𝐋𝐞 #passkey 𝐫𝐞𝐧𝐝𝐨𝐧𝐨 𝐢𝐥 𝐩𝐚𝐬𝐬𝐰𝐨𝐫𝐝𝐥𝐞𝐬𝐬 𝐜𝐨𝐧𝐜𝐫𝐞𝐭𝐨: meno attrito per gli utenti, più protezione da phishing e furto credenziali. Una scelta strategica per rafforzare sicurezza, governance e continuità operativa.
Leggi l'articolo➡️ https://t.co/x4arK8mbIG
I just wrote a new blog on bypassing CA policies in Entra ID that have a resource exclusion, and why you probably want to enable baseline enforcement if you have such policies. Enjoy!
https://t.co/a1rGl3wss8
Entra Connect v2.6.79.0 was just released and contains undisclosed security fixes and @Microsoft recommends to update fast. On the bright side, it will finally support FIDO2 based authentication!
As of right now, Microsoft are rolling our Passkey (FIDO2) registration campaigns! Read more here: https://t.co/xtiJWhD1Pw 💙
For clarity, you will only be impacted if:
• The Passkeys (FIDO2) authentication method policy is Enabled
• Allow self‑service setup is Enabled
• Target specific AAGUIDs is not selected (no AAGUID restrictions configured)
• The Registration Campaign state is set to Microsoft‑managed
• The tenant has at least one user enabled for both synced passkeys and device‑bound passkeys
It's worth checking your settings right away!
#Entra #Microsoft
Basta così. Non sottoporremo le 57 persone a bordo di #SeaWatch5 a un viaggio di altri 1.100 km per raggiungere Marina di Carrara. È tortura di Stato. Disobbediamo a questo ordine assurdo e facciamo rotta verso Trapani.
Get ready, folks. 🌟
You’re about to witness ONE. BIG. BEAUTIFUL. ABSURDLY. EPIC. THREAD. 🧵🔥
Some say this might be the MOST EPIC and MOST RIDICULOUSLY LONG identity thread ever written
📗 Bookmark this
Honestly… the cover image alone deserves a like + retweet
DO IT 😂
Please stop using Private browser sessions for cloud admin accounts
Look, we all know we shouldn't be using admin accounts while signed into our productivity account, but if you're gonna do it, at least use browser profiles so you can enforce compliance
https://t.co/e8I882Lh9w
On This Day in 1946: the unique spelling of Irn Bru was born. The drink, first made in 1901, had previously been called Strachan's Brew then Iron Brew. New advertising legislation required the removal of the word 'brew', because it is not brewed. Which can's your favourite?
If you dont know why 1FA with FIDO2/webauthn plus a managed device requirement to authenticate is a better alternative than 2FA with OATH tokens or push, you shouldn't be talking to people who know authentication and advising them on what they should or shouldn't be doing.
If you don't know how to respond to an incident in m365 because you don't know M365, you shouldn't be leading an incident response program.
If you don't know a technology, you shouldn't be making recommendations for architectural changes.
If this is you, you should re-evaluate your purpose.
🛡️Server 2025 brings no improvements in Active Directory? That’s just not true and updating will help you to mitigate known attack vectors.
Hopefully companies will see those benefits and upgrade and plan migrations.
#dMSA#ActiveDirectory#Security
https://t.co/YDujr8vJG8
As part of the Azure MFA enforcement rollout, emergency accounts will now need to be registered for MFA.
You should typically avoid using MFA methods that have dependencies on other services, such as the Azure MFA service or your mobile carrier.
This leaves the following as the three most resilient MFA options:
✅ Certificate-based authentication
✅ Windows Hello for Business
✅ FIDO2 security keys
These three methods' only dependency is the core Entra authentication service, which is the same as password authentication that relies on the Entra auth service.
Now, when it comes to your emergency access account, the most likely option is to use FIDO2 security keys.
Here's why.
Windows Hello for Business (WHfB) for emergency access
Windows Hello for Business is not a viable option for emergency access accounts. It requires a device that must be frequently updated, constantly connected to the internet for the PRT to be renewed, and there are also the costs and operational overhead associated with the device.
Certificate-based authentication for emergency access
If you haven't deployed certificate-based authentication, you'll need to set it up and ensure that you use self-signed keys to avoid dependencies on external PKI/CRL infrastructure. Not to mention a smart card and card reader or some other hardware for storing the certificates.
FIDO2 security keys for emergency access
This essentially leaves FIDO2 security keys, which are simple to enable in Entra ID, require very low or no maintenance, take up little space, can be stored securely, and can be purchased for $25 retail.
PS: I've intentionally not included device-bound passkeys in Authenticator as they are currently in public preview, and you most likely don’t want to use them for your emergency access account yet.
-------------
Liked this post? Bookmark this and feel free to follow me for more tips on Microsoft Security and Microsoft Entra.
Remember to click the bell icon on my Twitter profile. This way Twitter will show you all my posts in your feed so you don't miss anything.
Please like, repost to share with others. Thanks!
Forse così si capisce meglio: questa è la preziosa mappa delle rotte vessatorie assegnate dal Viminale alle navi ONG dopo i salvataggi in mare. L’ha fatta @scandura e vale più di mille chiacchiere. Quelle rotte sono soprusi. Sulla pelle dei migranti e di chi prova a salvarli.