Glenn Van Rymenant

91 posts

Glenn Van Rymenant

Glenn Van Rymenant

@gvanrymenant

Katılım Kasım 2016
120 Takip Edilen64 Takipçiler
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
@DebugPrivilege For backup scenarios, create BTGs in the target tenant to execute privileged actions like assigning roles and consenting to application permissions in case of a restore.
English
0
0
2
74
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
@DebugPrivilege I would personally avoid consenting such permissions, even to IAM solutions as they are absolute (cannot be scoped). Your entire Microsoft 365 (including Azure and potentially your AD) is at the mercy of your IAM solution.
English
0
0
2
85
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
@rucam365 @TechBrandon @NathanMcNulty Didn't immediately find the reference to 8 digits, what is your stance on 8 versus 6? I read a few reports that concluded that 8 doesn't offer the additional value people think it does because of human nature.
English
2
0
2
370
Louis Mastelinck | LouSec | MVP
Louis Mastelinck | LouSec | MVP@LouisMastelinck·
Is anyone else finding it incredibly difficult to hide non-email licensed cloud admin accounts from Teams search results? Or am I missing a trick here?
English
2
0
5
1.7K
Merill Fernando
Merill Fernando@merill·
In PowerShell, do you use PascalCase or camelCase for your variable names? The unofficial PowerShell style guide leans towards Pascal case. 👇 If you wish, you may use camelCase for variables within your functions (or modules) to distinguish private variables from parameters, but this is a matter of taste. github.com/PoshCode/Power… Which format do you prefer using?
English
35
11
43
19.2K
Nathan McNulty
Nathan McNulty@NathanMcNulty·
On my way to the Microsoft campus, first time trying to use Microsoft Authenticator passkeys on an airplane... I just learned the authenticator (phone) requires Internet access as well This means MS Authenticator is still a no go for poor signal areas - back to security keys
Nathan McNulty tweet media
Nathan McNulty@NathanMcNulty

Here we go 🛫

English
9
5
67
42K
David O'Brien (he/him)
David O'Brien (he/him)@david_obrien·
Confusing. I have an Entra ID access token with "Directory.AccessAsUser.All" scope. The user can browse the Entra ID portal and see everything (Global Reader), like #view/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/~/UserSettings" target="_blank" rel="nofollow noopener">portal.azure.com/#view/Microsof… . However, calling the REST endpoint for those settings using that token says "no access".
English
2
0
2
1.5K
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
@rucam365 This really is starting to become the "gift" that keeps on giving, curious for what else will pop up... Begs the question if they wouldn't have been better off disclosing the full breadth and possible ramifications from the start...
English
0
0
2
121
Ru Campbell
Ru Campbell@rucam365·
Sounds like Midnight Blizzard dumped all the mail they had access to (scope was never confirmed, but they had full_access_as_app), are harvesting it for secrets, then spraying those. microsoft.gcs-web.com/node/32471/html
Ru Campbell tweet media
English
2
11
45
20.2K
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
@reprise_99 And while you're at it, if you sync users to Entra ID with Password Hash Sync (PHS) and still expire passwords (for whatever reason), make sure you enable CloudPasswordPolicyForPasswordSyncedUsersEnabled #cloudpasswordpolicyforpasswordsyncedusersenabled" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/entra/id…
English
0
0
6
174
Matt Zorich
Matt Zorich@reprise_99·
This is your yearly reminder to go and deploy Microsoft Entra ID Password Protection to improve your password complexity in on-premises Active Directory if you're licensed for it. Over the years, I have collected a list of misconceptions about how this product works, see below:
English
5
62
276
66.8K
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
PSA: listing Privileged Access Groups (PAGs) a.k.a. PIM for Groups with Graph: graph.microsoft.com/beta/privilege… (spend an hour searching for it in documentation then tried some stuff based on Get-MgBetaPrivilegedAccessResource 🤦‍♂️)
English
0
0
1
75
Ru Campbell
Ru Campbell@rucam365·
not gonna lie. if you reply all to an email storm with “please remove me immediately”, i cannot take you seriously.
English
21
2
70
8.7K
Jan Bakker
Jan Bakker@janbakker_·
ING medewerker legt even uit waarom ik via de post mijn zaken moet regelen.....
Jan Bakker tweet media
Nederlands
3
0
3
1.3K
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
@merill as we can now set a sponsor on a (guest) user object in EID (preview), will we soon be able to leverage that in Identity Governance (e.g.: Access Review - reviewers) as well?
Glenn Van Rymenant tweet media
English
0
0
0
24
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
The car is working fine, besides that weird error light. Also keeps odd clicking noise, there wasn't anything like that on my previous Beemer. Any ideas @rucam365?
Dr. Nestori Syynimaa tweet media
English
8
0
29
4.4K
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
New azure-blue family member has arrived! Should I claim the price of new vanity plates from Microsoft due to #AzureAD re-branding 🤔
Dr. Nestori Syynimaa tweet media
English
18
6
169
27.9K
Glenn Van Rymenant retweetledi
Merill Fernando
Merill Fernando@merill·
If you are a reddit user, we now have a /r/entra subreddit where you can ask questions and get help from the Entra community. BTW if you are an MVP or Microsoft employee, join and let me know so I can set your user flair/badge.
Merill Fernando tweet media
English
5
12
71
11.3K
Glenn Van Rymenant
Glenn Van Rymenant@gvanrymenant·
@mariussmellum Good thing that MS allows eady blocking from the portal (creates auth policy on EXO as well) but I would love to see a whitelist option in the portal for orgs that have a few exceptions.
English
0
0
0
14
Marius Solbakken
Marius Solbakken@mariussmellum·
Lots of organizations seeing an increased number of smtp based brute force attempts towards their 365 environments, even though CA block is in place. You should look into disabling SMTP auth: learn.microsoft.com/en-us/exchange…
English
2
15
39
5.4K