<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Entra ID on Anything About IT</title><link>https://www.verboon.info/tags/entra-id/</link><description>Recent content in Entra ID on Anything About IT</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 28 Apr 2024 12:25:01 +0000</lastBuildDate><atom:link href="https://www.verboon.info/tags/entra-id/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Defender for Endpoint - Security Settings Management Internals 0x1</title><link>https://www.verboon.info/2024/04/microsoft-defender-for-endpoint-security-settings-management-internals-0x1/</link><pubDate>Sun, 28 Apr 2024 12:25:01 +0000</pubDate><guid>https://www.verboon.info/2024/04/microsoft-defender-for-endpoint-security-settings-management-internals-0x1/</guid><description>&lt;p&gt;In this post, we take a closer look at how &lt;strong&gt;Microsoft Defender for Endpoint Security Settings Management&lt;/strong&gt; works behind the scenes, especially for Windows Server scenarios.&lt;/p&gt;
&lt;h2 id="entra-id-device-registration"&gt;Entra ID Device Registration&lt;/h2&gt;
&lt;p&gt;Because Intune policy assignment is group-based, devices need an object in Entra ID. If a server already has an existing registration (for example Hybrid Join), that object is reused. If not, a synthetic device identity is created in Entra ID so the device can retrieve policy.&lt;/p&gt;</description></item><item><title>Users can create AzureAD tenants</title><link>https://www.verboon.info/2022/11/users-can-create-azuread-tenants/</link><pubDate>Tue, 22 Nov 2022 22:13:09 +0000</pubDate><guid>https://www.verboon.info/2022/11/users-can-create-azuread-tenants/</guid><description>&lt;p&gt;Hello there,&lt;/p&gt;
&lt;p&gt;In this blog post we look at a setting within the Azure AD portal: &amp;ldquo;Users can create Azure AD tenants&amp;rdquo;. Unfortunately, this setting is enabled by default. Most organizations will probably want to turn this off. You can find it in the Azure AD portal under Settings &amp;gt; Users &amp;gt; User settings &amp;gt; Tenant creation.&lt;/p&gt;
&lt;p&gt;
 &lt;img src="images/112222_2202_Userscancre1.png" alt=""&gt;

&lt;/p&gt;
&lt;p&gt;&lt;code&gt;Yes&lt;/code&gt; allows default users to create Azure AD tenants. &lt;code&gt;No&lt;/code&gt; allows only users with the Global Administrator or Tenant Creator roles to create Azure AD tenants. Anyone who creates a tenant becomes the Global Administrator for that tenant.&lt;/p&gt;</description></item><item><title>Collecting AzureAD User Authentication Method Information</title><link>https://www.verboon.info/2021/02/collecting-azuread-user-authentication-method-information/</link><pubDate>Sun, 07 Feb 2021 13:28:44 +0000</pubDate><guid>https://www.verboon.info/2021/02/collecting-azuread-user-authentication-method-information/</guid><description>&lt;p&gt;Hello everyone, last Friday I received an email from one of my customers, asking how to identify users in Azure AD that have enabled &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-phone"&gt;passwordless sign-in with the Microsoft Authenticator app&lt;/a&gt;. Previously I usually made use of the &lt;a href="https://docs.microsoft.com/en-us/samples/azure-samples/azure-mfa-authentication-method-analysis/azure-mfa-authentication-method-analysis/"&gt;Script for Azure MFA authentication method analysis&lt;/a&gt; but that script uses the MSOnline PowerShell module where the &lt;code&gt;Get-MsolUser&lt;/code&gt; cmdlet does not expose the information about these newer authentication methods.&lt;/p&gt;
&lt;p&gt;So heading over to Microsoft Graph and there we can grab all authentication methods for users as shown in the example below.&lt;/p&gt;</description></item><item><title>Windows 7 Hybrid Join and MFA ramblings</title><link>https://www.verboon.info/2019/02/windows-7-hybrid-join-and-mfa-ramblings/</link><pubDate>Tue, 05 Feb 2019 19:36:58 +0000</pubDate><guid>https://www.verboon.info/2019/02/windows-7-hybrid-join-and-mfa-ramblings/</guid><description>&lt;p&gt;Today I ran into an issue where Windows 7 would not hybrid join as expected. Before going into the details, for those who might not be aware like Windows 10 and Server 2016, you can also hybrid join down-level devices. The functionality is of course not built into Windows so you need to install the &amp;ldquo;&lt;a href="https://www.microsoft.com/en-us/download/details.aspx?id=53554"&gt;Microsoft Workplace Join for non-Windows 10 computers&lt;/a&gt;&amp;rdquo; software.&lt;/p&gt;
&lt;p&gt;One reason why you want to hybrid join Windows 7 devices is Conditional access. Let&amp;rsquo;s assume you plan to introduce Conditional access for your users where you want to enforce MFA when using a non-corporate device.&lt;/p&gt;</description></item></channel></rss>