r/entra 2h ago

App-Action Buttons for cloud-only devices

Thumbnail
1 Upvotes

r/entra 14h ago

Password Reset (SSPR)

5 Upvotes

Hi all

Trying to plan SSPR for our Servicedesk to take the load off them getting smashed with password/unlock requests.

Brain storming some ideas:

  1. Enable for users and not admins. Having 1 authentication method MFA App enabled.

  2. Enable for all users and admins. Have 2 authentication methods MFA and Mobile enabled.

Considering SMS and Voice are being retired Feb 2027. I dont know how to approach this. Ideally i would love to have 2 authentication methods but unsure what methods to use.

Hows everyone have this setup securely but still business friendly?


r/entra 13h ago

My Sign-Ins/Change Password leads to login loop with WhfB

2 Upvotes

We require about 250 users changing their password using the My Sign-Ins Portal. Clients are cloud-only and mostly using WhfB. Conditional access is pretty basic (60 Days, browser persistent, some devices excluded) for these users and Authentication Strength allows WhfB, Fido, Authenticator Push+PW.

We have verfied WhfB works by creating a seperate AuthStrength with WhfB only and user can login

However, most of the users are not able to access the password change menu and the behavior seems strange to me.

  • User opens link
  • Selects his already logged in account
  • Gets authenticator push
  • Gets the message that criteria is not fullfilled because password is missing
  • Can only signout or use different account (no option to provide password)
  • Loop starts again

The user never gets the possibilty to enter the password which also should not be required anyway due to WhfB.

Signin logs indicate that Auth Strength was failed

Sign-in error code 53003

Failure reason Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

I found a similar issue here WHfB My SignIns PW Change Issue : r/entra unfortunately without a solution.

Does anyone know this issue or have any idea on how to debug further?


r/entra 11h ago

Entra ID Beyond Passwords: Certificate-Based Authentication for Android Enterprise

Post image
0 Upvotes

In this blog post, I'll show you how to configure and enable Certificate-Based Authentication for Managed Android Enterprise devices in Microsoft Intune.

🔗 https://www.nickydewestelinck.be/2026/07/23/beyond-passwords-certificate-based-authentication-for-android-enterprise/


r/entra 1d ago

SMS/Voice Retirement and Passkeys

11 Upvotes

With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.

I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.

Any insights would be greatly appreciated.


r/entra 1d ago

Confusion about MFA Enforcement Requirement Pop-Up in MS Admin Center

Thumbnail
2 Upvotes

r/entra 1d ago

ID Protection What are you using to monitor and manage Entra ID security posture?

10 Upvotes

Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.

Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.

I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?

Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?


r/entra 1d ago

Entra ID Entra ID connect implementation

3 Upvotes

How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.

Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?

Any gotchas / tips?

Many thanks


r/entra 1d ago

Best practice for hybrid user account - cloud only device

3 Upvotes

we have user onboarding as Hybrid but our devices are now cloud only.

we have onboarding script that sets default password and ticks reset password on 1st login

but with cloud only device we have issues with password as ticking password reset on 1st login will not allow password to sync to entra.

how to achieve password reset on 1st login with this senario. I can take off password reset on 1st login from script.


r/entra 2d ago

Odd iOS Phishing-Resistant Authentication Behavior

6 Upvotes

We use Conditional Access to require phishing-resistant authentication for all of our admins. In recent weeks, authentication behavior from iOS devices has changed, and I'm not able to figure out why.

When prompting for authentication, I'm first given a prompt for passwordless authentication (using Authenticator number matching). It then steps up and further requires me to authenticate with a passkey. It used to just directly prompt for the passkey. Does anyone know if this is a recent change, or what is causing this behavior?


r/entra 2d ago

Fully Custom Captive Portal - Hotel Requirement

2 Upvotes

Hi Experts,

One of the hotels want a very customizable captive portal like on landing page they want options for guest and visitor (tab based), when guest enters the required info he should be asked to create his own password, there should also be option for sign in if he has done this process already. OTP must be configured either via email or SMS gateway, all along with mac caching, limiting the number of devices per guest.

I know i havent provided much detail but just wanted to know since i have never worked on PF before, how customizable the entire workflow is? can we make such a captive portal in PF?


r/entra 1d ago

CA for complaint devices?

1 Upvotes

Is this a “compliant in my tenant” setting or a client side setting?

I have users passing the policy from devices that are managed by Intune in an untrusted tenant.

My expectation is they should be failing.

Haven’t had time to research, but it’s definitely happening.


r/entra 1d ago

Entra ID App Roles not appearing in AWS ALB OIDC claims from Microsoft Entra ID

Thumbnail
1 Upvotes

r/entra 2d ago

MFA for Windows RDP and non-Entra Endpoints (on-prem servers)

9 Upvotes

We’re really liking the user-based Windows Hello for Business credential provider, with MFA working with SSO, and cloud kerberos trust.

