Filter
Exclude
Time range
-
Near
From Aman Jabbi - The ๐Ÿ‡บ๐Ÿ‡ธ data-center explosion is a Trojan horse for the United Nations Sustainability The ๐Ÿ‡บ๐Ÿ‡ธ data-center explosion is a Trojan horse for the United Nations Sustainability Agenda and its derivatives. #DigitalID #DigitalTransformation #UNSDG #ClimateLockdown #IoT #Geofencing #SmartCities #Tokenization #LandCapture #NAC #30x30 #WaterScarcity #EnergyScarcity #Biodiversity #LeastPrivilege #NIEO #Blockchain #ZeroTrust #DefaultDeny #ConditionalAccess #SmartContracts #TheGreatReset #InclusiveCapitalism #SocialImpactInvesting #Slaves4Life ๐Ÿ‘๏ธ
2
87
Still have users without #MFA in your org? Thatโ€™s like leaving your front door wide open. ๐Ÿ˜ฌ Discover the simple fix to ensure users complete MFA in #Microsoft365 and boost your secure score! ๐Ÿ‘‰ blog.admindroid.com/ensure-mโ€ฆ #EntraID #ConditionalAccess #AdminDroid #AuthenticatorApp
1
25
Your M365 default settings won't pass a SOC 2 Type II audit. Conditional access? Intune? External sharing controls? Auditors check all three. Reply "M365" and I'll DM the 15-point Microsoft 365 security checklist. #ConditionalAccess #Intune
54
#MFA for all users is not a #ConditionalAccess strategy. It doesn't stop a valid session token from a compromised account. It doesn't block legacy auth protocols that bypass MFA entirely. Get your free Conditional Access Policy template here: hubs.li/Q04d-Mqm0

1
9
๐ŸชŸ Microsoft 365 Baseline Security Mode is the โ€œsecure by defaultโ€ vibe without the chaosโ€ฆ but itโ€™s also Microsoftโ€™s scoreboard for what they think youโ€™re doing wrong. Goodโ€ฆ until you realize itโ€™s a roadmap, not a magic fix. windowsforum.com/threads/micโ€ฆ #ConditionalAccess
9
Finally: see every Conditional Access policy that applies to a user, group or app in one graph. EntraBoost's new Object Explorer maps the relationships native Entra ID hides across blades. Join the beta at entraboost.com. #Entra #ConditionalAccess #Microsoft365
13
1,653
Pratik Raval retweeted
๐Ÿ” Hunting for #ConditionalAccess bypasses and baseline scope enforcement in #MicrosoftEntra? โ€‰ConditionalAccessAudiencesโ€‰ logs every resource evaluated by CAP - but only as raw GUIDs. I built a KQL query that resolves them to names adds key signals. ๐Ÿ”— github.com/Cloud-Architekt/Aโ€ฆ
1
40
219
15,127
