Category: Events & Community
All my posts
Azure Italia Podcast: the episode where I was a guest is now online
⚠️ Warning for English-speaking followers: this podcast is in Italian language ⚠️
Fun chat, lightning-fast editing: the episode of Azure Italy Podcast that I was a guest on is already available online!
🎙️ You can find it here:
➡️ Azure Italia Podcast - Puntata 11 - Da Azure AD a Entra ID con Riccardo Corna
And on all the other major podcast platforms: Apple, Amazon, etc. 😉
Beyond this episode, I recommend subscribing to the podcast so you don’t miss any: it’s rare to find content like this in the Italian language, and Carlo Sacchi is doing an excellent job!
All my posts
#POWERCON2023: Watch the video of the session on Windows Hello for Business
A few days ago, the #POWERCON2023 was held, an online conference organized by the ICTPower.it community. As always, I was very happy to participate, and this year, I chose to present a session on Windows Hello for Business, discussing an aspect that I believe is underestimated and not well-known to most: Windows Hello for Business is a passwordless and multi-factor authentication!
Do you want to know why and how it works?
All my posts
I'll be a speaker at #POWERCON2023 on July 14, 2023
🗓️ #SaveTheDate July 14, 2023: one last exciting event before going on vacation, the #POWERCON2023! A whole day with many sessions together with industry experts, talking about security, Microsoft Entra, Intune, Virtual Desktop and Windows 365, Defender for Endpoint, and much more. In short, I would probably run out of characters in a LinkedIn post if I wanted to list everything.
🗓️ When? 14 Luglio 2023
🌍 Where? Online, all the information to register can be found at these links:
All my posts
Online: Video of My Session at Be Connected Day 11 (June 15, 2023)
The video of the session Artificial Intelligence in the Service of Cybersecurity: From 0 to Microsoft Security Copilot that I held (together with Michele Sensalari) at Be Connected Day 11 on June 15, 2023, in Bologna, is now available online.
For convenience, I have embedded the video to start directly at the beginning of our presentation, but from the same link, you can actually watch the live stream of the entire day.
All my posts
Be Connected Day 11: What a beautiful day!
What a beautiful day I had yesterday! So many inspiring contents, lots of friends to greet, many new people to meet, and plenty of ideas to develop for the community. As always, it was a fantastic #BeConnectedDay.
Thanks to BeConnected and Microsys for giving me the opportunity to participate, to Michele Sensalari, with whom I had the honor of sharing the stage, to all my colleagues in the SEC track, and lastly, to all the people from the communities I met—it’s fantastic to see each other in person!
All my posts
June 15, 2023: See You at Be Connected Day 11 in Bologna!
Here we go! Tomorrow is #BeConnectedDay with Michele Sensalari and many other friends. Don’t miss our session at 15:25 in Main Room Sirio P27 for those attending in person or via streaming for those following from home!
📌 There is still time to register for the streaming!
📌 Want to learn more about our session?
📌 Complete event agenda
See you tomorrow!
Riccardo
All my posts
A Coffee with... Maura Perra
Since 1994, Microsoft has been involved in device management: first with SMS, which later became SCCM, and then in 2011, with the advent of mobile devices, the Mobile Device Management service called Intune was created, which has grown… and grown… And today, it has become a suite! Let’s clarify the various pieces of technology we can find within this suite with Maura Perra, Technical Specialist in Cloud Endpoint for Microsoft!
All my posts
Video of the Tech Bits Event: Modern Endpoint Management is Available
On March 22, 2023, the Microsys event “Tech Bits: Modern Endpoint Management” took place, and now the video of the event is available!
Together with the legendary Paolo Bodini, we presented the 10 key elements to consider for modern management of corporate and personal devices.
Enjoy watching!
Riccardo
All my posts
A coffee with... Elisa Pirrone
Here we are with a new episode of “A Coffee with…”! Today’s protagonist is Elisa Pirrone, CSA Security for Microsoft Italy. Together with her, we will talk about disabling legacy protocols, creating conditional access policies, best practices, and why Windows Hello for Business is an MFA!
