r/entra • u/Limp_Substance4433 • 7h ago
r/entra • u/Sufficient-Pace7542 • 13h ago
SMS/Voice Retirement and Passkeys
With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.
I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.
Any insights would be greatly appreciated.
r/entra • u/WeirdoInTheShadow • 16h ago
Entra ID Entra ID connect implementation
How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.
Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?
Any gotchas / tips?
Many thanks
r/entra • u/NathanSecurity • 20h ago
ID Protection What are you using to monitor and manage Entra ID security posture?
Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.
Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.
I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?
Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?