Microsoft just dropped a game-changer for Hybrid Join! 🛡️Entra hybrid-join via Entra Kerberos (Public Preview) is here. No more waiting for Entra Connect sync cycles!
Perfect for: ✅ Non-persistent VDI ✅ Entra Cloud Sync ✅ Faster AVD/Win365
Full details: www.ctrlshiftenter.cloud/8f70
Posts by Patrick Seltmann
New blog post! Why the Trusted Platform Module (TPM) is critical and why disabling it—even once—can breaks your security chain. Spoiler: There is no "self-healing" process for critical artifacts like the PRT or Windows Hello keys! www.ctrlshiftenter.cloud/n2z1
#Microsoft #Cybersecurity #Endpoint
🚀 New blog post: Should you exclude "Microsoft Intune Enrollment" from your compliance conditional access policy or not?
Read more in my new blog post: www.ctrlshiftenter.cloud/31fa #conditionalaccess #intune #entra #microsoft #security
🚀 New: App Control for Business — Part 7. Automate ACfB policy deployment: maintain, sign, and deploy to Intune via Azure DevOps pipelines or with PowerShell 7. Read more about this on my blog: www.ctrlshiftenter.cloud/bn0o
#AppControl #WDAC #Intune #PowerShell #DevOps #Security #Microsoft
Thanks for your reply. I have already double checked that but the sign-inverification methods are still not there.
Does anyone know how to remove these old authentication methods from windows? #windows #authentication
🚀 New Blog Post – App Control for Business | Part 6
Learn how to sign, apply, and remove signed policies to protect against tampering.
Now on my blog 👇
👉 www.ctrlshiftenter.cloud/oat7 #WDAC #AppControl #EndpointSecurity #Cybersecurity #Microsoft #Intune #prevention
🚀 New Blog Post – App Control for Business | Part 5
How to create a custom base policy for fully managed devices — with PowerShell or the App Control Wizard.
Includes real examples with Notepad++
👉 www.ctrlshiftenter.cloud/4qz1
#WDAC #AppControl #Security #Intune
#Microsoft has announced the availability of E5 Security Add-On licenses for #nonprofits witch already own Business Premium Licenses.
This is a hugh benefit for nonprofit organization which want to take their #cybersecurity to the next level.
techcommunity.microsoft.com/blog/nonprof...
🔐 Reduce the attack surface of your Entra Connect Sync setup!
✅ Hard vs. soft match
✅ ImmutableID & mS-DS-ConsistencyGuid
✅ Secure app-based auth w/ CA
✅ Security Best Practises
🔎 Monitor changes via KQL
👉 www.ctrlshiftenter.cloud/q1oc #EntraID #Microsoft #Hybrid #Security
🎉 Just published an early public version of CAxPorter Utility – to manage #EntraID #ConditionalAccess Policies in bulk!
Import/export CA policies
Rename & delete policies
Generate Markdown docs via #OpenAI
Works with CLI & GUI
Blog: www.ctrlshiftenter.cloud/60zf
GitHub: github.com/PatrickSeltm...
Looks like Lifecycle Workflows just added the ability to revoke session tokens 💪
Previously, we had to create our own custom extension (Logic App) to do this, so really nice to see it as a built-in task now :)
learn.microsoft.com/...
#EntraID will block service prinicipal-less authentication from March 2026. Don't know what this is or if it will affect your #Microsoft365 tenant? It's time to check.... Microsoft will take care of 1P apps. Other vendors need to do the same
office365itpros.com/2025/04/15/s...
@nathanmcnulty.com
Hello #microsoft, your mslearn page “Conditional Access architecture and personas” from the #Azure Architect Center, which explains the Conditional Access Persona Framework, was deleted 5 days ago. Why?
🚀 New blog post: Mastering App Control for Business – Part 4 🔐
Learn how to create a “starter base policy” for lightly managed Windows devices.
www.ctrlshiftenter.cloud/qu8h
#WDAC #AppControl #Intune #CyberSecurity #ZeroTrust #Windows #MSIntune #Microsoft #EndpointManagement #Endpoint #Security
I've written a short explanations about the session toke lifetime: require reauthentication that was released by #microsoft with the march 2025 #MicrosoftEntra updates. www.ctrlshiftenter.cloud/hdf7
#ConditionalAccess #ZeroTrust #IdentitySecurity #M365 #CloudSecurity #PrivilegedAccess #PAW
🚀 New Blog Post: Mastering App Control for Business | Part 3 – App Tagging & Managed Installer
How to combine tagging policies with Windows Firewall & explore the pros/cons of Managed Installer.
🔗 www.ctrlshiftenter.cloud/gmva
#WDAC #AppControl #Intune #Securtiy #Microsoft
New Windows LAPS features just dropped with the March '25 Intune update! Check the docs:
learn.microsoft.com/en-us/mem/in...
#Intune #EndpointManagement #WindowsLAPS #WindowsSecurity
🚀 New Blog Post: Mastering App Control for Business | Part 2 🔐
Diving into policy templates, rule options & security settings in App Control for Business (ACfB)! 💡
📖 Read more: www.ctrlshiftenter.cloud/vmbo
#CyberSecurity #AppControl #WDAC #ITSecurity #ZeroTrust #EndpointSecurity #Intune
🚀 New Blog Post: Mastering App Control for Business | Part 1 🔐
Trusting all apps is risky! Attackers exploit detection gaps—traditional security is reactive, not proactive.
🔗 Read more: www.ctrlshiftenter.cloud/zhmp
#CyberSecurity #WDAC #ZeroTrust #AppControl4Business #Enterprise #M365 #Intune
🚀 New Blog Post: Mastering App Control for Business | Part 2 🔐
Diving into policy templates, rule options & security settings in App Control for Business (ACfB)! 💡
📖 Read more: www.ctrlshiftenter.cloud/vmbo
#CyberSecurity #AppControl #WDAC #ITSecurity #ZeroTrust #EndpointSecurity #Intune
Are there any use cases for #appcontrolforbusiness application tagging policies instead of tagging application to control these in the windows Firewall? #microsoft #endpointprotection #intune
🚀 New Blog Post: Mastering App Control for Business | Part 1 🔐
Trusting all apps is risky! Attackers exploit detection gaps—traditional security is reactive, not proactive.
🔗 Read more: www.ctrlshiftenter.cloud/zhmp
#CyberSecurity #WDAC #ZeroTrust #AppControl4Business #Enterprise #M365 #Intune