Here are some additional links for further information:
Common Conditional Access policy: Block legacy authentication Windows Hello for Business Overview How Windows Hello for Business works in Windows Devices Don’t forget to subscribe to our other channels as well:
All my posts
I will be a speaker at Global Azure 2023 in Turin
Spring means Global Azure, and I am delighted to announce that I will be a speaker at Global Azure 2023 in Turin, taking place on Saturday, May 13, 2023!
However, I won’t be alone on stage: joining me will be Pietro Visentin, Head of Security at Moresi!
By the way, I recommend checking out his blog Azvise, which is full of useful and interesting content.
For all the details about the agenda, it will take a few more days, so staytuned and don’t miss the event updates that you can find here:
All my posts
A coffee with... Valeria Sava
Today’s episode is a true injection of caffeine and valuable resources: Valeria Sava talks to us about ADFS and how to retire it by migrating applications to Azure AD.
Are you interested? Yes? Then after watching the video, don’t miss this workshop in Italian dedicated to this very topic! Valeria and I extensively discussed it while enjoying our coffee. Here are all the details!
🗓️ March 28, 2023
➡️ Microsoft Workshops: How to successfully migrate away from AD FS to Azure AD
All my posts
Sessions from the community event on March 8, 2023, now available
On March 8, 2023, a joint event was held between the Microsoft Intune Italian Users Group and the Microsoft Security Italian Users Group: the video of the sessions is now available.
Together with the legendary Michele Sensalari, we talked about certificate-based authentication on Azure AD.
Marco Moioli and Davide Salsi, on the other hand, delved into how to use the MAM (Mobile Application Management) features of Intune to provide security in BYOD scenarios, and Davide also demonstrated the new Microsoft Tunnel for Mobile.
All my posts
A coffee with... Francesco Molfese
“How can we leverage a public cloud while maintaining a proper security posture?”
Today, we ask this question (while sipping a cup of coffee) to Francesco Molfese (MVP), who has a clear understanding of how to maintain the right level of security both in the cloud and on-premises.
Here are some additional links for further reading:
Francesco’s blog Defender for Cloud Don’t forget to follow us on our social channels as well:
Category: Digressions
All my posts
Dedicated to Vittorio Bertocci
Today, I take a moment for a little reflection. Just a couple of months ago, I had started reading this book by Vittorio Bertocci because I felt the need to review some important concepts in the field of authentication protocols.
After reading some passages from the book, I found myself exclaiming in my head several times, “Okay… now I get it! Couldn’t they explain it like this in the official documentation?
All my posts
Back from holidays!
I haven’t sat in front of a computer for almost a month. Usually, when I sit at my home workstation, it feels like an extension of my body, given the amount of time I spend there daily for most of the year.
However, this morning, after nearly a month, I sat down to export the photos from my trip. I wasn’t accustomed to it anymore; being at the computer felt almost unnatural and uncomfortable.
All my posts
Have a great summer 2023!
Revamp of the workstation: before and after! I haven’t finished completely yet, but I’m already thrilled.
View this post on Instagram A post shared by Riccardo Corna (@itspecialistcloud)
From the photo, they seem very similar, but I assure you it was a lot of work spread over two weekends of wiring and cable ties, in the cable tray under the desk.
Finally, the ring light is in front along with the camera, and using the same support, I can also hold the microphone, all clamped to the desk without heavy and bulky stands.
All my posts
New Video Series: The Lab Series!
📰 News: Starting this week, I will be experimenting with a new format called “The Lab Series” in addition to the usual videos.
❓ What is “The Lab Series”? It will be a video of no more than a couple of minutes, without me blabbering, just pure content, like a little pill.
❓ What will it be about and who is it aimed at? It will cover practical and straightforward topics that 95% of professionals consider trivial or obvious but may not be so for someone else.
All my posts
Introducing the Microsoft Mac Admins Community!
Here’s the news we love on Mondays! 😍 Introducing the Microsoft Mac Admins Community, a new online community for IT professionals passionate about using Microsoft products on Apple Mac devices within enterprises!