Think all your admin portals are protected by #ConditionalAccess? My Staff Portal is often left out when applying those protections. One compromised manager accountโ€”and multiple user accounts could be at risk.โš ๏ธ Learn how to secure it: blog.admindroid.com/secure-mโ€ฆ #AdminDroid #M365
3
67
ุญุชู‰ ู„ูˆ ูƒุงุชุจ ุฃุนู‚ุฏ ูƒู„ู…ุฉ ู…ุฑูˆุฑ ูˆุชุณุชุฎุฏู… ุงู„ู€ MFA.. ู‡ุฌูˆู… ุงู„ู€ Session Hijacking ูƒููŠู„ ุจุชุฌุงูˆุฒ ุฏูุงุนุงุชูƒ ุจุงู„ูƒุงู…ู„ ููŠ ุซูˆุงู†ู ู‚ุฑุงุตู†ุฉ ุงู„ุฅู†ุชุฑู†ุช ุงู„ูŠูˆู… ุตุงุฑูˆุง ูŠุชุจุนูˆุง ุฃุณุงู„ูŠุจ ุฃุฐูƒู‰ุ› ุจุฏู„ ู…ุง ูŠุญุงูˆู„ูˆุง ูŠุฎู…ู†ูˆุง ุงู„ุจุงุณูˆุฑุฏุŒ ุจูŠู‚ูˆู…ูˆุง ุจุณุฑู‚ุฉ ู…ู„ูุงุช ุชุนุฑูŠู ุงู„ุงุฑุชุจุงุท (Cookies) ุงู„ุฎุงุตุฉ ุจุงู„ุฌู„ุณุฉ ุงู„ู†ุดุทุฉ ู„ู„ู…ู†ุชู‚ู„ูŠู† ุฏุงุฎู„ ุงู„ุดุจูƒุฉ. ุงู„ู†ุชูŠุฌุฉุŸ ุจูŠู‚ุฏุฑูˆุง ูŠุชุฌุงูˆุฒูˆุง ุนู…ู„ูŠุฉ ุชุณุฌูŠู„ ุงู„ุฏุฎูˆู„ ุจุงู„ูƒุงู…ู„ ูˆูŠุฏุฎู„ูˆุง ู„ู„ู†ุธุงู… ูƒุฃู†ู‡ู… ุฃู†ุชุŒ ุฏูˆู† ุงู„ุญุงุฌุฉ ู„ู„ู…ุฑูˆุฑ ุนู„ู‰ ุตูุญุฉ ุงู„ุชุญู‚ู‚ ุฃูˆ ุทู„ุจ ุงู„ู€ MFA. ุนุดุงู† ู†ุญู…ูŠ ุฃุตูˆู„ ุงู„ุดุฑูƒุฉ ูˆุญุณุงุจุงุชู‡ุง ู…ู† ู‡ุงุฏ ุงู„ุฎุทุฑุŒ ุจู†ุนุชู…ุฏ ุนู„ู‰ ุงุณุชุฑุงุชูŠุฌูŠุชูŠู† ู‡ู†ุฏุณูŠุชูŠู† ุญุงุณู…ุชูŠู†: ๐Ÿ›ก๏ธ ุงู„ูˆุตูˆู„ ุงู„ู…ุดุฑูˆุท (Conditional Access): ุชู‚ู†ูŠุฉ ุฐูƒูŠุฉ ุฌุฏุงู‹ ุจุชุญู„ู„ ุณูŠุงู‚ ุชุณุฌูŠู„ ุงู„ุฏุฎูˆู„ ุจุงู„ูƒุงู…ู„ (ุงู„ู…ูˆู‚ุน ุงู„ุฌุบุฑุงููŠุŒ ู†ูˆุน ุงู„ุฌู‡ุงุฒ ุงู„ู…ุณุชุฎุฏู…ุŒ ูˆุชูˆู‚ูŠุช ุงู„ู…ุญุงูˆู„ุฉ) ู‚ุจู„ ู…ุง ุชุนุทูŠ ุงู„ุฅุฐู† ุจุงู„ูˆุตูˆู„. ๐Ÿ›ก๏ธ ุณูŠุงุณุฉ ุงู„ุญุฏ ุงู„ุฃุฏู†ู‰ ู…ู† ุงู„ุตู„ุงุญูŠุงุช (Least Privilege): ุงู„ู…ูˆุธู ุจูŠู…ุชู„ูƒ ูู‚ุท ุงู„ุญุฏ ุงู„ุฃุฏู†ู‰ ู…ู† ุงู„ุตู„ุงุญูŠุงุช ุงู„ู„ุงุฒู…ุฉ ู„ุฃุฏุงุก ูˆุธูŠูุชู‡. ู‡ุงุฏ ุงู„ุชูˆุฌู‡ ุจูŠู‚ู„ู„ ู…ุณุงุญุฉ ุงู„ู‡ุฌูˆู… ูˆูŠู…ู†ุน ุงู„ู…ู‡ุงุฌู… ู…ู† ุงู„ุชุญุฑูƒ ุงู„ุฌุงู†ุจูŠ (Lateral Movement) ุฏุงุฎู„ ุงู„ุดุจูƒุฉ ู„ูˆ ู†ุฌุญ ุจุงุฎุชุฑุงู‚ ุญุณุงุจ ูˆุงุญุฏ. ุจุฑุฃูŠูƒุŒ ู„ู…ุงุฐุง ูŠุณู‡ู„ ุชุฌุงูˆุฒ ุงู„ุนุงู…ู„ ุงู„ุซุงู†ูŠ ุงู„ู‚ุงุฆู… ุนู„ู‰ ุฑุณุงุฆู„ SMS ู…ู‚ุงุฑู†ุฉ ุจุงุณุชุฎุฏุงู… ุชุทุจูŠู‚ุงุช ุงู„ู…ุตุงุฏู‚ุฉ ุงู„ุจุฑู…ุฌูŠุฉ (ู…ุซู„ Authenticator Apps)ุŸ #SessionHijacking #ConditionalAccess #LeastPrivilege #CyberSec #NetworkSecurity #ุฃูƒุงุฏูŠู…ูŠุฉ_ุงุชุตุงู„ุงุชูŠ
3
196
#ไผๆฅญๅ…ฌๅผ็›ธไบ’ใƒ•ใ‚ฉใƒญใƒผ ใใฎใ‚ขใ‚ฏใ‚ปใ‚นใ€ ๆœฌๅฝ“ใซโ€œ่จฑๅฏใ—ใฆใ„ใ„ใ‚ขใ‚ฏใ‚ปใ‚นโ€ใงใ™ใ‹๏ผŸ ่ฆ‹ใˆใชใ„่„…ๅจใฏใ€ IDใ‹ใ‚‰ๅง‹ใพใ‚‹ใ€‚ โœ” ไธๆญฃใƒญใ‚ฐใ‚คใƒณ โœ” ็‰นๆจฉIDไนฑ็”จ โœ” ๆจฉ้™ๆ”พ็ฝฎ โœ” ็›ฃๆŸปไธ่ถณ ใใ‚Œใ‚‰ใ‚’้˜ฒใใŸใ‚ใ€ IDaaSใ‚ฌใƒผใƒ‡ใ‚ฃใ‚ขใƒณ่ตทๅ‹•ใ€‚ ๅฑฑๅดŽ่กŒๆ”ฟๆ›ธๅฃซไบ‹ๅ‹™ๆ‰€ ใ‚ฏใƒฉใ‚ฆใƒ‰ๆณ•ๅ‹™ ร— AzureๆŠ€่ก“ๆ”ฏๆด #IDaaS #ZeroTrust #MFA #ConditionalAccess
7
99
