Cloud IdentitySummit

465 posts

Cloud IdentitySummit banner
Cloud IdentitySummit

Cloud IdentitySummit

@identitysummit

Community event with focus on related topics to #AzureAD and Cloud #Identity in #Azure. Organized by the @AzureBonn Team.

Koblenz, Germany Katılım Nisan 2020
14 Takip Edilen663 Takipçiler
Cloud IdentitySummit retweetledi
NeowinFeed
NeowinFeed@NeowinFeed·
Microsoft just dropped an emergency security hotpatch (KB5084597) for Windows 11 24H2 and 25H2. 🚨 It fixes a critical RCE flaw in the RRAS management tool that could let attackers execute code over a network. Check Windows Update now. 💻 Details: neowin.net/news/kb5084597…
English
2
39
99
10.1K
Cloud IdentitySummit retweetledi
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
I noticed that @brucon talks are published in Youtube, including my "Epic" talk on Entra ID Token Theft Protections! Besides the technical part, by watching the talk you'll learn: ✅ How to survive live-only-demo-talk when network isn't working 🥵 ✅ How to reveal your demo user password to the audience 🤦‍♂️ ✅ How to deal with very tricky questions from the audience 🥶 youtube.com/watch?v=YlPkCX…
YouTube video
YouTube
Dr. Nestori Syynimaa tweet media
English
1
12
60
6K
Cloud IdentitySummit retweetledi
Merill Fernando
Merill Fernando@merill·
🎙️ Satya Nadella predicts that soon, your organization will have more AI Agents than employees. Are you ready to manage them? The firehose of news from Microsoft Ignite was intense, and if you’re feeling overwhelmed by the shift to "Agentic AI" and the explosion of new identity features, you are not alone. To cut through the noise, I gathered a stellar panel of experts for the first-ever live episode of Entra.Chat: @NathanMcNulty, @rucam365 , @Thomas_Live, and Martin Sandren (who runs Identity globally for IKEA!). We skipped the fluff and went straight to the hard questions: 🔑 The Great Passkey Debate: Are "Synced Passkeys" a security compromise or the only realistic way to finally kill the password? 🤖 The Rise of Agent ID: You might already have hundreds of AI agents in your tenant without realizing it. We discuss how to govern this new layer of non-human identity before it becomes technical debt. 💰 The ROI of Account Recovery: Why spending $70 (or $30 tx to @UK_Daniel_Card for helping with the math 😉) on a helpdesk password reset is a thing of the past when you can automate recovery for a fraction of the cost. 🛡️ Security Copilot: Now included in E5 - we talk about how to actually use it to save time on investigations. Whether you are a consultant or running identity for a massive enterprise, this conversation is packed with practical takeaways. Listen to the full breakdown at entra.chat
Merill Fernando tweet media
English
5
9
40
5K
Cloud IdentitySummit retweetledi
Merill Fernando
Merill Fernando@merill·
👋 Folks, I'm super excited to announce the launch of the Microsoft Zero Trust Assessment! I've been working on this project for the past year at Microsoft with an extended team including our security researchers, product feature teams and docs Here's what it does 🧵👇
Merill Fernando tweet media
English
35
167
790
57.5K
Cloud IdentitySummit retweetledi
Thomas Naunheim
Thomas Naunheim@Thomas_Live·
Had the great privilege and a lot of fun joining 🎙️#EntraChat together with my friend and MVP fellow @samilamppu! 🙏 Big thanks to @merill for having us - it was a pleasure to be part of the podcast. I hope everyone listening enjoyed it as much as we did recording it!
Merill Fernando@merill

@Thomas_Live and @samilamppu quietly built one of the most useful open projects for Entra ID defenders. The Entra ID Attack & Defense Playbook It’s free, community-driven, and packed with real detection logic and KQL queries. 🧵👇

