Digital identity guy. Product manager for Microsoft Entra and Azure Active Directory. Aerospace, automotive, and NFL football enthusiast. Husband and father.
@Alex_A_Simons@tuna_gezer Hi @tuna_gezer, the fix for the $count issue was fully deployed on July 18th, are you still able to repro? And we are looking into the delta query issue, thanks for reporting it
🎉 Microsoft Entra Permissions Management is now generally available!
Remediate permission risks and ensure the security of your multicloud environment. Learn more: https://t.co/eJcreGXlIr #MicrosoftEntra
Azure identity geeks: You can now view in the Azure portal the set of resources that are associated with a user-assigned managed identity, like which VMs are using the identity: https://t.co/rrM4zO5OaU
I’m over the moon to help launch Microsoft Entra, our new family of Identity and Access solutions that includes Azure AD, Entra Permissions Management (previously CloudKnox), Entra Verified ID and a new simplified admin portal experience https://t.co/Le9XO5HSgE
I’m SO excited about today’s news! After 6+ years of effort, we have an open standard for passwordless authentication that Microsoft, Google and Apple (yes, even Apple!) have all agreed to build into their OS’s and browsers https://t.co/YUJwPIWz8R
You can now download all #AzureAD RBAC assignments using a button in the portal, instead of having to script this with PowerShell https://t.co/TDx0rfPjOb
Today's news: Azure AD now supports custom RBAC roles for devices scoped to Admin Units. Awesome new way to assure least privileges for devices! https://t.co/Bvvzyc6BJS
Kim was a transcendent figure in Identity. He literally changed the rules. I learned so much from him about technology and business, but also about humanity. I find myself learning from him to this day even without his being present. It is a shock to hear about his passing.
I think was the last time I saw Kim in person, on the keynote stage of @Identiverse 2019.
I love this picture as it epitomizes his role - when Kim spoke, the industry listened.
/cc @pamelarosiedee@annabellerings@ve7jtb@__b_c
@FrederikLeed @wiele They are meant to be general purpose. You should review the physical limits in the documentation though, to make sure they support the scale you need.
@FrederikLeed @wiele Let's say there's a "project" attribute and users with "project = Skagit" can read details of that project through ABAC. We've built this feature so that User Admins can't set this attribute on a user. Only the Attribute Assignment Admins for the project attribute can do that.
@FrederikLeed @wiele For example, User Admins cannot update the security attributes on a user. If they could, they could potentially give someone access they shouldn't have.
New preview today of custom security attributes in #AzureAD! Use them in Attribute Based Access Control to simplify access to #AzureBlob, for example "grant read access if user.project == blob.project". More scenarios coming soon! https://t.co/CxNDriUEDc
@Alex_A_Simons@NickolajA@inthecloud_247 Hi Kevin, we just last week added granular permissions for group management, so there's a specific custom role permission available now for setting the dynamic membership rule on a group. Check it out and let me know if it does what you need.