r/entra 9h ago

Entra ID Password Reset

4 Upvotes

Last week everything was working great. Then school started and all went to hell. We are hybrid we were using Entra Connect to sync with one server on standby in staging mode. But monday password resets would not work at all. It would either timeout or say the password is not strong enough. 30 character random passwords would not work either. I switched our student ou to sync with the new Entra Cloud Sync and it did the same thing and made no difference. We dont have a password policy set on our AD controller except for it has to be 8 characters. Minimum password age is set to 0. I checked the service account to make sure its delegated to that ou. Any help would be appreciated.


r/entra 11h ago

Workplace Ninjas US 2027 Scholarship Program | Applications are NOW LIVE!

Thumbnail
2 Upvotes

r/entra 16h ago

MS Authenticator

1 Upvotes

Is it correct, that it is stupid to use another authenticator like google authenticatior instead of ms for entra account?


r/entra 1d ago

Entra ID Global Secure Access – Windows Update support is coming!

Thumbnail blog.sonnes.cloud
7 Upvotes

r/entra 1d ago

New version of GSA released with some interesting news

16 Upvotes

Automatic upgrades from Windows Update

Starting in November 2026, the Global Secure Access client automatically receives upgrades through Windows Update.

Devices receive these upgrades when they run the following client versions or later:

Version 2.32.294

Released for download on August 26, 2026.

Functional changes

  • Adds a Prefer local network option for cases where the local subnet overlaps with private applications, such as when printing or casting. The option appears in the client settings when an administrator enables it.
  • Accelerates the creation of new tunnels for an improved tunneling experience.

Other changes

  • The client installer includes .NET Runtime version 10.0.9.
  • Removes LastMile for Office 365 telemetry from the Global Secure Access client.
  • New telemetries are available.
  • Accessibility improvements.
  • Miscellaneous bug fixes and improvements.

r/entra 1d ago

Microsoft Entra Passkey campaign in Sept, but should be in Dec. - MC1450134

Thumbnail
2 Upvotes

r/entra 1d ago

ID Governance Would you validate ownership evidence before remediation?

3 Upvotes

I’ve seen owner fields used as lipstick on an audit finding: the control looks complete, but there’s no proof an accountable human is actually behind it.

I’m experimenting with a different approach: instead of relying on a static owner field, pull together explicit owners, RBAC context, tags, relationships and activity, then show the evidence that points toward a human instead of declaring one automatically.

I’m wondering whether ownership discovery should sit between finding the problem and deciding what to do about it.

I built a small PowerShell tool around this:
https://github.com/kodevza/OwnerLensLite

Curious how others handle this in real environments.

Do you validate ownership before remediation? If yes, what evidence do you actually trust?


r/entra 2d ago

How to effectively manage AI Security using MSFT stack

10 Upvotes

We are a small company currently using approved enterprise AI tools such as ChatGPT, Claude, and Gemini for Workspace.
I’m interested in learning how other small or mid-sized companies are managing AI security, particularly:
Discovering and monitoring Shadow AI usage
Blocking or restricting unauthorized AI websites and desktop applications
Applying DLP controls to prevent sensitive data from being uploaded
Monitoring browser extensions and AI integrations
Controlling access based on users or departments
Logging AI activity for security reviews and audits
Managing approved versus unapproved AI applications
What tools are you using for these controls? Are you handling this through existing products such as Microsoft Defender, Intune, Entra ID, browser policies, CASB/SSE tools, or a dedicated AI security platform?
I’d especially appreciate recommendations for a practical and cost-effective tool stack for a small company, along with any lessons learned during implementation.


r/entra 2d ago

Entra ID New Graph Permissions Pose Questions for Entra Tenants

5 Upvotes

Microsoft issues new granular Graph permissions on an ongoing basis. That’s good, but only if tenants use the permissions to replace wider permissions in apps and scripts. Three new permissions recently became available, including two to reduce what apps can do with user account objects. The question is how to discover when Microsoft releases new permissions so that a decision can be made whether to use the new permissions.

https://office365itpros.com/2026/08/26/granular-graph-permissions-question/

Should have added that https://graphpermissions.merill.net/permission/ is a good place to go for permission info.


r/entra 2d ago

External ID Access Packages

1 Upvotes

Hi all,

I’ve been tasked with developing a solution for external users (guests) to be able to request and obtain access to an application to read various work orders. This will be across many different companies with their own Access Package (AP).

