Samuel Devasahayam

1.2K posts

Samuel Devasahayam banner
Samuel Devasahayam

Samuel Devasahayam

@MrADFS

Group Program Mgr in the Identity division @ Microsoft. Run the Authentication & Device platform team which includes Azure AD, ADFS and Devices. Music lover.

Seattle Bergabung Haziran 2013
194 Mengikuti2.7K Pengikut
Kévin Chalet
Kévin Chalet@kevin_chalet·
@Alex_A_Simons hey. Do you know if there are plans to update Azure AD/Microsoft Account to support returning code_challenge_methods_supported in the server configuration document?
English
2
0
0
0
Anders Abel
Anders Abel@anders_abel·
I have SAML2 compatibility issue with @azuread. I've tested two different XML Signature validation tools and it looks like AzureAD might sometimes create incorrect signatures. Do I know someone with contacts in the AAD team that can help find the right person to look into it?
English
1
0
0
0
Samuel Devasahayam
Samuel Devasahayam@MrADFS·
Hey folks! We just added a set of new features to help customers move their apps/authentication off ADFS (3P IDP) over to Azure AD & secure them better with Conditional Access! Check it out!
Samuel Devasahayam tweet media
English
4
53
135
0
Samuel Devasahayam
Samuel Devasahayam@MrADFS·
@Luis_P_743 @jsnover Hey Luis, did this get resolved? If not could u clarify the scenario. It seems like an automated device provisioning scenario.
English
1
0
0
0
Luis
Luis@Luis_P_743·
@jsnover Have you heard any progress on using PS to AAD join/enroll a device? PPKG expirations are a pain and not everyone wants to use AP.
English
1
0
0
0
Samuel Devasahayam
Samuel Devasahayam@MrADFS·
@DrAzureAD @zatennisfan @Secureworks Thanks for the detailed post! As mentioned, this requires GA (which you should be protecting at all costs) and treat your ADDS/ADFS physical infrastructure as is normally recommended for Tier0 infra.
English
1
0
2
0
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
@zatennisfan @Secureworks This doesn't actually need AD FS infrastructure at all. Global Admins can register fake agents to any tenant with Azure AD P1 or P2 subscription and use them to spoof sign-ins log. #registering-fake-agents-with-aadinternals-v0-5-0-and-later" target="_blank" rel="nofollow noopener">o365blog.com/post/hybridhea…
English
1
0
0
0
Samuel Devasahayam me-retweet
Sean Deuby
Sean Deuby@shorinsean·
Heads up, #ActiveDirectory #sysadmin's. This free utility evaluates your AD against 59 different IoEs, orders them by severity, and maps them to the MITRE ATT&CK framework. @MrADFS
Semperis@SemperisTech

How secure is your #ActiveDirectory environment? Find out with #PurpleKnight, a free #security assessment tool that uncovers dangerous misconfigurations attackers can use to steal data and launch #malware campaigns. ​bit.ly/2Ov4Fxr

English
0
6
15
0
Samuel Devasahayam
Samuel Devasahayam@MrADFS·
@IwisVC Which log is this? ADFS logs? If so, I need to check with my engineering team. Let me know if you still need help.
English
1
0
0
0
Iris Van Cauwenbergh
Iris Van Cauwenbergh@IwisVC·
@MrADFS I'm looking for help. for one of our customers we've had to go through the unified audit log and found in the properties UserAuthenticationMethod=16. Through docs we think it is "Secure PIN Reset". What is it exactly?MFA deleted? PIN of WHfB PIN reset locally?
English
2
0
0
0
Jay Van der Zant
Jay Van der Zant@jayvdz·
@MrADFS hey Samuel, are Custom Attribute Stores still supported on #ADFS 2019? There's no documentation for them beyond this old article (docs.microsoft.com/en-gb/archive/…). My customer has an issue uplifting a 2016 CAS for 2019, just want to check before I warm up the lab to investigate.
English
1
0
0
0
Samuel Devasahayam
Samuel Devasahayam@MrADFS·
@miketheitguy Hey Mike, do work with your GTP contact to file this as a blocker with some clarity on use cases (e.g. air gapped vs on-prem only app)
English
0
0
0
0
Samuel Devasahayam
Samuel Devasahayam@MrADFS·
@miketheitguy Hi Mike, we are still completing FIDO in AAD. Currently we have no plans to bring FIDO natively to on-premises. Things could always change!
English
0
0
0
0
Morgan Simonsen
Morgan Simonsen@msimonsen·
@MrADFS Need some help with Azure AD DS. Can we get in touch?
English
1
0
0
0
Samuel Devasahayam
Samuel Devasahayam@MrADFS·
@AlexFilipin @markwahl @azuread @markmorow @citrix Yup. Should work. Front end auth to Citrix via AAD B2B, token contains the UPN that has been provisioned in Citrix server AD environment. FAS acts like an impersonation service that provisions a short lived certificate to the client that is used to RDP.
English
0
0
3
0
Tobias Zuegel | mrentraid.bsky.social
@nicolonsky Device Code flow is a problem on its own when using ADFS and a 3rd party MDM as everything on ADFS is evaded. This is the perfect way for data leakage. My opinion is that device code flow should be an optional configuration per app and off by default. Any news here @MrADFS ?
English
2
0
2
0