Blog

November 12, 2025
How I accidentally replaced Maester and half of my weekend plans

If you had told me a month ago that I'd build an assessment framework from scratch - one that would completely replace both Maester and Pester - I would have laughed, said "sure", and gone back to debugging my PowerShell script.

But here we are.

The need for a better way

I've spent a fair...

November 07, 2025
Soft-delete for security groups is finally supported in Entra ID

Not a day to soon, security groups can now be soft-deleted, something that has been around for Office groups for ever.

Recently Microsoft added soft-delete support for Conditional Access poclies, but this is in my mind an even bigger improvement.

If you take a look in any tenant today, you will...

October 27, 2025
Change Source of Authority for AD synced security groups to implement Entitlement Management

Changing SoA for synced AD groups was recently made available as a public preview feature in Entra ID. In a previous blog post, I demonstrated how this can be used to move your management of these groups to Entra ID from Active...

October 10, 2025
Soft-delete for Conditional Access

Until now, once you deleted a Conditional Access policy it was gone forever. You always had the option to disable it or set it to report-only mode but as with so many other things, old policies have a tendency to be kept "just in case" and be forgotten.

Having the option to restore a deleted...

October 08, 2025
Change of Source of Authority for users is now in public preview

Microsoft has opened a long-awaited door: you can now switch a synced user's Source of Authority (SoA) from AD DS to Microsoft Entra ID without delete/recreate gymnastics. It's designed for "road-to-cloud" programs where you want to retire on-premises user management but keep identities, GUIDs, and...

September 02, 2025
Improved mail notifications in Lifecycle Workflow

On lacking feature in Lifecycle Workflows used to be the option to address other people than the user's manager when sending mail.

I usually set up a reminder before a user's end date is about to occure, to make sure that an incorrect end date doesn't offboard a user by accident.

Previously, the...

August 30, 2025
Delegation of access reviews and approvals are in Public Preview

Entitlement Management has a distinct separation of being an approver or access reviewer, and being able to manage who holds those roles. If you are an approver or reviewer and need to delegate it to other people, temporary or on a permanent basis, you have been dependent on contacting someone with...

August 29, 2025
Defender for Identity now scans AD for exposed passwords in Comments

If you’ve worked with on-prem Active Directory for a while, you’ve probably seen passwords stored in user attributes and notes, especially for service accounts and shared accounts.

MDI - Example of Secret in Description

Image not found: /api/images/MDI-SecretinDescription.png

Microsoft Defender for Identity...

August 27, 2025
Changing Source of Authority for groups

The feature to change Source of Authority (SOA) for AD groups synced to Entra ID is currently in public preview. This is very useful for organizations on the their cloud first journey, as it makes it easy to transition existing groups in Active Directory to be managed in Entra ID.

It is especially...

August 16, 2025
Managing Self-Service Licenses in Entra ID

Microsoft Entra ID includes a Self-Service Purchase and Subscription feature that allows users to acquire Microsoft 365 and Power Platform licenses without IT intervention. While this can empower teams to move quickly, it can also lead to unmanaged costs and compliance issues if left unchecked.

In...

Popular Tags
access reviewsadaiassessmentconditional accesscredentialsentitlement managementgroup migrationid governancelcwlicensingmdisoasoft-deleteuser migration
Popular Tags
No tags found

Remind the blog authors to tag their posts!