All my posts
Free eBook: Azure Defenses for Ransomware Attacks
📢 Free-resource-friday! Azure Defenses for Ransomware Attacks. Today, I’ve gathered for you a highly informative (and free) eBook that discusses the tools available in Azure to counter a Ransomware attack. Almost mandatory reading in these times!
📌 Bonus tip: Don’t miss the plethora of links to documents and resources in the “Additional Resources” slide!
📖 Here’s where you can download it:
➡️ Azure Defenses for Ransomware Attacks
Your IT Specialist, Riccardo
All my posts
Microsoft Entra ID Protection: what is Risk in Entra ID?
In a Zero Trust Security approach, where identity is a fundamental element, the security of authentications can be measured to some extent based on the so-called “signals.” Analyzing these signals provides a level of “risk” for a particular user when authenticating to Microsoft 365 services. Today, I’ll tell you about Mirosoft Entra Identity Protection and what the concept of “risk” means.
As always, before diving headfirst into this “risky” journey (pun intended 🤣), we need to introduce another concept: you need to understand what signals are.
All my posts
What's New in Conditional Access: Templates and a New Overview Available
Fresh news in the Microsoft Entra ID realm: templates and a brand new overview are now publicly available. Let’s start with the templates.
Template Conditional Access policies are a powerful tool that offers a high degree of customization and granularity. That’s why it can sometimes be less intuitive to know where to begin when it comes to implementing a particular policy for a specific situation.
The availability of templates helps in this regard by providing ready-to-use tools for specific situations, making it easier to implement a conditional access criterion.
All my posts
The Lab Series: Installing Azure AD Application Proxy
As anticipated a few days ago, today we begin a series of short video clips, lasting no more than a couple of minutes, where I demonstrate activities and procedures that most people take for granted but, for various reasons, may not be so straightforward.
Welcome to “The Lab Series”!
Today, we have a quick-and-dirty procedure for installing the Azure AD Application Proxy connector.
Useful documentation for further reference:
📄 Tutorial: Add an on-premises application for remote access through Application Proxy in Azure Active Directory
All my posts
FIDO2 Key Authentication demo in Microsoft 365 on Safari iOS
🎥💊 Video Pill News: FIDO2 key support on Safari iOS!
The key used in this video is a FEITIAN, iePass K44 model, with dual interfaces: USB-C and Lightning.
I hope that FIDO2 key support arrives soon for Microsoft apps on iOS!
Riccardo
All my posts
Implementing LDAPS in Active Directory on-premises
Every forest and Active Directory domain should have LDAPS implemented, but in very few cases is it actually implemented. The topic can be intimidating because it involves certificates, but once you understand some basic concepts, it’s easier to tame than it seems. Let’s see how to implement it!
Video You can find the entire video below, or you can continue reading the article.
Article With all this talk about the cloud, I realized that I have neglected our beloved Active Directory!
All my posts
macOS Single Sign-On on Azure AD
About 2 years ago (June 2021), I had fun experimenting with a new feature that was in preview: macOS Single Sign-On (SSO) for Azure AD on Microsoft 365 applications and services.
⚠️ Update as of June 1, 2023 The “Microsoft Azure AD” plug-in is finally in General Availability and is ready to use in production environments!
You might be wondering, “What on earth is it for?”
This feature allows you to authenticate yourself and your fantastic Mac more easily to Microsoft 365 services and applications without repeated credential prompts, making the user experience even smoother and seamless.
All my posts
Convert ObjectID to SID in Azure AD and vice versa
Friday resource! If you’re tinkering with Local Groups Membership policies in Intune and (like me) have cursed a bit while converting group/role ObjectIDs to SIDs and vice versa, here’s a website that does it online instantly and conveniently.
🔹 ObjectId ➡️ SID
🔹 SID ➡️ ObjectId
I’d love to tag the author of this wonderful utility (Erik Engberg) here, but from what I’ve seen, they’re not on LinkedIn. If I’m mistaken and someone knows their exact profile, please let me know so I can give them proper thanks.
All my posts
Windows Hello for Business is the MFA for Windows login!
Why Windows Hello for Business is the Multi-Factor Authentication for Windows login and how to configure it via Intune in Azure AD Kerberos Cloud Trust mode, through the Settings Catalog.
Below is the documentation I refer to in the video:
📄 Windows Hello for Business Overview 📄 How Windows Hello for Business works in Windows Devices 📄 Windows Hello for Business and Authentication 📄 Cloud Kerberos trust deployment 📄 Enable passwordless security key sign-in to on-premises resources by using Azure AD Have you implemented Windows Hello for Business?
All my posts
Configuring BitLocker via Intune using the Settings Catalog
A few days ago, I came across a very interesting article from the Intune Customer Success Team. The article discusses how to configure BitLocker through the Intune Settings Catalog. This piqued my curiosity because, considering the Settings Catalog, there are now three different ways to deploy BitLocker from Intune.
I wanted to understand the advantages of using the Settings Catalog compared to the already available methods. Here’s my experience!
⚠️ As mentioned in the video: the settings you see were done for purely educational and illustrative purposes.
All my posts
Azure Virtual Desktop: Single Sign-On su Azure AD
It took me a while to make this video, but finally, here I am: Azure Virtual Desktop Single Sign-On to Azure AD.
One of the main “criticisms” always directed at AVD is the double authentication, which many consider a hassle. With Single Sign-On, the process becomes smoother, and the required authentications decrease.
Could I have just shown you the simple SSO?
Clearly NO, so I even included a FIDO2 security key in it!
All my posts
Temporary Access Pass in Azure AD
📺 New video: Today I’ll tell you about Temporary Access Pass in Azure AD and how it can be useful in specific situations.
☑️ Onboarding a user to register a passwordless authentication method ☑️ Recovery of a lost or unusable passwordless access ☑️ Initialization of a Windows Autopilot device ☑️ Joining a device to Azure AD ☑️ Initial setup of Windows Hello for Business All the details in the video!