Here’s a direct quote:
“This community is a place where Mac administrators working with Microsoft 365 or Intune management for Mac can connect with other users, share experiences and best practices, learn from experts and colleagues, get help with common issues, and draw inspiration from the latest innovations.
All my posts
New Twitter profile
If you’re interested, I’m starting from scratch on Twitter with a brand new profile. There, I’ll be primarily writing in English.
Why? Several reasons:
To get used to using English more frequently: I read a lot of content in this language every day, but I go through (too) long periods without writing or speaking it. Because in the Microsoft sphere on Twitter, there are truly unmissable profiles and content, and the MVP community there is very active.
Category: Cloud Datacenter
All my posts
Free eBook: Azure Defenses for Ransomware Attacks
📢 Free-resource-friday! Azure Defenses for Ransomware Attacks. Today, I’ve gathered for you a highly informative (and free) eBook that discusses the tools available in Azure to counter a Ransomware attack. Almost mandatory reading in these times!
📌 Bonus tip: Don’t miss the plethora of links to documents and resources in the “Additional Resources” slide!
📖 Here’s where you can download it:
➡️ Azure Defenses for Ransomware Attacks
Your IT Specialist, Riccardo
All my posts
Shrinking Azure VM Disk Size with PowerShell
Shrinking the disk size of a VM in Azure to save on storage costs? With a little bit of tinkering and some PowerShell magic, it can be done.
Today, I’m stepping a bit outside the usual topics I cover. 😉
A few days ago, I was looking at the consumption of my lab subscription and noticed that the disk costs were eating up a good chunk of my (limited) monthly budget.
Category: Identity & Security
All my posts
Free eBook: Azure Defenses for Ransomware Attacks
📢 Free-resource-friday! Azure Defenses for Ransomware Attacks. Today, I’ve gathered for you a highly informative (and free) eBook that discusses the tools available in Azure to counter a Ransomware attack. Almost mandatory reading in these times!
📌 Bonus tip: Don’t miss the plethora of links to documents and resources in the “Additional Resources” slide!
📖 Here’s where you can download it:
➡️ Azure Defenses for Ransomware Attacks
Your IT Specialist, Riccardo
All my posts
Microsoft Entra ID Protection: what is Risk in Entra ID?
In a Zero Trust Security approach, where identity is a fundamental element, the security of authentications can be measured to some extent based on the so-called “signals.” Analyzing these signals provides a level of “risk” for a particular user when authenticating to Microsoft 365 services. Today, I’ll tell you about Mirosoft Entra Identity Protection and what the concept of “risk” means.
As always, before diving headfirst into this “risky” journey (pun intended 🤣), we need to introduce another concept: you need to understand what signals are.
All my posts
What's New in Conditional Access: Templates and a New Overview Available
Fresh news in the Microsoft Entra ID realm: templates and a brand new overview are now publicly available. Let’s start with the templates.
Template Conditional Access policies are a powerful tool that offers a high degree of customization and granularity. That’s why it can sometimes be less intuitive to know where to begin when it comes to implementing a particular policy for a specific situation.
The availability of templates helps in this regard by providing ready-to-use tools for specific situations, making it easier to implement a conditional access criterion.
All my posts
The Lab Series: Installing Azure AD Application Proxy
As anticipated a few days ago, today we begin a series of short video clips, lasting no more than a couple of minutes, where I demonstrate activities and procedures that most people take for granted but, for various reasons, may not be so straightforward.
Welcome to “The Lab Series”!
Today, we have a quick-and-dirty procedure for installing the Azure AD Application Proxy connector.
Useful documentation for further reference:
📄 Tutorial: Add an on-premises application for remote access through Application Proxy in Azure Active Directory
All my posts
FIDO2 Key Authentication demo in Microsoft 365 on Safari iOS
🎥💊 Video Pill News: FIDO2 key support on Safari iOS!
The key used in this video is a FEITIAN, iePass K44 model, with dual interfaces: USB-C and Lightning.
I hope that FIDO2 key support arrives soon for Microsoft apps on iOS!
Riccardo
All my posts
Implementing LDAPS in Active Directory on-premises
Every forest and Active Directory domain should have LDAPS implemented, but in very few cases is it actually implemented. The topic can be intimidating because it involves certificates, but once you understand some basic concepts, it’s easier to tame than it seems. Let’s see how to implement it!
Video You can find the entire video below, or you can continue reading the article.
Article With all this talk about the cloud, I realized that I have neglected our beloved Active Directory!
All my posts
macOS Single Sign-On on Azure AD
About 2 years ago (June 2021), I had fun experimenting with a new feature that was in preview: macOS Single Sign-On (SSO) for Azure AD on Microsoft 365 applications and services.
⚠️ Update as of June 1, 2023 The “Microsoft Azure AD” plug-in is finally in General Availability and is ready to use in production environments!
You might be wondering, “What on earth is it for?”
This feature allows you to authenticate yourself and your fantastic Mac more easily to Microsoft 365 services and applications without repeated credential prompts, making the user experience even smoother and seamless.
All my posts
Convert ObjectID to SID in Azure AD and vice versa
Friday resource! If you’re tinkering with Local Groups Membership policies in Intune and (like me) have cursed a bit while converting group/role ObjectIDs to SIDs and vice versa, here’s a website that does it online instantly and conveniently.
🔹 ObjectId ➡️ SID
🔹 SID ➡️ ObjectId
I’d love to tag the author of this wonderful utility (Erik Engberg) here, but from what I’ve seen, they’re not on LinkedIn. If I’m mistaken and someone knows their exact profile, please let me know so I can give them proper thanks.
All my posts
Windows Hello for Business is the MFA for Windows login!
Why Windows Hello for Business is the Multi-Factor Authentication for Windows login and how to configure it via Intune in Azure AD Kerberos Cloud Trust mode, through the Settings Catalog.
Below is the documentation I refer to in the video:
📄 Windows Hello for Business Overview 📄 How Windows Hello for Business works in Windows Devices 📄 Windows Hello for Business and Authentication 📄 Cloud Kerberos trust deployment 📄 Enable passwordless security key sign-in to on-premises resources by using Azure AD Have you implemented Windows Hello for Business?
All my posts
Configuring BitLocker via Intune using the Settings Catalog
A few days ago, I came across a very interesting article from the Intune Customer Success Team. The article discusses how to configure BitLocker through the Intune Settings Catalog. This piqued my curiosity because, considering the Settings Catalog, there are now three different ways to deploy BitLocker from Intune.
I wanted to understand the advantages of using the Settings Catalog compared to the already available methods. Here’s my experience!
⚠️ As mentioned in the video: the settings you see were done for purely educational and illustrative purposes.
All my posts
Azure Virtual Desktop: Single Sign-On su Azure AD
It took me a while to make this video, but finally, here I am: Azure Virtual Desktop Single Sign-On to Azure AD.
One of the main “criticisms” always directed at AVD is the double authentication, which many consider a hassle. With Single Sign-On, the process becomes smoother, and the required authentications decrease.
Could I have just shown you the simple SSO?
Clearly NO, so I even included a FIDO2 security key in it!
All my posts
Temporary Access Pass in Azure AD
📺 New video: Today I’ll tell you about Temporary Access Pass in Azure AD and how it can be useful in specific situations.
☑️ Onboarding a user to register a passwordless authentication method ☑️ Recovery of a lost or unusable passwordless access ☑️ Initialization of a Windows Autopilot device ☑️ Joining a device to Azure AD ☑️ Initial setup of Windows Hello for Business All the details in the video!
Category: Modern Endpoint
All my posts
Introducing the Microsoft Mac Admins Community!
Here’s the news we love on Mondays! 😍 Introducing the Microsoft Mac Admins Community, a new online community for IT professionals passionate about using Microsoft products on Apple Mac devices within enterprises!
