult_Angle_1499 • 20h ago
Best practice for hybrid user account - cloud only device
we have user onboarding as Hybrid but our devices are now cloud only.
we have onboarding script that sets default password and ticks reset password on 1st login
but with cloud only device we have issues with password as ticking password reset on 1st login will not allow password to sync to entra.
how to achieve password reset on 1st login with this senario. I can take off password reset on 1st login from script.
Odd iOS Phishing-Resistant Authentication Behavior
We use Conditional Access to require phishing-resistant authentication for all of our admins. In recent weeks, authentication behavior from iOS devices has changed, and I'm not able to figure out why.
When prompting for authentication, I'm first given a prompt for passwordless authentication (using Authenticator number matching). It then steps up and further requires me to authenticate with a passkey. It used to just directly prompt for the passkey. Does anyone know if this is a recent change, or what is causing this behavior?
r/entra • u/j1mmyfever • 23h ago
CA for complaint devices?
Is this a “compliant in my tenant” setting or a client side setting?
I have users passing the policy from devices that are managed by Intune in an untrusted tenant.
My expectation is they should be failing.
Haven’t had time to research, but it’s definitely happening.
r/entra • u/Extra-Citron-7630 • 1d ago
Entra ID App Roles not appearing in AWS ALB OIDC claims from Microsoft Entra ID
r/entra • u/Adnan2559 • 1d ago
Fully Custom Captive Portal - Hotel Requirement
Hi Experts,
One of the hotels want a very customizable captive portal like on landing page they want options for guest and visitor (tab based), when guest enters the required info he should be asked to create his own password, there should also be option for sign in if he has done this process already. OTP must be configured either via email or SMS gateway, all along with mac caching, limiting the number of devices per guest.
I know i havent provided much detail but just wanted to know since i have never worked on PF before, how customizable the entire workflow is? can we make such a captive portal in PF?
r/entra • u/No_Actuator_4762 • 1d ago
MFA for Windows RDP and non-Entra Endpoints (on-prem servers)
We’re really liking the user-based Windows Hello for Business credential provider, with MFA working with SSO, and cloud kerberos trust.
The other option I also like is passkey by way of Yubikey.
I’m not completely settled on WHfB because I don’t see how to provide MFA for RDP connections, or for on-prem servers that don’t have Entra objects sync’d.
Workstations are all hybrid joined.
How can I possibly go with WHfB and still get Kerberos+MFA when either Remote Desktop is used, and/or I want to log into an on-prem device? Is it possible? Am I going to have to “settle” on issuing Yubikeys to do this?
I do have a PKI if that could provide some help here.
Thanks!
r/entra • u/Mediocre_Prior_1868 • 1d ago
ID Protection Configure mfa for onprem
Dear All,
I am currently assigned a task to configure mfa for specific onprem server . Currently we are using Microsoft secure access to access our servers and a connector is already added to a server and it is health . Not sure what I am missing and how I can configure that .
r/entra • u/switched55 • 1d ago
Entra Connect > Entra Cloud Sync (quick cutover)
Hi,
We have a simple one way sync happening for password hashes , 28 AD accounts purely for EXO.
Ive looked at the MS recommended steps to migrate to cloud sync. It looks like a lot of work having to add in sync rules, test on one OU, etc for such a small environment.
Anyone just installed Cloud sync and simply stopped or set connect sync to staging mode?
CoPilot outlined the quick cutover steps which make sense, i'm wondering if anyone else had done this?
What I do in practice
For a straightforward environment like yours:
1. Install Cloud Sync
2. Configure Cloud Sync
3. Verify all users appear correctly
4. Verify password sync
5. Put Entra Connect in Staging Mode
6. Observe for a few days
7. Uninstall Entra Connect
I keep the overlap period short. Once Cloud Sync is proven, I move Connect into Staging Mode so there is only one active sync engine but an immediate rollback path remains available.
FYI I wouldn't sync everything, just the user and security group OU's.
r/entra • u/WonderfulPattern3927 • 1d ago
Passkey limitation
So found an issue with this whole passkey item and thought maybe someone had an idea.
1 desktop - entra joined to “Redd.com”
1 AVD - entra joined to “Goog.com”
When using the Windows app on “Redd.com” you cannot launch the passkey via your Authenticator for a connection to “Goog.com”.
The Windows app requires a physical FIDO - no request for the one on the phone, zero QR shown. The only request is to insert your device.
Anyone hit this limitation?