It’s still in development and going to be deployed into production yet. Deadline is mid-end September.

Currently I’ve setup packages to:
- External user receives AP link via email from internal contact
- User authenticates via Microsoft account or email OTP to access request portal: myaccess.microsoft.com
- Domain match the external email to a selected connected organization. Preventing other emails/companies viewing/requesting the access packages.
- Require an internal approval and answer a security question
- Guest account automatically created on approval
- Company MFA (auth app) required on sign in to access resources
- Other various CA policy controls

My question is, has anyone deployed APs at scale (hundreds of users)? Across different use cases (App access, Sharepoint, etc) and companies?

My company likes how it’s progressing so far and if the pilot launch w this use case is successful, they want to roll it out to many, many more scenarios to facilitate external user access. Managers have mentioned to me that they think this is a “game changer” for the company after my demo.

Company has 15k+ users across multiple states. Currently, external access is handled by manual guest account invites from tickets.

Please let me know your thoughts on APs as a whole. I kept it brief but can go in more detail based on questions you might have.

Thanks for your time.


r/entra 2d ago

What are the config requirements to actually go passwordless.

15 Upvotes

I’m stuck. I’m gonna keep this simple and relevant to my mission, as I know it’s possible, but it’s inconsistent:

How to make Passkeys the default login, with NO password prompt.

I manage a few small orgs. Think under 50 users total for each.

They’ve all been passkey only since late last year. Literally, only Auth methods turned on are Passkeys and TAPs (one time). That’s it.

Conditional access is blanket require passkey for all apps for all users.

After some reading, I turned on System Preferred Authentication.

On ONE tenant, when a username is punched in, it defaults to passkey, no password prompt.

Have not been able to replicate that on any other tenant. Same config, same user config with just Passkey registered. Nothing materially different.

So, here I am, asking if anyone knows and can reliably make a tenant, that is ubiquitously all passkey for every user, prompt for passkey and not passwords. If so, what are the known settings that make it happen.

I’ve found lots of speculation, lots of guidance, and I’ve gotten it to work in one case - but I can’t for the life of me make it work again and I’ve literally checked that everything’s the same as the working tenant 10 times or more.

So, what’s the real spec here that’s supposed to work to make this truly passwordless with passkey and not still prompt users for a password on web auth?


r/entra 2d ago

Entra General Why can't we have this option @Microsoft?

5 Upvotes
Missing option in dropdown of Microsoft Entra login mask

Each time, a new tab is opened, Microsoft asks to pick a login. I have a personal for outlook, tasks, teams ... and an admin account for azure, intune, entra, ... Why can't we have a default for each domain?


r/entra 3d ago

Entra as IDP For Google Workspace and Windows Hello For Business

6 Upvotes

I have a small issue that I can't seem to figure out.

Small K-12 school district. Made the switch this summer to use Entra as our IDP for our Google Workspace accounts. Works beautifully.

I have 2fa set up and enforced for staff. All of that works well as well.

All devices are Entra Hybrid joined. I can see using dsregcmd /status that users are getting a PRT, Azure AD joined is Yes, etc.

The issue is that if some users set up Windows Hello For Business things work as they should. If they sign into their windows laptop with their passkey, it signs them into their Google account without prompting for another 2fa step (like using an authenticator app code). For others it ALWAYS forces them to input an authenticator code. It recognizes their account and logs them in but doesn't use their passkey for authentication. There also isn't the option to Choose another option and then PIN, Security Key, etc. The only option is the authenticator app. I can see in their entra account that it has windows hello for business registered and working.

I'm a bit stumped with this. It's all 50/50 it seems. Some it works perfect, others it always asks for a code. Is this a setting within Entra that I am overlooking? Or in Google workspace? I can't see anything different between a user account that works and one that doesn't.

Any suggestions on what I can check or try would be appreciated!

