Mike Weaver

226 posts

Mike Weaver banner
Mike Weaver

Mike Weaver

@MADMike_365

Microsoft MVP | Office 365 Technologist Specializing in Mergers, Acquisitions & Divestitures | Equality & Inclusion Advocate | Author of https://t.co/jyetLJeBeE | He/Him

London, UK Katılım Nisan 2015
264 Takip Edilen227 Takipçiler
Mike Weaver
Mike Weaver@MADMike_365·
This is a great explanation. I run into a lot of clients that demand they own & create the App Reg. This clearly explains why it isn’t usually the right decision.
Merill Fernando@merill

I've recently noticed that Azure AD admins are being asked to create multi-tenant apps in their corporate tenant. In some instances, it was the devs in the org asking for this, in other instances it was the application vendor. Here are some things to watch out for 👇 Multi-tenant apps are meant for ISVs and SaaS vendors to create an instance of an app in 'their own tenant'. Examples of such apps are ServiceNow and SalesForce. When an app is created as a multi-tenant app, ANY user from ANY Azure AD tenant can visit the app's url and sign in. If you create a multi-tenant app in your corporate tenant and apply a conditional access policy. The policy only applies to users in your tenant. ⚠️ I'll repeat ➟ your CA policies do not apply to users signing into your multi-tenant app in their own tenant. So, what is the general rule of thumb that Azure AD admins and cybersecurity teams should follow? If the app is from a vendor/SaaS provider: ✅ Add the app to your tenant from the Azure AD Application Gallery ✅ If the app is not in the gallery, you as the customer can request the vendor to get their app listed on the Azure AD app gallery ✅ If app gallery is not an option, request the vendor to create the app in their own tenant. Use the admin consent model to add the app to your tenant. ✅ If the only option provided by the vendor is to create the app in your tenant, push for the vendor to allow you to create a single tenant app. If the app is developed by devs in your org and is only meant for users in your own org. ✅ Ask why the dev needs this to be a multi-tenant app? ✅ Ask if the devs have implemented appropriate checks to prevent sign-ins from other tenants. There are many valid scenarios for creating multi-tenant apps in your tenant, including ✅ You are a SaaS vendor or ISV and you create and publish apps that Azure AD customers can consume ✅ You manage multiple Azure AD tenants in your org and you need a single service principle (workload identity) to access the other tenants (e.g. automate DevOps tasks across your tenants) Here are some further reading on the topic of multi-tenancy. These are meant for devs however its good reading for admins to appreciate what it takes to build a least-privilege multitenant app. 👉 learn.microsoft.com/en-us/azure/ar… 👉 learn.microsoft.com/en-us/azure/ac… Liked this post? Please retweet this to share with your network. 🚀 Feel free to follow me. I try to post at least one weekly tip related to Microsoft Identity, Azure Active Directory or Microsoft Graph. 🙏

English
0
0
1
263
Mike Weaver retweetledi
Microsoft 365 Status
Microsoft 365 Status@MSFT365Status·
We've rolled back a network change that we believe is causing impact. We're monitoring the service as the rollback takes effect.
English
105
312
876
298.9K
Mike Weaver
Mike Weaver@MADMike_365·
MADNick and I have added Roxy to our family ;). I don’t think MADRoxy works, but will see in time!
Mike Weaver tweet media
English
0
0
4
481
Mike Weaver
Mike Weaver@MADMike_365·
@paulrobichaux @LastPass I am, for now, taking the stance that all of these firms are strong targets and can get hit. But one more issue and they are fired.
English
0
0
1
165
paulrobichaux
paulrobichaux@paulrobichaux·
In light of the @LastPass breach, I'm firing them from my family security team. What should I move to instead?
English
5
1
0
1.5K
Mike Weaver
Mike Weaver@MADMike_365·
It’s afternoon tea here in London, time for that third coffee in New York, and time for a brisk morning walk in Cali.  In one hour, CJ Gregorios and I are here at Virtual #TEC2022 with our ENI Session on Preferred Gender Pronouns For Systems Administrators!
Mike Weaver tweet media
English
0
0
3
0
Mike Weaver
Mike Weaver@MADMike_365·
Sound check done! Ready for my session with Becky Cross at virtual #TEC2022!
Mike Weaver tweet media
English
1
0
4
0
Ru Campbell
Ru Campbell@rucam365·
What Intune/GPO settings would you recommend to make Windows 10/11 more enterprise ready? Eg: OneDrive SSO, remove Edge bloat, security baselines, disable first sign in animation.
English
33
41
249
0
Mike Weaver
Mike Weaver@MADMike_365·
Well…LCY -> ZUR -> FRA -> LHR. Gets me the three segments I need way cheaper than any other option. Leave at 8:45am and land at 4:45pm. I wish I had enough time for the lounge at Zurich!
English
0
0
0
0
Mike Weaver
Mike Weaver@MADMike_365·
Ugh. I am very close to maintaining Star Gold. United got rid of the PQF requirement for non-residents. Do I fly EWR to BDL to keep status? Might end in divorce where it’s the day after landing from London. It would be a amazing race with Nick as he gets the hire car!
English
2
0
1
0
Mike Weaver
Mike Weaver@MADMike_365·
@uacat92 I’m looking at a non direct trip to Zurich and back the same day right now ;)
English
0
0
1
0
Mike Weaver
Mike Weaver@MADMike_365·
@jsnover Husband and I both have them. We love them. The monitor arms are very good, including the laptop attachment. Highly recommend the keyboard tray so it’s at the right height whether you are standing or sitting.
English
0
0
1
0
Jeffrey Snover
Jeffrey Snover@jsnover·
Does anyone have experience with the #Uplift V2 Standing Desk? Worthwhile? Any must-have accessories? Any pass-on-this accessories?
English
38
2
32
0
Mike Weaver
Mike Weaver@MADMike_365·
@rucam365 It really is the big conflict. For home devices I have been helping people with bitlocker to go. For so many years I forced a chip down on people, but was always hard to convince people of the price. (And rightfully so)
English
0
0
1
0
Ru Campbell
Ru Campbell@rucam365·
@MADMike_365 Most of them look so old they're unusable. The thing that got me about the TPM requirement is there are so many good desktop devices from the i5-ish era that will just become e-waste :( I get the need for TPM as the guardian of all secrets, but the waste grosses me out.
English
1
0
0
0
Mike Weaver
Mike Weaver@MADMike_365·
The TPM Requirement for #windows11 is crap…till you see stuff like this on the way to the gym this morning. I fully support "forcing" basic security principles by default. Everyone needs local #diskencryption. If you are running Windows, this is #bitlocker for most.
Mike Weaver tweet media
English
3
0
2
0
Mike Weaver
Mike Weaver@MADMike_365·
@AlanMByrne I’ll send you the family Apple Crisp recipe ;). It’s like a crumble but better!
English
0
0
0
0