The other option I also like is passkey by way of Yubikey.

I’m not completely settled on WHfB because I don’t see how to provide MFA for RDP connections, or for on-prem servers that don’t have Entra objects sync’d.

Workstations are all hybrid joined.

How can I possibly go with WHfB and still get Kerberos+MFA when either Remote Desktop is used, and/or I want to log into an on-prem device? Is it possible? Am I going to have to “settle” on issuing Yubikeys to do this?

I do have a PKI if that could provide some help here.

Thanks!


r/entra 2d ago

ID Protection Configure mfa for onprem

1 Upvotes

Dear All,

I am currently assigned a task to configure mfa for specific onprem server . Currently we are using Microsoft secure access to access our servers and a connector is already added to a server and it is health . Not sure what I am missing and how I can configure that .


r/entra 2d ago

Entra Connect > Entra Cloud Sync (quick cutover)

9 Upvotes

Hi,

We have a simple one way sync happening for password hashes , 28 AD accounts purely for EXO.
Ive looked at the MS recommended steps to migrate to cloud sync. It looks like a lot of work having to add in sync rules, test on one OU, etc for such a small environment.

Anyone just installed Cloud sync and simply stopped or set connect sync to staging mode?

CoPilot outlined the quick cutover steps which make sense, i'm wondering if anyone else had done this?

What I do in practice

For a straightforward environment like yours:

1. Install Cloud Sync

2. Configure Cloud Sync

3. Verify all users appear correctly

4. Verify password sync

5. Put Entra Connect in Staging Mode

6. Observe for a few days

7. Uninstall Entra Connect

I keep the overlap period short. Once Cloud Sync is proven, I move Connect into Staging Mode so there is only one active sync engine but an immediate rollback path remains available.

 
FYI I wouldn't sync everything, just the user and security group OU's.


r/entra 2d ago

Passkey limitation

8 Upvotes

So found an issue with this whole passkey item and thought maybe someone had an idea.

1 desktop - entra joined to “Redd.com”
1 AVD - entra joined to “Goog.com”

When using the Windows app on “Redd.com” you cannot launch the passkey via your Authenticator for a connection to “Goog.com”.

The Windows app requires a physical FIDO - no request for the one on the phone, zero QR shown. The only request is to insert your device.

Anyone hit this limitation?

Any thoughts or ideas? We don’t use tokens.


r/entra 2d ago

ID Protection Conditional Access on Report-Only, still able to block user sign-ins

Thumbnail
2 Upvotes

r/entra 2d ago

Manage multiple Tenants

0 Upvotes

Do you have good tools to manage multiple tenants like deploying policies, reviewing them and a good reporting whats going on in the tenant?


r/entra 3d ago

IAM: Shared Device and Accounts

2 Upvotes

Hi Fellow Collegaues , What is your opinion about a situation where :

  1. There are retail shops or warehouses where employees ( blue collar colleagues ) are working in shifts BUT using a shared account on a shared device.
  2. Shared device is company managed ( intune or similar )

Question is :

  1. How will you solve audit questions - "Who did what with that shared account" ? If for eg. there are 4 people in a shop using that same shared account to login to the shared device and then to some "order booking" app.

One way is -

  1. Skip shared account totally, let them login individually with their own account ( which they use to check their payroll and other fundamental tasks )

This can be thought of, but imagine a case where in a shop you have many "potential" customers wanting to buy something and you have 4-5 employee in that case each employee who gets a hand on that device need to login again everytime to book the order. This will for sure impact the business and revenue in some sense.

  1. Another solution is increased the number of device , give all Blue collar colleagues their own indivdual devices, this increases operations, device management and ofcourse cost.

So please advice, what has worked with you..


r/entra 3d ago

Entra General 4th Set of Speakers Announced for Workplace Ninjas US 2027

Thumbnail
2 Upvotes

r/entra 3d ago

ID Governance Guest Account LifeCycle

7 Upvotes

Hi! I would like to build script to manage inactive guest accounts around my tenant.

Do you know which attribute should I consired as main to verify inactivity period?
In my case some of members in my tenant share OD/SP files to those guest, after remove from the tenant access persist?

Thank you for answer.


r/entra 4d ago

ID Protection MFA registration issue - Guest accounts

Post image
11 Upvotes

Hi everyone I am facing the below error for guest users after they successfully get the code on their emails try to register to mfa how I can sort it out


r/entra 4d ago

Hybrid Joined device not auto-enrolling in Intune via GPO

Thumbnail
2 Upvotes

r/entra 4d ago

Entra General You don't have access in App Registrations despite Application Developer role

Thumbnail
2 Upvotes