🚨 Entra ID External MFA (old name was External Authentication Methods) is now Generally Available.

Custom Controls is being deprecated on 30 Sept 2026.

Here's how to check your usage.

https://thedxt.ca/2026/03/microsoft-entra-id-external-mfa/

#Entra #MFA #M365 #Microsoft #Microsoft365 #ConditionalAccess

Microsoft Entra ID External MFA

Microsoft recently announced that External Authentication Methods has been renamed to External MFA and is Generally Available. Microsoft also announced that Custom Controls is being deprecated, with its deprecation currently planned for September 30th, 2026. Microsoft Entra ID External MFA (formerly External Authentication Methods) replaces Custom Controls. Here is a brief timeline of Custom... Read More Read More

theDXT

Azure DevOps is moving some auth flows to Entra token issuance this summer, so token payloads will stop being readable by clients.

The exact mechanism isn’t specified (JWE would be my guess), but anything decoding tokens to read claims like UPN or tenant ID will break — no graceful degradation.

Most likely to hit internal tooling and scripts, but worth a check either way.

Supported path: Azure DevOps REST APIs for user and org data.

https://devblogs.microsoft.com/devops/authentication-tokens-are-not-a-data-contract/

#AzureDevOps #DevOps #Entra

Authentication Tokens Are Not a Data Contract - Azure DevOps Blog

Authentication tokens exist to answer one question: is this caller authorized to do this? They are not intended to be a stable data interface, a schema you can depend on, or an input into application logic. If your application decodes tokens and reads claims from them, this is an important heads-up. Token Claims Were Never […]

Azure DevOps Blog
Mientras la erradicación contra Irán entra en su segundo mes, los hutíes de Yemen abren un nuevo frente | Aniquilamiento entre Estados Unidos e Israel contra Irán Parte – ButterWord

The Yemeni group pledges more attacks on Israel as fears mount that the worsening conflict will spiral out of control.

ButterWord
Trying to set up an alert policy in Microsoft 365 Business Premium for Entra ID admin role assignments ("Added member to role"). Can't find this activity in the new Defender portal alert policies, only seeing Exchange/threat management activities. Any clue ? #entra #security #Microsoft365

I hope this doesn't get me labeled as an "AI Bro". But I made a thing with Claude, and figured I'd write about it. Really, I just wanted to play with Claude and see the hype. Check it out, open to suggestions:

https://joeloveless.com/blog/introducing-endpointfeed.com/

#intune #configmgr #entra #apple #windows #avd

Introducing EndpointFeed.com | Joe Loveless

A new website built with Claude Code to aggregate endpoint community RSS feeds.

Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys

Microsoft is rolling out passkey support for Microsoft Entra on Windows devices, adding phishing-resistant passwordless authentication via Windows Hello.

BleepingComputer

Waar begin je als organisatie met #digitalesouvereiniteit. En dan m.n. hoe maak je je onafhankelijker van het Hotel California van #Microsoft. Velen denken aan kleine, makkelijke applicaties, laaghangend fruit etc.
Langzaam begin ik echter te zien: Richt je op het vermijden/verlaten van #Entra ID als #IdentityProvider.
Wanneer je daar een andere oplossing voor hebt, kan je SSO methodiek volgen. Daarna is het maken van keuzes mbt alle andere applicaties in je netwerk bijna triviaal.

#idp

Invite Guest users in a Entra ID Multi-tenant setup

This post looks at implementing a guest user invite in a cross tenant setup. This is useful when creating partner tenants using an Entra ID MAU license for all partner guests and members. This make…

Software Engineering

🥩🥩Mr T-Bone tip!🥩🥩[New from Tech Community]
Unlock the future of identity with self-service account recovery in Microsoft Entra! No more helpdesk waits—take control! 🚀🔐

#MVPBuzz #Security #MicrosoftTechCommunity #Identity #Entra
👉👉 https://tip.tbone.se/9s1WnB
[AI generated, Human reviewed]

OAuth redirection abuse enables phishing and malware delivery - RedPacket Security

Microsoft observed phishing-led exploitation of OAuth’s by-design redirection mechanisms. The activity targets government and public-sector organizations and

RedPacket Security