
D Lind
2.5K posts

D Lind
@dnsinit
Tweets are my own. Lucky guy who works with his hobby. 👨🏼💻 Here for the awesome knowledge in the MSFTverse, threat intelligence and FPL tweets.




Unprotected groups in Entra ID can lead to privilege escalation. Part 2 of our 4-part series shows how weakly protected groups can be abused to bypass controls, gain privileged access, and lead to full compromise—and how to detect this with EntraFalcon: blog.compass-security.com/2026/03/common…

Most VPN migrations fail before they even start. Not because of technology. Because of approach. In our latest podcast, remote access expert @richardhicks shares something interesting: He’s helped organizations transition away from legacy VPNs multiple times and the successful migrations all follow a similar pattern. One of the biggest secrets? 👉 Don’t rip out the VPN first. Instead: 🔹 Deploy Microsoft Entra Private Access alongside the existing VPN 🔹 Let the new client intercept traffic before the tunnel 🔹 Gradually move apps over 🔹 Then retire the VPN This reduces risk dramatically and gives teams time to understand how identity-based access changes the model. The shift is bigger than most teams expect: 🔰 Legacy VPN → network access 🔰 Modern Zero Trust → application access If you're considering moving to Microsoft Entra Private Access, this episode is full of practical lessons from someone who has already done it several times. 🎧 Watch the full conversation at entra.news/p/how-to-migra…





Taken from the Stryker Handala / Intune Detection Pack v2 "Check PIM role settings for Global Administrator, Intune Administrator, and Cloud Device Administrator. If you see only the "Require Azure MFA" checkbox and no Authentication Context configured, you have the same gap that enabled the Stryker wipe. Configure Authentication Context with FIDO2 or certificate-based auth today. Enable Intune Multi-Admin Approval for wipe, retire, and delete actions. Tenant Administration > Multi Admin Approval. Under 10 minutes. No additional licensing required. Deploy Rule 13 (bulk wipe threshold alert). Five wipes in 15 minutes from a single identity fires the alert. Wire it to a Logic App that calls revokeSignInSessions on the triggering account via Microsoft Graph. " link to Detection Pack v2 blog and direct download. Please share so others can lock down their InTune environments please threathunter.ai/blog/iran-hand…






azd + maester = 😲 Soon ™️






✨ Track Speakers: Identity ✨ ✨ Ever dreamt of being a tech superhero? Cape up and dive into the Microsoft Identity cosmos with us! 🚀 Get set for the geek fest of the year at Experts Live Denmark 2026 on 24+25th February 2026! 🔗 All aboard: eldk26.expertslive.dk 🤖💡 Rub elbows with tech titans like Christopher Brumm (@cbrhh?s=09) | Fabian Bader (@fabian_bader) | Eric Woodruff (@ericonidentity) | Thomas Naunheim (@thomas_live) | Jan Vidar Elven (@JanVidarElven) | Klaus Bierschenk | Merill Fernando (@merill) | Pim Jacobs. #ELDK26 #ExpertsLiveDK #Microsoft #Community #Security #Azure #AI #ModernWorkplace #Intune #DevOps #Automation #M365 #PowerPlatform #Data #Purview #Development #OpenAI #Copilot #AVD #W365 #Identity #Entra ELDK26 Organizers: Morten Knudsen (@knudsenmortendk) Martin Byskov (@ByzzByskov) Morten Leth Hedegaard (@morten_leth) Kent Agerlund (@agerlund)


Today at 15:00 CET #YellowHat will start. It's a free live streamed conference around Microsoft Security and we have amazing speakers and topics lined up for you. Register now to reserve your free spot. yellowhat.live