๐Ÿš€AccessLens v1.9.0 is live This release focuses on one thing: making token theft and identity abuse harder across Microsoft 365. Whatโ€™s new: ๐Ÿ›ก๏ธ Agent Identity gap checks for Microsoft 365 Copilot Agents & autonomous workload identities ๐Ÿ” Expanded Token Protection coverage validation for Exchange, SharePoint & Teams ๐ŸŽฏ Authentication Context checks for PIM role activation ๐ŸŒ Continuous Access Evaluation strict location enforcement analysis ๐Ÿ“ก Global Secure Access compliant network coverage checks โš ๏ธ Improved detection for adversary-in-the-middle and token theft exposure ๐Ÿ‘ค Expanded admin role detection across newer Entra roles Plus a range of analysis improvements and risk scoring updates. ๐Ÿ”— accesslens.co.uk #MicrosoftEntra #ConditionalAccess #CyberSecurity #IdentitySecurity #ZeroTrust #InfoSec #M365 #EntraID
2
11
1,139
๐Ÿ“ขBlog Post: Most geo-blocked Conditional Access setups eventually turn into a mess of permanent travel exceptions. โŒ Stale named locations โŒ Bloated exclusion lists โŒ โ€œTemporaryโ€ bypasses nobody audits Well, There is a better way: Time-bound travel exemption group with PIM. Access auto expires. No CAP edits required. New blog post ๐Ÿ‘‡ accesslens.co.uk/blog/travelโ€ฆ #EntraID #ConditionalAccess #ZeroTrust
3
16
80
6,279
๐Ÿšจ Your Conditional Access policies probably have blind spots. AccessLens Quick Scan is completely free and finds them in seconds. ๐Ÿ“ค Upload your CA policy JSON ๐Ÿ”’ No OAuth permissions ๐Ÿง  No sign-up required โšก Runs entirely in your browser Detect gaps, overlaps, risky exclusions, and misconfigurations before attackers do. ๐Ÿ”— accesslens.co.uk/upload #MicrosoftEntra #ConditionalAccess #ZeroTrust #InfoSec #MSP
7
94
8,548
๐Ÿ”’ย Secure Bits ๐Ÿ’ก ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ-๐—ด๐—น๐—ฎ๐˜€๐˜€ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€: ๐—ณ๐˜‚๐—น๐—น ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒ (๐—ฃ๐——๐—™) In my last post I talked about the โ€œworst dayโ€ scenario:ย CA misconfig โ†’ admins locked out. Most orgs think theyโ€™re coveredโ€ฆ until they test it. As promised, ๐—ต๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐—น๐—น ๐—ฃ๐——๐—™ ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒย that walks you through aย practical break-glass setup: โ–ช๏ธ Naming โ–ช๏ธ Permissions โ–ช๏ธ Role-Assignable Security Group โ–ช๏ธ Custom Break-glass Administrator role (Optional) โ–ช๏ธ Restricted Management Administrative