Stuart Kwan

326 posts

Stuart Kwan

Stuart Kwan

@StuartKwan

Digital identity guy. Product manager for Microsoft Entra and Azure Active Directory. Aerospace, automotive, and NFL football enthusiast. Husband and father.

Redmond, WA Joined Ocak 2014
68 Following1.8K Followers
Stuart Kwan
Stuart Kwan@StuartKwan·
@Alex_A_Simons @tuna_gezer Hi @tuna_gezer, the fix for the $count issue was fully deployed on July 18th, are you still able to repro? And we are looking into the delta query issue, thanks for reporting it
English
1
0
0
135
TunaMania
TunaMania@tuna_gezer·
@Alex_A_Simons Is this a bug in the implementation of the directoryRoles API. The API call with $count was randomly failing and since yesterday it constantly fails. Per doc this should work, any help or recommendation would be appreciated #optional-query-parameters" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/graph/ap…
TunaMania tweet media
English
1
0
4
783
Stuart Kwan retweeted
Microsoft Security
Microsoft Security@msftsecurity·
🎉 Microsoft Entra Permissions Management is now generally available! Remediate permission risks and ensure the security of your multicloud environment. Learn more: msft.it/6016bIZ1w #MicrosoftEntra
English
2
45
67
0
Derek Liu
Derek Liu@DerekLiu44·
@StuartKwan Hi Stuart, do you know if there is a plan to scope the set of possible group members for the group administrator role? As far as I know, this isn't possible with AUs, which only allows groups to be included without the ability to scope the members of those groups.
English
1
0
0
0
Stuart Kwan
Stuart Kwan@StuartKwan·
Azure identity geeks: You can now view in the Azure portal the set of resources that are associated with a user-assigned managed identity, like which VMs are using the identity: docs.microsoft.com/en-us/azure/ac…
English
0
12
31
0
Stuart Kwan retweeted
Alex Simons
Alex Simons@Alex_A_Simons·
I’m over the moon to help launch Microsoft Entra, our new family of Identity and Access solutions that includes Azure AD, Entra Permissions Management (previously CloudKnox), Entra Verified ID and a new simplified admin portal experience microsoft.com/security/blog/…
English
6
84
203
0
BitFisk
BitFisk@BitFisk·
@StuartKwan Sadly it doesnt include elligible assignments only the active ones atm :-(
English
1
0
1
0
Stuart Kwan
Stuart Kwan@StuartKwan·
You can now download all #AzureAD RBAC assignments using a button in the portal, instead of having to script this with PowerShell #download-role-assignments" target="_blank" rel="nofollow noopener">docs.microsoft.com/en-us/azure/ac…
English
2
12
45
0
Stuart Kwan
Stuart Kwan@StuartKwan·
Kim was a transcendent figure in Identity. He literally changed the rules. I learned so much from him about technology and business, but also about humanity. I find myself learning from him to this day even without his being present. It is a shock to hear about his passing.
Vittorio@vibronet

I think was the last time I saw Kim in person, on the keynote stage of @Identiverse 2019. I love this picture as it epitomizes his role - when Kim spoke, the industry listened. /cc @pamelarosiedee @annabellerings @ve7jtb @__b_c

English
0
2
16
0
Stuart Kwan
Stuart Kwan@StuartKwan·
@FrederikLeed @wiele They are meant to be general purpose. You should review the physical limits in the documentation though, to make sure they support the scale you need.
English
0
0
1
0
Frederik Leed
Frederik Leed@FrederikLeed·
@StuartKwan @wiele Than you @StuartKwan forynge updates. Is there like a “this is the supported intention of Security Attributes” or some kind of boundry or limitations? I see all kinds of possible usecases but do not want to go Down a path that wont work in the Long run
English
1
0
0
0
Stuart Kwan
Stuart Kwan@StuartKwan·
@FrederikLeed @wiele Let's say there's a "project" attribute and users with "project = Skagit" can read details of that project through ABAC. We've built this feature so that User Admins can't set this attribute on a user. Only the Attribute Assignment Admins for the project attribute can do that.
English
1
0
2
0
Stuart Kwan
Stuart Kwan@StuartKwan·
@FrederikLeed @wiele For example, User Admins cannot update the security attributes on a user. If they could, they could potentially give someone access they shouldn't have.
English
1
0
1
0
Stuart Kwan
Stuart Kwan@StuartKwan·
@Alex_A_Simons @NickolajA @inthecloud_247 Hi Kevin, we just last week added granular permissions for group management, so there's a specific custom role permission available now for setting the dynamic membership rule on a group. Check it out and let me know if it does what you need.
English
0
0
3
0
Peter Klapwijk | MVP
Peter Klapwijk | MVP@inthecloud_247·
@azuread Why don't we have the option option to use microsoft.directory/bitlockerKeys/… in a custom role? Or support Application permissions on GET /informationProtection/bitlocker/recoveryKeys/'{bitlockeryRecoveryKeyId}' I don't want to assign the Helpdesk role to allow certain users to
English
5
2
12
0