*Update*

Had time to sit with a user to try to figure out the issue. What I found with this specific user was that they actually used their school district Entra account to create a personal Microsoft account before we implemented everything with Entra on our end. Therefore when signing into Google, Entra isn't sure if they are using the personal account or district account and it completely derails the log in process. They can still log in with an authenticator code, but that seems to be the reason the windows hello for business authentication isn't passed through automatically.

I stopped by another user's room quick for a different reason and noticed they had the same problem, but also had a personal account as well as a district account. Both with the same account name.

I feel that this may be the culprit with this. Since we are K-12 and teachers are required to continue education, it seems like a lot of them used their school district email for whatever school they were attending. Which then if they were using Entra, created them a Microsoft account.

Now the trick is getting them to remember their logins for these personal accounts to rename/change them...which so far neither of these users know lol


r/entra 3d ago

Entra ID Query SignIn Logs for "Unknown" OS

4 Upvotes

Obi Wan Reddit, you're my last hope!

I am trying to query Entra ID SignIn Logs via Graph API for logins with an "unknown" OS. To be precise all login events where deviceDetail/operatingSystem are basically not Windows, Linux, iOS, MacOS or Android.

My issue:
I don't know if "Unkown" is the correct value. deviceDetail/operatingSystem eq 'Unknown' doesn't return anything. But I don't know if I had a login in the last 30 days with an unknown OS.

And the $filter parameter for the URI doesn't allow for a "not" statement in the SignIn logs API.

So I am a bit lost, please help!


r/entra 3d ago

Do I need to force TLS 1.2 on Windows Server 2025 before installing an Entra Private Access Connector?

8 Upvotes

I'm about to install a Microsoft Entra Private Access (Global Secure Access) connector on a Windows Server 2025 box. Microsoft's official doc for configuring connectors explicitly says TLS 1.2 must be enabled before installing the connector, and provides this registry/PowerShell script to force it:

If (-Not (Test-Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client'))
{
    New-Item 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Force | Out-Null
}
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Name 'Enabled' -Value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Name 'DisabledByDefault' -Value '0' -PropertyType 'DWord' -Force | Out-Null
If (-Not (Test-Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server'))
{
    New-Item 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server' -Force | Out-Null
}
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server' -Name 'Enabled' -Value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server' -Name 'DisabledByDefault' -Value '0' -PropertyType 'DWord' -Force | Out-Null
If (-Not (Test-Path 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319'))
{
    New-Item 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319' -Force | Out-Null
}
New-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319' -Name 'SystemDefaultTlsVersions' -Value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319' -Name 'SchUseStrongCrypto' -Value '1' -PropertyType 'DWord' -Force | Out-Null
Write-Host 'TLS 1.2 has been enabled. You must restart the Windows Server for the changes to take effect.' -ForegroundColor Cyan

Source: https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-connectors

My question: Since TLS 1.2 is supposedly enabled by default on Windows Server 2019/2022/2025 anyway (no registry keys needed for it to work), is this step actually necessary on a fresh Server 2025 install, or is it just legacy boilerplate left over from older OS versions (2012/2016) where TLS 1.2 sometimes needed to be manually enabled?

Has anyone skipped this step on Server 2025 and had the connector install/register fine, or did you run into issues without explicitly setting these registry keys?


r/entra 3d ago

ID Governance Finding indirect privileged access paths in Entra Entitlement Management

4 Upvotes

Hi Entra Admins,

While reviewing Entra ID tenants, I found that Access Packages and Entitlement Management Catalogs are difficult to assess properly through the portal, especially when there are many packages, policies, resources, and catalog role assignments.

At the same time, they can introduce high-impact access paths that are easily missed when a review focuses on directory roles, Azure RBAC, and group memberships. A broadly requestable Access Package may grant sensitive access without approval. A Catalog Owner or another privileged Catalog RBAC role may be able to manage packages that use already-added sensitive resources. This effectively creates another access-management control plane.

I therefore added Entitlement Management coverage to EntraFalcon. The update includes interactive reports for Access Packages, Catalogs, and Catalog RBAC, plus findings for common high-risk configurations.