Unit (RMAU) โ–ช๏ธ Authentication Methods โ–ช๏ธ Conditional Access Configuration โ–ช๏ธ Monitoring & Alerting โ–ช๏ธ Operational Procedures ๐Ÿ“Žย Download the PDF here: academy.horizon-secured.com/โ€ฆ ๐˜ˆ๐˜ถ๐˜ต๐˜ฉ๐˜ฐ๐˜ณ:ย Martin Strnad ๐Ÿ’ฌ When was the last time you tested your break-glass access? #EntraID #IdentitySecurity #ConditionalAccess #SecureBits #HorizonSecured
13
95
6,545
"Apply and wait" isnโ€™t a testing strategy. But there is a better way! Entra IDโ€™s #WhatIf tool lets you simulate how a #ConditionalAccess policy will behave for a user, app, or location, before it goes live. Try it ๐Ÿ‘‡ blog.admindroid.com/what-if-โ€ฆ #EntraID #AdminDroid #CAPolicy
2
114
๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐˜๐—ฒ๐—ป๐—ฎ๐—ป๐˜ ๐—ต๐—ฎ๐˜€ ๐—–๐—” ๐—บ๐—ถ๐˜€๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป. ๐—˜๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ฎ๐—ฑ๐—บ๐—ถ๐—ป ๐—ถ๐˜€ ๐—น๐—ผ๐—ฐ๐—ธ๐—ฒ๐—ฑ ๐—ผ๐˜‚๐˜. ๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ต๐—ฎ๐˜ƒ๐—ฒ ๐—ฎ ๐˜„๐—ฎ๐˜† ๐—ฏ๐—ฎ๐—ฐ๐—ธ ๐—ถ๐—ป? Most organizations donโ€™t โ€” or think they do, until they discover their break-glass accounts are untested, unmonitored, or built on outdated guidance. You donโ€™t want to find that out the hard way, and you definitely donโ€™t want to go through Microsoftโ€™s Tenant Recovery process. ๐Ÿค” ๐—ช๐—ต๐˜† ๐—ฐ๐—ฎ๐—ฟ๐—ฒ? A lockout from a bad CA policy, a compromised admin, or a personnel emergency means opening a support ticket with Microsoft and waiting. In urgent situations, you donโ€™t have 14 days for that process. ๐Ÿง  ๐—ช๐—ต๐—ฎ๐˜ ๐˜„๐—ฒ ๐˜€๐—ฒ๐—ฒ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—ณ๐—ถ๐—ฒ๐—น๐—ฑ โ€ข๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ-๐—ด๐—น๐—ฎ๐˜€๐˜€ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—บ๐—ถ๐˜€๐˜€๐—ถ๐—ป๐—ด โ€” Two geographically separated accounts is the baseline. โ€ข๐—š๐—ฒ๐—ป๐—ฒ๐—ฟ๐—ถ๐—ฐ ๐—ป๐—ฎ๐—บ๐—ฒ๐˜€ โ€” admin@โ€ฆ, info@โ€ฆ are not break-glass accounts. โ€ข๐—™๐˜‚๐—น๐—น ๐—–๐—” ๐—ฒ๐˜…๐—ฐ๐—น๐˜‚๐˜€๐—ถ๐—ผ๐—ป ๐—ถ๐˜€ ๐—ฑ๐—ฒ๐—ฎ๐—ฑ โ€” MFA is now enforced by Microsoft regardless. โ€ข๐—ช๐—ฒ๐—ฎ๐—ธ ๐—ฎ๐˜‚๐˜๐—ต ๐—บ๐—ฒ๐˜๐—ต๐—ผ๐—ฑ๐˜€ โ€” Phone or certificate-based auth will fail exactly when you need it. โ€ข๐—จ๐—ป๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ โ€” Any admin can edit or delete them. โ€ข๐—ก๐—ผ ๐—บ๐—ผ๐—ป๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ป๐—ด โ€” If someone touches these accounts, you should know immediately. ๐Ÿ› ๏ธ ๐—–๐—ฟ๐—ฒ๐—ฎ๐˜๐—ฒ ๐˜๐˜„๐—ผ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ Use descriptive names on onmicrosoft[.]com with a random string โ€” e.g. BreakGlass_c3287ba1@org.onmicrosoft.com. Assign ๐—š๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐—ถ๐˜€๐˜๐—ฟ๐—ฎ๐˜๐—ผ๐—ฟ as a direct, permanent, active role. No eligibility. ๐Ÿ› ๏ธ ๐—Ÿ๐—ผ๐—ฐ๐—ธ ๐˜๐—ต๐—ฒ๐—บ ๐—ฑ๐—ผ๐˜„๐—ป Place both accounts and their group inside an ๐—ฅ๐— ๐—”๐—จ (requires Entra P1). Manage access via a custom PIM role โ€” max 1-hour activation, approval required, auth context enforced (requires Entra P2). ๐Ÿ› ๏ธ ๐—–๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ ๐—ฎ๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป Scope a passkey profile to the break-glass group with specific AAGUIDs for your hardware keys (YubiKey, Token2). Enforce via a custom authentication strength in a dedicated CA policy. Exclude the group from all other CA policies โ€” run a What If to verify only your two break-glass policies apply. ๐Ÿ› ๏ธ ๐—ฆ๐—ฒ๐˜ ๐˜‚๐—ฝ ๐—ฎ๐—น๐—ฒ๐—ฟ๐˜๐—ถ๐—ป๐—ด Stream AuditLogs and SignInLogs to a Log Analytics Workspace (requires Azure subscription). KQL alert rule on the break-glass Object IDs โ€” any event fires immediately. ๐Ÿ›ก๏ธ ๐—ฆ๐˜๐—ผ๐—ฟ๐—ฒ, ๐˜๐—ฒ๐˜€๐˜, ๐—ฑ๐—ผ๐—ฐ๐˜‚๐—บ๐—ฒ๐—ป๐˜ Each passkey PIN in a separate physical location. Define who can trigger the procedure and under what circumstances. Test end-to-end at minimum every 180 days โ€” Microsoft recommends 90. Pick your cadence, but validate. ๐Ÿ’ฌ When was the last time you tested these accounts? ๐˜ˆ๐˜ถ๐˜๐˜ฉ๐˜ฐ๐˜ณ: Martin Strnad PS: We will soon ๐—ฝ๐˜‚๐—ฏ๐—น๐—ถ๐˜€๐—ต ๐—ณ๐˜‚๐—น๐—น ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒ on this topic! #EntraID #IdentitySecurity #ConditionalAccess #SecureBits #HorizonSecured
2
25
141
8,665
๐Ÿ›ก๏ธ AccessLens Baseline Builder ๐Ÿ”— accesslens.co.uk Stop guessing which Conditional Access policies you need. Start building against real standards. Baseline your tenant in minutes, not weeks. ๐Ÿ“š Microsoft, CIS, CISA, NCSC, Maester framework โœ… Guided checklist of required CA policies ๐Ÿ“Š See progress against each framework instantly ๐Ÿ”„ Update once - every framework stays aligned ๐Ÿš€ Ideal for new tenants or security uplift projects ๐Ÿงญ Every recommendation explained Build a compliant baseline. Without reinventing it. No uploads. No storage. No risk. #MicrosoftEntra #ConditionalAccess #ZeroTrust #InfoSec
1
2
51
4,414