Kenneth van Surksum - MVP

9.4K posts

Kenneth van Surksum - MVP banner
Kenneth van Surksum - MVP

Kenneth van Surksum - MVP

@kennethvs

Microsoft MVP Enterprise Mobility & Security | Modern Workplace Consultant | Workplace Ninja User Group Netherlands | Secure At Work

Amersfoort, the Netherlands Katılım Kasım 2007
3.5K Takip Edilen5.3K Takipçiler
Sabitlenmiş Tweet
Kenneth van Surksum - MVP
Kenneth van Surksum - MVP@kennethvs·
🚀 New Conditional Access Baseline (v2025-10) is now live on GitHub! 👉 github.com/kennethvs/caba… It includes: ✅ JSON export of all CA policies 📄 PDF overview via Merill’s CA Documenter 🧰 Export tooling by Mikael Karlsson Based on my earlier Conditional Access Demystified whitepaper still updated regularly with the latest Microsoft Entra ID practices. Full post 👉 vansurksum.com/2025/10/18/con…
English
2
25
154
7.8K
Kenneth van Surksum - MVP retweetledi
MEM Summit 2026
MEM Summit 2026@MemSummit·
Identity attacks continue to evolve, and so must our defenses. Session : What’s Next After You Mitigated AITM? Speakers ⭐️ Erik Loef @erikloef ⭐️ Kenneth van Surksum @kennethvs Over the last decade we moved from passwords to MFA, and more recently to phishing-resistant MFA to mitigate adversary-in-the-middle attacks. But attackers continue to adapt, and new threats are emerging. In this session, Erik and Kenneth will explore what comes next in protecting identities, including risks such as token theft and session hijacking, and what organizations should consider as the next step in strengthening their identity security strategy. What you will learn • How identity attacks have evolved from passwords to AITM attacks • Why phishing resistant MFA is only part of the solution • What new threats such as token theft mean for modern identity security Discover the full agenda and all sessions at endpointsummit.com #MEMSummit #Endpointmanagement
English
0
5
2
366
Kenneth van Surksum - MVP retweetledi
MC2MC
MC2MC@mc2mcbe·
On February 5th, we’re excited to have @pdaalmans and @kennethvs take the stage at MC2MC Connect. Their session, “Essential Tips and Tricks for Today’s Workplace Admin,” is packed with actionable, real-world insights. 🎟️ connect.mc2mc.be #MC2MC #ConnectMC2MC2026
MC2MC tweet media
English
0
2
4
298
Kenneth van Surksum - MVP retweetledi
WP Ninjas User Group NL
WP Ninjas User Group NL@wpninjasnl·
🚀 Speaker Announcement! Excited to welcome Ugur Koc, well-known community contributor and Senior Product Manager at glueckkanja, to WP Ninja Connect on 4 Feb 2026! Creator of many tools that truly help the community move forward. 🔗 nl.wpninjas.global/wpninjas-conne… 🥷🏼 #WPNinjasNL
WP Ninjas User Group NL tweet media
English
0
4
7
453
Miha Pecnik
Miha Pecnik@MihaPecnik·
@kennethvs Just going through this, considering it for a project. I see that CAU005 is missing, is that on purpose?
English
1
0
0
47
Kenneth van Surksum - MVP
Kenneth van Surksum - MVP@kennethvs·
🚀 New Conditional Access Baseline (v2025-10) is now live on GitHub! 👉 github.com/kennethvs/caba… It includes: ✅ JSON export of all CA policies 📄 PDF overview via Merill’s CA Documenter 🧰 Export tooling by Mikael Karlsson Based on my earlier Conditional Access Demystified whitepaper still updated regularly with the latest Microsoft Entra ID practices. Full post 👉 vansurksum.com/2025/10/18/con…
English
2
25
154
7.8K
Kenneth van Surksum - MVP
Kenneth van Surksum - MVP@kennethvs·
RT @Mister_MDM: The Intune MDM Device Certificate and its renewal… Next year (around 03/04 of 2025) every single Intune MDM certificate wi…
English
0
6
0
26
Kenneth van Surksum - MVP retweetledi
Rudy Ooms
Rudy Ooms@Mister_MDM·
Ever feel like Intune takes its time to apply a policy? That behavior isn’t something new…. it goes back to the original “get, set, get” model Microsoft built nearly twenty years ago. The same OMA DM Protocol that once powered Windows Phone became the blueprint for every Intune policy still running today. Even now, you can still spot WindowsPhoneProvider references buried inside the OMA DM client code. This blog looks at where Intune all started: patchmypc.com/blog/the-histo… #Intune #MSIntune #Windows #Windows11
Rudy Ooms tweet media
English
1
26
103
15K
Kenneth van Surksum - MVP retweetledi
Rudy Ooms
Rudy Ooms@Mister_MDM·
Ever wondered what those S 1 12 1 entries in your Administrators group actually represent With the new AADSidToNameV2Support feature, Entra group and role SIDs are automatically translated into real names and stored on the device (cached) Here is the blog that explains how it works patchmypc.com/blog/windows-f… #Intune #MSIntune #Windows #Entra #Windows11 #Azure
Rudy Ooms tweet media
Rudy Ooms@Mister_MDM

