@IAMERICAbooted Are you aware of any solutions that helps with entra app attestation? Essentially attest app is still valid or it will be disable/deleted.
Did more testing today following your blog @NathanMcNulty but wasn’t able to add eligible member to pim enabled group located in an RMAU. This test group is not enabled for role assignments. After looking over audit logs for my account (even though it proxies through service principal) it does show the failure but it’s not for ms-pim identity. It’s for one called Azure AD PIM. Only the sp id is listed, app id is not provided. Perhaps MS has changed what sp is used? Without app id I can’t register it and hence can add it to custom role. Thought?
@NathanMcNulty@IAMERICAbooted I think the problem I had run into was PIM in combination with ATR flag. Thanks for that article, that’s exactly the guidance I followed.
Hey @merill wondering if you have any insight on this topic. I want to leverage device-bound passkey in MS Authenticator, however there is a known issue when also leveraging Conditional Access to require app protection policy for all apps on mobile os. The provided workarounds aren’t great but there is an undocumented work around of excluding Azure Credential Configuration Endpoint Service app from app protection CAP. This works but not sure if that introduces additional risk. Thoughts?