Here’s a direct quote:
“This community is a place where Mac administrators working with Microsoft 365 or Intune management for Mac can connect with other users, share experiences and best practices, learn from experts and colleagues, get help with common issues, and draw inspiration from the latest innovations.
All my posts
Intune Organizational Messages in General Availability
Intune Organizational Messages are coming to Intune (GA as of 31/5)! Organizing a communication campaign towards users for urgent updates or the release of new configurations that impact the user experience will now be easier.
Here are the key licensing and requirements details.
📌 Licenses
Microsoft 365 E3 Microsoft 365 E5 Windows 10/11 Enterprise E3 with Microsoft Intune Plan 1 Windows 10/11 Enterprise E5 with Microsoft Intune Plan 1 📌 Operating Systems
All my posts
Intune Account Protection: Local user group membership
IT specialists, hello everyone! In this video, we will see the tools that Azure AD and Intune provide us with to manage local group membership.
Video You can find the entire video below, or you can continue reading the article.
Article After playing with the new Windows LAPS in my previous video, I was reviewing the list of local administrators on my lab machine, and since the machine is registered in Azure AD Join, the Azure AD user who joined it has become an administrator.
All my posts
Windows LAPS in Azure AD (preview)
I have tried the new Windows LAPS (Local Administrator Password Solution) with direct support for Azure AD.
If you have Windows 11 machines (which natively support it), it is really simple and fast to implement.
Here are some useful information:
📌 No licensing requirement, available from Azure AD Free and above
📌 Supported operating systems:
Windows 11 22H2 - April 11, 2023 Update Windows 11 21H2 - April 11, 2023 Update Windows 10 20H2, 21H2, and 22H2 - April 11, 2023 Update Windows Server 2022 - April 11, 2023 Update Windows Server 2019 - April 11, 2023 Update In the video, besides configuring the Intune profile to re-enable the built-in local Administrator, I also tested a slightly more specific scenario by renaming the Administrator.
All my posts
Video of the Tech Bits Event: Modern Endpoint Management is Available
On March 22, 2023, the Microsys event “Tech Bits: Modern Endpoint Management” took place, and now the video of the event is available!
Together with the legendary Paolo Bodini, we presented the 10 key elements to consider for modern management of corporate and personal devices.
Enjoy watching!
Riccardo
All my posts
Configuring BitLocker via Intune using the Settings Catalog
A few days ago, I came across a very interesting article from the Intune Customer Success Team. The article discusses how to configure BitLocker through the Intune Settings Catalog. This piqued my curiosity because, considering the Settings Catalog, there are now three different ways to deploy BitLocker from Intune.
I wanted to understand the advantages of using the Settings Catalog compared to the already available methods. Here’s my experience!
⚠️ As mentioned in the video: the settings you see were done for purely educational and illustrative purposes.
All my posts
Native macOS Update Management Arrives in Intune
This news was from the end of January, but amidst the chaos of activities and news, I can finally share it now: native management of macOS updates in Intune!
Prior to this functionality, managing updates for Macs enrolled in Intune was not very straightforward: scripts, third-party solutions, or user self-service management were required.
With this new set of features, it will be possible to natively manage the following types of updates from the Intune interface:
Category: Digressions
All my posts
Trying Out a Vlog Setup!
I have plans to introduce a different type of video, in addition to the usual tutorials, in the future. Yesterday, I tested the “vlog setup” for the first time.
First impressions: excellent image quality (I had no doubts with this Sony camera), the grip is great and doubles as a remote control, and the Falcam quick release is very convenient.
Things to assess: audio quality, as I’m using the built-in microphone, and stabilization.
Category: Miscellaneous
All my posts
Automatic Expiration of Microsoft Teams Meeting Recordings
How many times have you been asked to record a meeting because “you never know” or because “I want to review it later”? 🙋🏻♂️ Well, 99% of the recordings in Microsoft Teams are never viewed within 60 days after the meeting. It’s a waste of space and, potentially, a security issue if the recording contains sensitive information that is consciously or inadvertently shared.
Finally, the ability to set an expiration date for recorded videos has been introduced!