Jef Kazimer

583 posts

Jef Kazimer banner
Jef Kazimer

Jef Kazimer

@JefTek

Principal Product Manager @Microsoft #MicrosoftEmployee #Microsoft #Entra #Identity #EntraID - Tweets are my own

Chicago, IL Beigetreten Şubat 2007
2.9K Folgt5K Follower
EZ
EZ@IAMERICAbooted·
. @merill we need to talk. I will be filing a ticket today. This is a perfect example of people reading documentation and not understanding what impacts the recommendation may have. Adding high severity attack surface is not the way. A better way to govern is having updated and accurate CMDB for lifecycle management and owners of business decisions. Every time an employee leaves, there should be an automated process to replace them in the CMDB with their manager until a new owner is assigned. As for adding the owners to app registrations - do not do this. A better solution is to use service principals that govern. Only cloud app admins, app admins, privileged role admins, and global admins should be allowed to alter manifests, secrets, federations, certs+keys, redirect URIs, and delegated permissions. Not app owners at the Entra level.
Juan Garrido@tr1ana

@IAMERICAbooted @CynicLib @CyberDivergent I didn’t mind to offend you. Congratulations on being an expert in Entra. The official recommendation is that there should be at least 2 owners learn.microsoft.com/en-us/entra/id…

English
5
0
16
1.3K
Jef Kazimer
Jef Kazimer@JefTek·
@IAMERICAbooted @merill Yes this is part of where custom security attributes (CSA) are used in applications. In the docs we call them out for use as governance attributes but I think we can elevate this. I’d like to have a common sponsor attribute we can use in our built in governance flows
English
1
0
1
8
EZ
EZ@IAMERICAbooted·
@JefTek @merill This can be fixed by adding the owners in the properties pane instead of adding them in the owners pane. When owners leave, it can be automatically updated with their manager and signaled to evaluate new owners for lifecycle governance
English
1
0
0
9
Jef Kazimer
Jef Kazimer@JefTek·
@IAMERICAbooted @merill Understood. I look to improve the capabilities so customers get value from it so more see the value in using those capabilities. I’ve wanted to look at a universal sponsor for apps and groups for awhile so thanks for the reminder.
English
1
0
1
12
EZ
EZ@IAMERICAbooted·
@JefTek @merill Unfortunately, lost orgs are not using Entra Governance in my experience.
English
2
0
0
14
Jef Kazimer
Jef Kazimer@JefTek·
@IAMERICAbooted @merill Anything more specific you can share? I assume exploring the designated owner account to be able to configure application?
English
1
0
1
11
EZ
EZ@IAMERICAbooted·
@JefTek @merill Correct Jeff. People exploiting this are not just Russia and China anymore
English
1
0
0
9
Jef Kazimer
Jef Kazimer@JefTek·
@IAMERICAbooted @merill To have designated people as custodians or decision makers but without ability to make configuration changes? If you look at how we have sponsors on other entities which are responsible for limited lifecycle tasks and approvals but can’t manage configuration?
English
1
0
1
14
Jef Kazimer
Jef Kazimer@JefTek·
@IAMERICAbooted @merill I think there is a bit of conflated terminology here. Owner in Entra entities typically is a designated user who has ability to manage and responsibility. So 2 owners who are responsible to and have ability to manage config of that application. I think you want …
English
1
0
0
26
Jef Kazimer retweetet
Marc-André Moreau
Marc-André Moreau@awakecoding·
A colleague encouraged me to share some of my AI prompting tips. I often see people struggle with tasks that somehow just work well for me, yet it's hard to figure out what differs in the approach. Beyond the tools and models, here are my tricks for achieving better results 🧵👇
English
2
7
39
6.5K
Jef Kazimer retweetet
$anjay
$anjay@sanjaygpts·
@claudeai pov: you're celebrating claude's new features while knowing it's the same tool that's going to replace you by end of 2026
English
18
113
2.1K
127.7K
Jef Kazimer
Jef Kazimer@JefTek·
@callmidavid @claudeai Save your receipts for your toolbox so you can return it. Just wait till robots get cheap enough to use AI to do manual tasks.
Jef Kazimer tweet media
English
0
0
0
55
David Uchenna
David Uchenna@callmidavid·
@claudeai Time to become a Plumber Thanks for taking my job, Anthropic
GIF
English
2
2
37
10.6K
Claude
Claude@claudeai·
Introducing Claude Design by Anthropic Labs: make prototypes, slides, and one-pagers by talking to Claude. Powered by Claude Opus 4.7, our most capable vision model. Available in research preview on the Pro, Max, Team, and Enterprise plans, rolling out throughout the day.
English
3.7K
13.7K
136.1K
48.5M
EZ
EZ@IAMERICAbooted·
Who can tell me how many agents are connected to your Microsoft tenant and what are they doing? This is a problem I'm going solve.
English
7
0
29
4.9K
Jef Kazimer retweetet
Fabian Bader
Fabian Bader@fabian_bader·
If you have a conditional access policy scoped to user action "Register security information" starting May 2026 the registration of Windows Hello for Business and macOS Platform SSO credentials will be in scope. #EntraID
Fabian Bader tweet media
English
2
27
117
8.1K
Jef Kazimer retweetet
spencer
spencer@techspence·
On-prem is going to make a come back, yes or no?
spencer tweet media
English
27
3
61
8.8K
EZ
EZ@IAMERICAbooted·
@JefTek Its beyond that Jeff :) it has to do with SaaS apps being enumerable from the internet due to sp-initiated authn implementations. If its on the internet, attackers will do what attackers do :)
English
1
0
0
38
EZ
EZ@IAMERICAbooted·
Who can tell me what benefit having Named Locations/IP Allowlists when you already have FIDO2 for authn to SaaS? Think like an attacker. I'll wait, hopefully not too long.
English
13
2
36
6.9K
Jef Kazimer
Jef Kazimer@JefTek·
@IAMERICAbooted I can still walk up to an airport kiosk and use a FIDO2 key to get a token that could be stolen for example. Or maybe not wanting you to use your grandmothers PC to access work services even if using PR auth. Right control for right threat.
English
1
0
2
278
Jef Kazimer
Jef Kazimer@JefTek·
@IAMERICAbooted We have to think of authentication strengths of PR methods as an AND control and not the only control. Think layered controls. Require Phishing Resistant auth AND compliant device. Or PR auth AND allowed network.
English
1
0
2
282
EZ
EZ@IAMERICAbooted·
For everyone allowing unmanaged device connections to their network/m365, regular people now have full permissioned agents doing things on their behalf. 😆 🤣 😆 🤣 If you still allow access to your network from unmanaged devices, last year was the time to close that gap. Better late than never!
English
4
6
77
4.5K
Jef Kazimer
Jef Kazimer@JefTek·
RIP Adam the woo. 51 is so young to pass. We really enjoyed his travel and sharing his adventures.
English
0
0
3
533