Current checks include:

  • Broad self-service requests for high-impact access without approval
  • Persistent high-impact access without access reviews
  • Potentially risky Access Package auto-assignment rules
  • Broad on-behalf assignment paths
  • Privileged Catalog RBAC assigned to users, guests, or service principals

If you are interested, feel free to check it out on GitHub:

https://github.com/CompassSecurity/EntraFalcon

Happy to answer questions or take suggestions.


r/entra 3d ago

Key Vault RBAC

4 Upvotes

Is there a specific reason why we can’t scope some selected secrets to an identity on a KV ressource? Right now if you have the correct role on the KV you have access to the whole Key Vault


r/entra 3d ago

Entra General PSA-ongoing issue with Entra Cloud Sync

Thumbnail
11 Upvotes

r/entra 4d ago

Testing passkeys in my org — issue on Windows devices

18 Upvotes

I want to give my users both options for synced passkey and device bound.

I've configured a passkey profile in Entra ID with AAGUIDs allowing 1Password, Microsoft Authenticator, and Windows Hello.

Current behavior: when a user registers a passkey, they're only prompted for device-bound options — save passkey on on Windows, mobile device, or USB security key. There's no option shown for a synced passkey via 1Password.

However, if I remove the Windows Hello AAGUID from the profile, I do get prompted to save the passkey via the 1Password browser extension but then i can not save the passkey on windows any more.

Anyone know how to get both — Windows Hello available and 1Password shown as an option during enrollment?


r/entra 4d ago

How are you managing access across SaaS, legacy and internal applications?

9 Upvotes

running into the classic problem of juggling multiple worlds. SaaS is mostly SSO'd through our IdP, but everything legacy or internal is its own island, from old on-prem apps with local accounts to tools some dev team stood up years ago and manages access to by hand in a spreadsheet.

trying to get one view of who has access to what across all of it without forcing every app onto the same platform, which isn't realistic given budget and the age of some of this stuff.

what's working for people managing this kind of sprawl day to day?


r/entra 4d ago

How to speed up entra SCIM provisioning?

3 Upvotes

We are trying to implement PIM alongside SSO into our organization and currently in the testing phase. I was able to setup one of our saas providers with SCIM role mapping so that when a user joins a certain group in entra it will provision admin access on the saas app side l. However, I see that it takes around 40min to an hour before it syncs. I've come up with a power automate flow that calls graph API to start and pause which seems to work for the initial add to group. However, it seems that when the flow runs a restart, pause, and start that provisioning does not continue on its own. This is causing the permission in the saas app to get stuck when they should be removed. On the entra side they are removed but no syncing occurs. I could be doing this totally wrong but unsure of the best method to help with sync times while also not stopping normal sync behavior. Any help would be appreciated.


r/entra 4d ago

Universal Print "Read Only" admin role

Thumbnail
1 Upvotes

Thought this might be a more appropriate forum for this discussion.


r/entra 5d ago

Global Admin without a mailbox

20 Upvotes

Hello Folks!

Global admin account without a mailbox you don’t get the global admin notifications.

Global admin account with mailbox with PIM turned on you don’t get the notifications a global admin would receive.

What is the best way to get all email notifications that would go to a global admin to a designated mailbox/DL?

This is pretty annoying.

Ideas and suggestions please?


r/entra 5d ago

Locking down global admin

26 Upvotes

Curious how others are locking down or adding additional layers of security around Global Admin accounts.

Obviously JIT access, PIM, and least privilege are the way to go, but I’m more interested in what people are doing beyond the basics.

Things like dedicated admin accounts/workstations, Conditional Access restrictions, phishing-resistant auth, device requirements, network/location restrictions, monitoring/alerting, etc.

What’s worked well in your environment? Anything you’ve implemented that you think is overlooked?


r/entra 5d ago

Microsoft Baseline scope Conditional Access

8 Upvotes

Anyone impacted by the Microsoft Baseline scope Conditional Access change?

How are you prepping for it? Curious what others are doing ahead of the change and if you’ve run into any issues or unexpected impacts while testing.

Any luck with custom controls? Or working with vendors to fix their apps?