Eric Woodruff

@ericonidentity.com

Entra nerd currently @ #Semperis. Parent. Partner. MS Security MVP. Views are those of my cat.

I’ve been finding the #Entra Usage & Insights report useless lately when it comes to #passkey reporting. Why? It’s broken. It’s concerning that this seems to be an ongoing issue that isn’t tenant specific and Microsoft hasn’t caught it. #EntraID ericonidentity.com/2025/09/02/e...

Entra Useless Insights Report - Eric on Identity

Exploring the Entra Usage & Insights report on MFA usage, and the issues with the reports lack of accuracy, as well as a workaround.

ericonidentity.com

Yesterday morning, I woke up to an email from Microsoft with the subject "Congratulations on your Microsoft MVP award". I immediately thought it was a phish, but I dug a bit further. It's real! 🤯 I was selected as an MVP in "PowerShell" and "Identity & Access"!

Bild

If you consume multi-tenant apps in #EntraID, and they’ve been granted consent to do things in your tenant, you can spy on the auth choices your vendor makes - secrets or certs - in the logs available in your #Entra tenant. #infosec #m365 #azure ericonidentity.com/2025/01/13/s...

Spying on your ISVs credential choices - Eric on Identity

Examining Entra ID sign-in and graph activity logs to determine what type of credentials your ISVs use in their multi-tenant applications.

ericonidentity.com

With all the speaking I burnt and crashed a bit towards the end of 2024. I plan on writing about the speaking experience… but first hoping to get back into writing more as I research stuff. Hope to have both a personal blog and Semperis blog article out this week 🤞.

Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