Azure AD Passwordless Authentication with Yubico FIDO2 key

Lately I got the opportunity to test the latest Identity Authentication method with Azure AD. None other than the Passwordless Authentication. I will post few related articles on FIDO2 and what it does rather than re-explaining what has already well explained by the FIDO Alliance and Microsoft. The good thing is passwordless methods can be … Continue reading Azure AD Passwordless Authentication with Yubico FIDO2 key

Cool and a Powerful feature to stop bulk accidental/ intentional deletion exports in an Azure AD Hybrid Environment

This is a hidden gem for Azure AD Sync connect configurations and I was looking for a feature like this for sometime now. Noticed this was available while trying to perform a migration of the tool to anew server and when reviewing the new confit before commuting. There can be many reasons for this kind … Continue reading Cool and a Powerful feature to stop bulk accidental/ intentional deletion exports in an Azure AD Hybrid Environment

Azure MFA Authentication Loop Fix

Issue: Office 365 Web apps users (SharePoint Online, Office.com, OWA etc.) will receive the MFA prompt every time after opening the browser.Ideally the browser should honor the “Stay signed in?” messages when there are no session lifetime settings configured.When the user click Yes, the persistent browser cookie will get saved and work for 90 days. … Continue reading Azure MFA Authentication Loop Fix

Effective use of Azure AD Administrative Units [Azure AD AUs]

I look at the Azure AD portal with curiosity to see what are the new features and then want to play around with them to better understand it’s usage. This is not a latest feature, but it’s out of the preview mode and this is me writing the effective use of Azure AD AUs. How … Continue reading Effective use of Azure AD Administrative Units [Azure AD AUs]

Preparing workstations for the Cloud Journey with Hybrid Azure AD Join – Part 2: Add the devices to Intune

Part 1: Preparing workstations for the Cloud Journey with Hybrid Azure AD Join Now that we have add the existing computers to Azure AD in the Hybrid Join mode, there are few more steps that needs to be completed before adding it as an Intune managed device. Just the tip of the iceberg This part … Continue reading Preparing workstations for the Cloud Journey with Hybrid Azure AD Join – Part 2: Add the devices to Intune

How to federate Google (Gmail) accounts with Azure AD to access resources without a Microsoft account

My DIY project for this weekend is to try and implement a method to set Google as an identity provider for Azure AD resource access requirements. If someone can access apps or services on a different platform without having to create an account of the resource owner's end, that makes lives more easier and simply … Continue reading How to federate Google (Gmail) accounts with Azure AD to access resources without a Microsoft account

Microsoft 365 Groups Cheat Sheet

This is my compilation of the something out of everything you need to know about the M365 Groups. Over the course of time Microsoft brought different types of groups to manage users and computers. In all those scenarios, the group was capable of performing one task or 2 maximum.Act as a Security Group or an … Continue reading Microsoft 365 Groups Cheat Sheet

Azure AD User Automation For Better Identity And Access Management

Why automate such a workload? Few reasons though Better Identity and access managementNot having to update too many locations for these type of requestsMeet demands/ less stress on the frontline IT This is the age of automation and everyone is in the automation bandwagon to automate the tech workloads in the cloud or on-premises. If … Continue reading Azure AD User Automation For Better Identity And Access Management

Preparing workstations for the Cloud Journey with Hybrid Azure AD Join

In almost all the cases, the organization is not in a position to get away from the local domain as its tightly connected with other services that are running on-premises and maintaining the on-premises identity is vital. Further, you have the on-premises domain and the workstations are joined to it, GPOs being pushed across and … Continue reading Preparing workstations for the Cloud Journey with Hybrid Azure AD Join

Blocking Basic Auth – Personal Thoughts

Sometime a go I wrote on How to Disable Basic auth to make way to Modern Authentication. The procedure is manageable and with a bit of effort, you can achieve it with less or no noise in your Organization. Either you block Basic Auth via an Azure AD Conditional Access policy or creating an EXO … Continue reading Blocking Basic Auth – Personal Thoughts

Azure AD Connect Cloud Provisioning. The new feature that may come in handy!

Microsoft have finally answered the prayers of the IT admins! Long story short, gone of the days where the IT admins had to make sure 2 AD forests can see each other and the ports are opened, before it adds to the Azure AD Sync tool as another directory, so the users from that directory … Continue reading Azure AD Connect Cloud Provisioning. The new feature that may come in handy!

Microsoft is retiring Basic Authentication, because Modern Authentication is here to stay!

Microsoft have announced that they will retire the Basic Authentication method from Office 365 Exchange Online and make Modern Authentication method the standard way of authenticating going forward.There are continues updates in the M365 Admin Center messages and what admins need to do to prepare for the change. Companies now have to prepare for the … Continue reading Microsoft is retiring Basic Authentication, because Modern Authentication is here to stay!

Azure AD Group Based Licensing

As opposed to adding cloud based licenses per user basis or via PowerShell to automate license assignment with a security group, Azure's group based licensing is easy to do and will save a lot of time.This setup is ideal for the organizations which has a number of licenses for different types of users. Also will … Continue reading Azure AD Group Based Licensing