ENTRA

Entra Connect Sync 2.5.76 released

Entra Connect Sync 2.5.76 released

Andres Bohren
Hi All, Just a few days ago, Microsoft has released a new Version of Entra Connect Sync. It’s only downloadable via the Microsoft Entra Admin Center Microsoft Entra Connect: Version release history There is also a new Article (or at least new to me) about the diffrent Stages for Identity Cloud transformation Cloud transformation posture Download Download is only availabel in Entra Admin Portal and is now not as hidden anymore
Entra Connect Sync 2.5.3 released

Entra Connect Sync 2.5.3 released

Andres Bohren
Hi All, Just a few days ago, Microsoft has released a new Version of Entra Connect Sync. It’s only downloadable via the Microsoft Entra Admin Center Microsoft Entra Connect: Version release history It’s really hidden: Entra Admin Center > Identity > Hybrid Management > Microsoft Entra Connect > Get started > Manage > Download Connect Sync Agent If you click on the Download Link you have to click on the “Accept terms & download” Button.
The diffrence between Managed and Federated Domain

The diffrence between Managed and Federated Domain

Andres Bohren
Hi All, In Entra Id there are fundamentally three diffrent Identity Models Cloud Identity (Cloud Only Accounts) Syncronized Identity / Hybrid Identity (Syncronized with Entra Connect Sync or Cloud Sync from OnPrem Active Directory with password sync) Federated Identity (Like Syncronized Identity but without password sync - Authentication happens on the Federation Server and requrires a Trust between Entra and the Federation Service) Image Source: Choosing a sign-in model for Office 365
Updated Conditional Access HTML Export Script

Updated Conditional Access HTML Export Script

Andres Bohren
Hi All, I’ve released an updated Version of my Conditional Access HTML Export PowerShell Script on my GitHub Repo. It’s always a Pain to document Conditional Access Policies. So i’ve forked and modified the Script from https://github.com/dougsbaker/CA-Export to match my needs. Recently i saw the new “Network” Section in the Conditional Access Policies. I Like when the Sections match the HTML Output Users Target resources Network Conditions Grant Session The Script requires the Microsoft.
Entra Connect Sync 2.4.131 released

Entra Connect Sync 2.4.131 released

Andres Bohren
Hi All, From time to time i check, if there is a new Version of Microsoft Entra Connect Sync available. Microsoft Entra Connect: Version release history Just a few days ago, the Version 2.4.131.0 has been released for Auto upgrade. Let’s check the Auto Upgrade Settings Get-ADSyncAutoUpgrade -Detail Let’s check the Version of Entra Connect Sync (Get-Item "C:\Program Files\Microsoft Azure AD Sync\Bin\miiserver.exe").VersionInfo The Version can also found in Entra Admin Center
Set Entra Application Tags with PowerShell

Set Entra Application Tags with PowerShell

Andres Bohren
Hi All, A few Weeks ago, i wrote a PowerShell Script and an Azure Runbook to report expiring Clientsecrets and Certificates. With the Runbook, the Owners woul even receive an Email bevore the expiry date. Depending on the Permissions of the Application, beeing Owner could add a Path for Privilege Escalation. So i was looking for another Way of storing the Information who is responsable of the App. Tags If you look at the Manifest of an App, there is a String Array Property called Tags
Check for retiring OneNote App Permission in Entra

Check for retiring OneNote App Permission in Entra

Andres Bohren
Hi All, With the MC1011142 Message Center Post, Microsoft has announced the retirement of App Permissions for OneNote: Effective March 31, 2025, we will retire support for authentication tokens with application permissions (app-only tokens) for MSGraph OneNote APIs. We will continue to support authentication tokens that have delegated permissions. While app-only tokens are easy to use, they may be more easily exploited compared to more sophisticated authorization methods. Requests to the Notes API endpoints using tokens with application permissions will return 401 unauthorized errors starting March 31, 2025.
Entra Connect Sync from multiple AD Forests

Entra Connect Sync from multiple AD Forests

Andres Bohren
Hi All, I’ve added a second Active Directory Forest in my Entra Connect Sync in my Lab. Compliant to the supported Entra Connect Sync topologies. Multiple forests, single Microsoft Entra tenant It’s already a few Months ago, since i’ve configured this and created the Screenshots. Since then Azure AD Connect has been Rebranded to Entra Connect Sync, got updated Icons - but the Process remains the same. Architecture This Article describes, how to add an additional Active Forest to an existing Entra Connect Sync Infrastructure to sync to a common Entra ID Tenant.
Report Microsoft Authenticator Registration in Entra ID with Graph PowerShell

Report Microsoft Authenticator Registration in Entra ID with Graph PowerShell

Andres Bohren
Hi All, I am working with a customer on a M365 Onboarding. Bevore migrating Users to the Cloud, we want to make sure the Onboarding of the Microsoft Authenticator App is successful. I was tasked to figure out a way to find out the Users that have registered the Microsoft Authenticator App for MFA Authentication. Enduser Portal From a User Perspective you can see in the Security Information that there are registered two Microsoft Authenticators.
Entra Connect Sync 2.4.129 released

Entra Connect Sync 2.4.129 released

Andres Bohren
Hi All, By coincidence I’ve stumbled across the Entra Connect Sync Update 2.4.129. It’s released for Auto Upgrade. I am running currently Entra Connect Sync 2.4.27.0 Microsoft Entra Connect: Version release history If it has been released at 01/15/2025 then it’s over three weeks - enough time for the Auto Upgrade to kick in i guess. Microsoft Entra Connect: Automatic upgrade Auto Upgrade is enabled and no SuspensionReason has been set.