Any thoughts or ideas? We don’t use tokens.
r/entra • u/Spanjoekel • 1d ago
ID Protection Conditional Access on Report-Only, still able to block user sign-ins
r/entra • u/Dull_Ordinary_9883 • 1d ago
Manage multiple Tenants
Do you have good tools to manage multiple tenants like deploying policies, reviewing them and a good reporting whats going on in the tenant?
r/entra • u/snow-leapord-1 • 2d ago
IAM: Shared Device and Accounts
Hi Fellow Collegaues , What is your opinion about a situation where :
- There are retail shops or warehouses where employees ( blue collar colleagues ) are working in shifts BUT using a shared account on a shared device.
- Shared device is company managed ( intune or similar )
Question is :
- How will you solve audit questions - "Who did what with that shared account" ? If for eg. there are 4 people in a shop using that same shared account to login to the shared device and then to some "order booking" app.
One way is -
- Skip shared account totally, let them login individually with their own account ( which they use to check their payroll and other fundamental tasks )
This can be thought of, but imagine a case where in a shop you have many "potential" customers wanting to buy something and you have 4-5 employee in that case each employee who gets a hand on that device need to login again everytime to book the order. This will for sure impact the business and revenue in some sense.
- Another solution is increased the number of device , give all Blue collar colleagues their own indivdual devices, this increases operations, device management and ofcourse cost.
So please advice, what has worked with you..
r/entra • u/Electronic-Bite-8884 • 2d ago
Entra General 4th Set of Speakers Announced for Workplace Ninjas US 2027
r/entra • u/Checior2000 • 2d ago
ID Governance Guest Account LifeCycle
Hi! I would like to build script to manage inactive guest accounts around my tenant.
Do you know which attribute should I consired as main to verify inactivity period?
In my case some of members in my tenant share OD/SP files to those guest, after remove from the tenant access persist?
Thank you for answer.
r/entra • u/Mediocre_Prior_1868 • 3d ago
ID Protection MFA registration issue - Guest accounts
Hi everyone I am facing the below error for guest users after they successfully get the code on their emails try to register to mfa how I can sort it out
r/entra • u/Ok-Mirror6644 • 3d ago
Hybrid Joined device not auto-enrolling in Intune via GPO
r/entra • u/TopDry7004 • 4d ago
Entra General You don't have access in App Registrations despite Application Developer role
r/entra • u/Relevant_Celery7903 • 4d ago
SSPR Combined Registration
Our Org is looking to role out SSPR + MFA using combined registration. MS Authenticator App with Push notifications.Admons will not be enabled for SSPR.
Initially we were planning to use 2 verification methods Auth App + SMS (using ca auth strength policy to block sms as mfa).
With the recent MS announcement re sms and voice were thinking of initially requiring the one method.Although we want sspr - having all staff registered for MFA is the main identity/security benefit here from an IAM perspective.
We want as little friction as possible to get staff on on boarded but conscious two methods is the recommended but potentially we could move to two methods further down the line when there's more clarity of where sspr is going from MS. Is this a valid approach for an org who don't currently have MFA registered for all staff ?
Much appreciated for any feedback 👍
r/entra • u/rgsteele • 4d ago
Entra ID Is system-preferred first factor overriding Single Sign-On?
My colleagues and I have noticed that we've started being prompted to perform a Windows Hello for Business authentication when we use Edge to access web resources that are authenticated with Entra. Previously, this authentication occurred silently through Single Sign-On with the PRT, per Understanding Primary Refresh Token (PRT) in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn.
While investigating what might have caused this change in behavior, I found MC1411574 in the M365 Message Center, which talks about a change to system-preferred authentication that started rolling out in late June 2026, whereby it now applies to the first factor as well as multi-factor authentication. I excluded myself from system-preferred authentication and sure enough, that seems to have restored the previous behavior.
Is it intended that this change to system-preferred authentication will disable SSO, or do we have something misconfigured?
r/entra • u/Zealousideal_Bug4743 • 5d ago
Restrict Synced Passkeys only to Mac
Hi, I am planning to enable synced passkeys for Mac users. Because this feature relies on iCloud keychain, it will also let users apply the same passkey on personal devices linked to the same Apple account. Right now, users can already use same apple account it on their enterprise Mac, a situation we will address later. I would like to know whether we can limit synced passkeys to Mac only, even when users belong to a synced profile and use the same Apple account on other devices. Essentially, I aim to permit access on Mac while blocking it on iPad and iPhones. Like if their specific AADGUID we can use here or alternative ways