English
0
5
13
2.6K
Cloud IdentitySummit retweetledi
Intune Support Team
Intune Support Team@IntuneSuppTeam·
🚀 Windows 11 25H2 + Intune: New Settings Unlocked! 🛬 36 new Windows 11 25H2 settings have landed in Intune’s settings catalog! 🛡️ From expanded controls for security and privacy, to device management, there are many settings available to configure today, with many more to come in future updates. 📚 Read the blog to see the available settings, and let’s empower your IT administrators to efficiently manage and secure devices from day one! ➡️ Learn more: aka.ms/Intune/Windows… #MSIntune #IntuneSettingsCatalog
English
6
54
152
13.8K
Cloud IdentitySummit retweetledi
Ru Campbell
Ru Campbell@rucam365·
Still time to sign up at aka.ms/EntraZeroTrust for the rest of the Entra Zero Trust Practitioner series. On 9 October, I'm joining @merill, @nathanmcnulty, and more for a live Q+A on everything Entra identity and network access.
Ru Campbell tweet media
English
3
6
41
9.5K
Cloud IdentitySummit retweetledi
Merill Fernando
Merill Fernando@merill·
Hey folks, here's a lucky opportunity to spend an hour with some brilliant Entra minds. Join me for a live AMA 🎙️ with the Entra architecture team! Bring all your hard questions or just listen in to a fun chat. Register at aka.ms/entra/ama Want to warm us up? Post your questions 👇
Merill Fernando tweet media
English
3
9
32
6.2K
Cloud IdentitySummit retweetledi
Windows IT Pro
Windows IT Pro@MSWindowsITPro·
Windows 11, version 25H2 is now available! Explore the tools and resources to help you roll out this update at your organization! msft.it/6015svG8J
Windows IT Pro tweet media
English
9
52
241
21.8K
Cloud IdentitySummit retweetledi
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
Ready for @identitysummit 2025! ✅️ Morning run ✅️ Breakfast ✅️ Slides ✅️ Demos
Dr. Nestori Syynimaa tweet mediaDr. Nestori Syynimaa tweet media
English
3
1
28
2K
Cloud IdentitySummit retweetledi
Merill Fernando
Merill Fernando@merill·
🚨 Microsoft admins, are your conditional access policies weak? 😱 @fabian_bader shares some common bypasses in our latest Entra.Chat podcast episode! 🔒 Dive into this thread for must-know insights to secure your tenant! 🧵👇 #Cybersecurity #MicrosoftEntra
Merill Fernando tweet media
English
2
34
162
21.5K
Cloud IdentitySummit retweetledi
Fabian Bader
Fabian Bader@fabian_bader·
A very important security feature finally in a wonderful @merill visual. And there is already something in the making, according to this message center information, that will help to target attestation for critical users mc.merill.net/message/MC1097…
Merill Fernando@merill

So who else has seen this 'Enforce attestation' setting and didn't really understand what it does? Well you can count me as one of the clueless until today. So I had to create this visual so I won't forget it the next time. (Bookmark this!)👇 What is Passkey Attestation? ❓ Passkey attestation is a verification process that ensures: 🎯 The passkey was created by a legitimate, trusted authenticator ✅ 🎯 The authenticator meets security and compliance requirements 📋 🎯 The passkey is hardware-backed and meets organizational security policies 🏢 🔑 For FIDO2 Security Keys: → Microsoft relies on the FIDO Alliance Metadata Service (MDS) to validate security keys → During registration, security keys must provide a "packed" attestation statement as defined by the FIDO standard → The attestation certificate must chain back to roots in the FIDO Alliance MDS → Each security key has an Authenticator Attestation GUID (AAGUID) - a 128-bit identifier indicating the key type and model 📱For Microsoft Authenticator: → 🍎 iOS: Uses the iOS App Attest service to verify the legitimacy of the Authenticator app. → 🤖 Android: Uses two methods: → Play Integrity API to verify app legitimacy. → Android key attestation to verify hardware backing. 🎛️ Configuration Options Administrators can configure attestation enforcement in the Passkey (FIDO2) authentication method policy: 👍 Enforce attestation = Yes : Only allows registration of attested passkeys from verified vendors/apps. 👎 Enforce attestation = No : Allows any passkey but still collects attestation data. Requirements for Vendor Compliance ☑️ ✅ For FIDO2 security keys to pass attestation when enforcement is enabled: ✅ FIDO2 certification at any level 🏅 ✅ Metadata published to FIDO Alliance MDS 📖 ✅ Support for FIDO 2.0 or higher ⬆️ ✅ User verification capability (biometrics or PIN) 👆 ✅ Resident keys (discoverable credentials) 🔎 ✅ HMAC secret or PRF extension support 🔐 🏆 Benefits 💜 Security Assurance: Ensures only legitimate, hardware-backed passkeys are registered 🔰 💜 Vendor Verification: Validates that passkeys come from trusted manufacturers/providers 🤝 💜 Compliance: Helps organizations meet security requirements by blocking potentially compromised authenticators 📋 💜 Hardware Backing: Ensures passkeys are stored in secure hardware elements 🤔 Limitations and Considerations → ☁️ Attestation relies on external services (Apple, Google) which can experience outages → ⏳ There may be up to a 4-week delay for new security keys to be recognized after appearing in FIDO Alliance MDS → 🔄 Heavy service usage can cause registration failures requiring retry attempts To learn more see: → Entra ID attestation vendors - learn.microsoft.com/en-us/entra/id… → Enable passkeys in Authenticator - learn.microsoft.com/en-us/entra/id… If you found this useful please, bookmark, like, and retweet 🙏 Follow me for more tips like this.

English
0
6
29
3.9K
Cloud IdentitySummit
Cloud IdentitySummit@identitysummit·
with speakers and attendees from around the world. 📸 Here are some impressions from those early days up to last year’s event… Now, we’re gearing up for our latest edition on September 4th in Dortmund.
English
1
0
0
79
Cloud IdentitySummit
Cloud IdentitySummit@identitysummit·
🚀 Looking back on five years of #IdentitySummit It all began during the pandemic — our first edition was a virtual-only event, streamed live from Koblenz. Over the years, we’ve taken the road through the Rhineland region —
Cloud IdentitySummit tweet mediaCloud IdentitySummit tweet mediaCloud IdentitySummit tweet mediaCloud IdentitySummit tweet media
English
1
1
1
160