Advertisement · 728 × 90

Posts by Michael Epping

This month, I'm happy to announce that we've updated the Entra passwordless guide to include instructions on how to use the new Phishing-Resistant Passwordless Workbook we just released! https://aka.ms/PasswordlessWorkbook

1 year ago 8 6 0 1

If you have Apple devices in your environment (you do) and Entra ID, give the #macadmin podcast a listen podcast.macadmins.org/2024/12/17/.... @michaelepping.com and I discuss how you can improve your end user experience and security. Thanks to @tombridge.com & Marcus for having us. #infosec

1 year ago 15 6 0 0

Got it, makes sense. This is definitely an edge case we plan to address, being able to use a passkey in the Office apps when SSO is not present.

1 year ago 0 0 0 0

@crh.bsky.social and seconded what Mark said, if there's something in the guide we can make clearer please let me know

1 year ago 0 0 0 0

@crh.bsky.social totally hear you on the need for this and its something we'll resolve. Broad FIDO coverage on clients has some interesting technical challenges. But if you're using PSSO why do you have users re-authing in Outlook anyways? Generally they should be getting an SSO experience.

1 year ago 0 0 3 0

If you missed JNUC, all sessions are now live. www.youtube.com/playlist?lis.... Check out @michaelepping.com session on how you can use Platform SSO with #JAMF to get that phishing resistant credential for #EntraID. Please deploy this. youtu.be/KepEeeOx99I... #MacAdmins

1 year ago 13 5 2 0

Today your options are use full MDM rather than MAM controls (auth app can satisfy full MDM compliance checks) or give the users temporary exemptions from the all apps policy that requires MAM

1 year ago 0 0 1 0
Advertisement

Not sure what you mean by safeguarded, that isn’t a concept we have in CA. MAM and passkeys can coexist on the same device just fine, but if you have an overly broad MAM CA policy then registration can be blocked, since you’re covering the reg endpoint with the overly broad CA policy.

1 year ago 0 0 1 0

@jeftek.com for visibility

1 year ago 0 0 0 0

This problem doesn't exist if you are using full MDM compliance as one of the checks instead, Authenticator can satisfy that grant control in CA. But if you are mandating app protection policy then you need to adjust your policy so that this scenario is not in scope.

1 year ago 0 0 2 0

This experience is expected if you have policies that require app protection policies for all cloud apps. Microsoft Authenticator doesn't support MAM policies, so you are getting the expected outcome, which is users cannot register due to not passing the app protection policy check

1 year ago 0 0 1 0

Innovative!

1 year ago 0 0 0 0

I have exactly this problem, always too lazy to dig into it

1 year ago 1 0 2 0

It’s a little rough on the west coast, but we make it work. Don’t think my wife likes it too much when I tell her we have to go to a bar at 7am though…

1 year ago 1 0 0 0

Correct, assuming these are device-bound passkeys. If they are synced, then the user can recover them through the sync process (on consumer devices, where Windows is adding sync support soon)

1 year ago 2 0 0 0

Inside the Windows Hello container, which is protected by the TPM

1 year ago 8 0 1 0

Excellent! That’s what we like to hear!

1 year ago 0 0 0 0
Advertisement
Post image

I am very excited for the App Discovery capabilities coming. This is a challenge many customers have, not knowing what apps exist that they need to secure! #entra #msignite

1 year ago 36 3 1 0

What this means is that despite the bullshit populism the media laps up, Trump is going to make sure airlines don't have to compensate passengers for hours and hours of delays and that flight attendants are worked to the bone. That's what this guy who earns $34 million a year is crying about.

1 year ago 504 141 11 5

Don’t love this, but I can forgive it if they’d ever release Bloodborne on PC…

1 year ago 1 0 0 0
Preview
a man with a beard says hello there in a star wars scene ALT: a man with a beard says hello there in a star wars scene

Happy to help if you’ve got questions!

1 year ago 3 0 0 0

I did know this!

1 year ago 1 0 1 0
425 Show | Phishing-Resistant Passwordless Deployment Guide
425 Show | Phishing-Resistant Passwordless Deployment Guide YouTube video by Microsoft Security Community

We also recently recorded an episode of the 425 Show to talk about our new deployment guidance, so check it out to get the latest and greatest info: www.youtube.com/watch?v=5J03...

1 year ago 5 1 1 0
Preview
Get started with a phishing-resistant passwordless authentication deployment in Microsoft Entra ID - Microsoft Entra ID Detailed guidance for planning the prerequisites to deploy passwordless and phishing-resistant authentication for organizations that use Microsoft Entra ID.

In case you missed it, back in October we published a brand new guide for deploying phishing-resistant passwordless in your organization with Entra ID: aka.ms/Passwordless... ! This is the outcome of a ton of effort across Microsoft, please use it to begin your journey!

1 year ago 15 4 1 0

Seems like bluesky has really been blowing up since last week, I’ve gotten hundreds of new followers. Guess I’ll have to spend some more time on here! Definitely a lot fewer bots than I’ve gotten used to see on twitter

1 year ago 5 0 1 0
Advertisement
Preview
GitHub - AzureAD/MSIdentityTools: Repository for the Microsoft Identity Tools PowerShell module which provides various tools for performing enhanced Identity administration activities. Repository for the Microsoft Identity Tools PowerShell module which provides various tools for performing enhanced Identity administration activities. - AzureAD/MSIdentityTools

@michaelepping.com has a great script you can find as part of Identity Tools (github.com/AzureAD/MSId...) and if you want a video walk through of it, @merill.net has you covered www.youtube.com/watch?v=vO0m.... /3

1 year ago 9 2 1 0
Best Practices for Deploying Platform SSO with Microsoft Entra ID–Michael Epping, Mark Morowczynski
Best Practices for Deploying Platform SSO with Microsoft Entra ID–Michael Epping, Mark Morowczynski YouTube video by MacAdmins Conference

Have you watched this video from @michaelepping.com and @markmorow.com www.youtube.com/watch?v=NEoK...

1 year ago 12 4 1 0

Nothing quite like getting online at 745am for your dreaded 8am call and seeing it was pushed back a week. Truly blessed

2 years ago 3 0 0 0