When you see an S-1-12-1-something SID in (for example) your local Administrators group, you have no idea what it actually represents. Now that’s changing! With the new feature flag active, Windows finally recognizes Entra groups by name. No more guessing which SID, resembles which group . It's now perfect readable. #Intune #MSIntune #Windows #Windows11

English
2
36
138
12.9K
Kenneth van Surksum - MVP
Kenneth van Surksum - MVP@kennethvs·
When “Block All” in Conditional Access blocks too much… 🔒 Until recently, guest users couldn’t change their MFA methods when you blocked all cloud apps. The My Sign-ins app is now selectable in Conditional Access 🎉 Finally possible: ✅ Limit guests to M365 resources ✅ Keep self-service (MFA, profile) working 🧩 Read how to configure it: vansurksum.com/2025/10/12/con… #EntraID #ConditionalAccess #Microsoft365 #Intune
English
0
20
133
9.2K
Kenneth van Surksum - MVP retweetledi
Jose | MVP
Jose | MVP@schenardie·
@wpninjasummit is kicking off soon. All paths lead to Baden.
Jose | MVP tweet media
English
1
4
25
1.6K
Rudy Ooms
Rudy Ooms@Mister_MDM·
🚨 KB5065848: The ZDP Update That broke Autopilot and Broke the BitLocker Policies! First, BitLocker policies started failing silently. The event logs showed “applied,” but devices didn't accept the 256-bit encryption. Then, Windows Autopilot devices were stuck on the "Identifying" stage during ESP. Same week. Same Windows image. Same assignments. Same Policies The trail led us to KB5065848, a Zero Day Patching (ZDP) update dropped during OOBE. This ZDP quietly introduced the restore functionality for Windows Backup for organizations, but also updated the PolicyManager.dll. Combining Application Guard and Edge policies will break the omadmclient.exe. Microsoft has since pulled the ZDP update, which fixed BitLocker and Autopilot but it also means the restore functionality for Windows Backup for Organizations, the very thing KB5065848 was meant to enable, is now gone again. Two problems, one ZDP package, and one feature quietly disappearing. 🔗BitLocker ISSUE: patchmypc.com/blog/bitlocker… 🔗Autopilot ISSUE and FIX: patchmypc.com/blog/windows-a… #Intune #MSIntune #Windows #WindowsAutopilot
Rudy Ooms tweet media
English
8
27
93
8.8K
Kenneth van Surksum - MVP retweetledi
WorkPlaceNinjaSummit
WorkPlaceNinjaSummit@wpninjasummit·
When productivity meets flexibility, security must keep up. In this session, Kenneth van Surksum shows how to protect your data in Microsoft 365 and other SaaS apps, without blocking collaboration. Real-world experience, demos, and practical strategies to secure your workplace.
WorkPlaceNinjaSummit tweet media
English
0
1
5
351