π¨ Entra Conditional Access gotcha from Andres Canello Selecting every device platform β βAny device.β An attacker can spoof the browser user-agent, get no platform match, and that CA policy condition wonβt apply. Watch Entra.Chat with for more nuggets π entra.news/p/the-ult...
Merill Fernando π
@merill.net
Product Manager @microsoft | Creator of bluesky.ms β’ cmd.ms β’ idPowerToys.merill.net β’ Graph X-Ray β’ π¦πΊ β’ π±π° β’ Posts my own http://youtube.com/@merillx Sign up to my newsletter https://entra.news
π§ Folks, weβre planning a major architecture change for Maester 3.0: a native test model with structured metadata, simpler contributions, centralized prerequisite handling, and compatibility for existing Pester tests. We want your feedback before finalizing the design π
RFC: A Maester-native test model for Maester 3.0 Β· maester365/maester Β· Discussion #2050
RFC: A Maester-native test model for Maester 3.0 Status: We have decided on the overall direction, but the design and migration experience are still open for community input. We are planning a sign...
github.com
Iβll be honest. Purview has always felt like someone elseβs part of the Microsoft security stack. Iβm an Entra person. Ray Reyes isnβt, and thatβs why I wanted him on Entra.Chat The lines between our products and teams are disappearing.
Folks, Maester 2.2 is here!! It was just a couple of months ago when we launched Maester 2.0 and the amazing Maester community has been SUPER busy.
Putting the final touches on the upcoming π₯ Maester 2.2 release and look at this! A new Contributors page dedicated to the awesome community of folks that make Maester what it is today. Check it out and click through to the detail page of each author. maester.dev/contribu...
π Check out this new Microsoft Entra blog post π Modernize SAP Identity Management with Microsoft Entra techcommunity.microsoft.com/t5/microsoft...
Modernize SAP Identity Management with Microsoft Entra
See how Microsoft Entra and SAP help automate provisioning, strengthen governance, and modernize access across SAP and non-SAP applications.
techcommunity.microsoft.com
π Check out this new Microsoft Entra blog post π Microsoft Entra ID enhances security of branded sign-ins techcommunity.microsoft.com/t5/microsoft...
Microsoft Entra ID enhances security of branded sign-ins | Microsoft Community Hub
Microsoft Entra ID blocks custom CSS positioning properties to help deliver more secure and trusted branded sign-ins. [Action may be required]
techcommunity.microsoft.com
I was explaining how Microsoft Entra Staged Rollout works and realised it would make a great video especially the under-the-hood details that arenβt in the docs. A quick 7-minute walkthrough is coming soon. What would you like me to cover? π
Huge Entra News this week. Microsoft announced plans to phase out SMS and Voice from Entra and passkeys becoming the default. 1/3
π Check out this new Microsoft Entra blog post π AI agents are everywhere. Are your access controls ready? techcommunity.microsoft.com/t5/microsoft...
AI agents are everywhere. Are your access controls ready?
AI agents are multiplying fast. See what 150 identity pros said about sprawl, shadow AI, and governance at Identiverse 2026.
techcommunity.microsoft.com
We just added GitHub to the list of products that Maester monitors the security configuration for. These are CIS tests too!
The best time to set up security tests for your Entra tenant is when you create it The next best time is today π I'm spinning up Entra External ID tenants for maester.cloud (my SaaS solution), & every one gets Maester baked in from day one π₯ Maester monitoring Maester Cloud. As it should be 1/3
One compromised Agent ID blueprint can become a multitenant blast radius. That is the most important idea in my latest conversation with Katie Knowles, Senior Security Researcher at Datadog, about her three-part security analysis of Microsoft Entra Agent ID. Watch or listen: https://entra.chat
Me teaching Entra Workload ID Federation to Sol. Fable made the same mistake too. All those badly coded auth code is tripping up the LLMs. For reference this is the article I linked to devblogs.microsoft.c...
π Check out this new Microsoft Entra blog post π Govern AI agent identities and access the same way you govern your employees techcommunity.microsoft.com/t5/microsoft...
Govern AI agent identities and access the same way you govern your employees | Microsoft Community Hub
Use Microsoft Entra Agent ID to assign accountable identities, control agent access, and automate sponsor lifecycle management at scale.
techcommunity.microsoft.com
AI agent risk is not just attackers using AI. It is attackers targeting the agent ecosystem most orgs cannot see yet: MCP servers, skills, packages, API keys, tool calls, and prompts. I talked with Thomas Roccia about the new blind spot: 1/8
π Check out this new Microsoft Entra blog post π Bring business logic into PIM role activation workflows techcommunity.microsoft.com/t5/microsoft...
Bring business logic into PIM role activation workflows | Microsoft Community Hub
Use PIM custom extensions to validate tickets, enforce HR policies, and automate approval decisions during role activation.
techcommunity.microsoft.com
π Check out this new Microsoft Entra blog post π Microsoft Entra Backup and Recovery is now generally available techcommunity.microsoft.com/t5/microsoft...
Microsoft Entra Backup and Recovery is now generally available | Microsoft Community Hub
Move from point-in-time restore to a full tenant recoverability strategy with Microsoft Entra Backup and Recovery, included in Entra P1 and P2.
techcommunity.microsoft.com
π Folks "passkeys won't save you." Vince Smith, who leads Agent ID at Microsoft Entra, explains why: squeeze one end of the balloon (users) and attackers move to the other π NHI + workloads. New Entra Chat π entra.news/p/from-wi...
π Check out this new Microsoft Entra blog post π Secure AI at scale: Join the Microsoft Entra + Purview webinar series techcommunity.microsoft.com/t5/microsoft...
Secure AI at scale: Join the Microsoft Entra + Purview webinar series | Microsoft Community Hub
Learn how to protect data, govern access, and reduce risk across AI apps, agents, browsers, and networks with Microsoft Entra and Microsoft Purview.
techcommunity.microsoft.com
Tiny AI workflow hack that saves me every day Pin your top 3 active chats and give each one an emoji. Now you can switch contexts instantly without hunting through old threads. Works with ChatGPT, Codex, Claude, Cursor, GitHub CP or any tool where projects pile up. Simple, but underrated.
Not every admin in your tenant is a person. π Erica Zelic and I break down the "shadow admins" apps, service principals & agent identities quietly holding the keys to your Entra tenant. New Entra Chat episode: entra.news/p/shadow-...
AI agents should not get a blank check to your tenant. I added experimental Guardrails to Lokka.dev so you can limit model-driven Microsoft Graph/Azure calls by HTTP method, API path, tenant, or specific resources. β When something is blocked, Lokka shows exactly why and where to fix it.
For years, "secure" meant MFA + a compliant device. AI agents just broke that. They decide and act faster than any human the split-second of latency that used to give you time to react is gone. An agent can run away with your data before you read the alert. 1/3
π Lokka Guardrails is a new feature coming to the MCP server π This puts you in control of what the AI can do. The problem with Graph permission scopes is they are too broad. Now you can apply more precision to what is allowed even if it has a token with all the perms. 1/2