Entra.Chat

Merill Fernando
Entra.Chat
Último episodio

55 episodios

  • Entra.Chat

    5 Entra ID Updates You Can’t Afford to Ignore in 2026 (Backup, Governance, CA Agent & Risk Score Exposed)

    04/04/2026 | 1 h
    Microsoft just dropped a massive wave of features for Entra, and the rules of Tenant Governance have officially changed.
    Join us as we talk to three world-class MVPs about their hands-on experience with the new Entra Backup and Recovery and Tenant Governance features.
    Our Microsoft MVP guests Nathan McNulty, Ru Campbell, and Thomas Naunheim break down the most exciting new features in Microsoft Entra.
    In this episode, we explore:
    * The “Shadow Tenant” Problem: One org found 700+ Entra tenants they didn’t know they had.
    * Version Control for Admins: Why “Difference Reports” are a total game-changer for troubleshooting.
    * Recovery Safeguards: How to protect your tenant from accidental deletions and “sneaky” background changes.
    * Backup & Recovery: The truth about Entra Backup vs. Third-Party ISV tools.

    Subscribe with your favorite podcast player or watch on YouTube 👇

    About The Guests
    Nathan, Ru, and Thomas are highly experienced MVPs specializing in identity security, governance, and Microsoft Entra.
    Nathan McNulty - LinkedIn - https://www.linkedin.com/in/nathanmcnulty/
    Ru Campbell - LinkedIn - https://www.linkedin.com/in/rlcam/
    Thomas Naunheim LinkedIn - https://www.linkedin.com/in/thomasnaunheim/
    🔗 Related Links
    * Microsoft Entra Backup and Recovery Documentation - https://learn.microsoft.com/en-us/entra/backup/overview
    * Microsoft Entra Tenant Governance - https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview
    * Synced Passkeys - https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-passkeys-fido2
    * Microsoft Work IQ CLI (Public Preview) - https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/workiq-overview
    * Playwright https://playwright.dev/
    * Entra Auth Tracer (Chrome Extension) - https://github.com/darrenjrobinson/EntraAuthTracer
    * Unified Risk Score - https://learn.microsoft.com/en-us/defender-xdr/investigate-users#risk-score-tab-preview
    📗 Chapters
    00:00 Intro to New Entra Features
    02:04 Entra Backup and Recovery Deep Dive
    10:41 Difference Reports Explained
    15:54 Intro to Tenant Governance
    23:34 Managing Multi-Tenant Organizations
    33:31 Conditional Access Optimization Agent
    36:55 The Great Passkey Debate
    47:22 Retirements: SP-less Auth & ACS for SharePoint
    48:46 Unified Risk Score in Defender
    52:38 MVP Tips of the Week
    Podcast Apps
    🎙️ Entra.Chat - https://entra.chat
    🎧 Apple Podcast → https://entra.chat/apple
    📺 YouTube → https://entra.chat/youtube
    📺 Spotify → https://entra.chat/spotify
    🎧 Overcast → https://entra.chat/overcast
    🎧 Pocketcast → https://entra.chat/pocketcast
    🎧 Others → https://entra.chat/rss
    Merill’s socials
    📺 YouTube → youtube.com/@merillx
    👔 LinkedIn → linkedin.com/in/merill
    🐤 Twitter → twitter.com/merill
    🕺 TikTok → tiktok.com/@merillf
    🦋 Bluesky → bsky.app/profile/merill.net
    🐘 Mastodon → infosec.exchange/@merill
    🧵 Threads → threads.net/@merillf
    🤖 GitHub → github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    Finding Every MFA Gap: Testing 250 Million Conditional Access Combinations in Under 20 Minutes

    28/03/2026 | 1 h 1 min
    Emilien Socchi, Cloud Security Research Engineer at Storebrand, joins us to discuss CA Insight and AZTier.
    Two open-source tools Emilien built to find gaps in Conditional Access policies and categorize Azure/Entra roles based on attack paths.
    Learn how CA Insight evaluates 250 million sign-in combinations offline in minutes instead of days, why the What If API doesn't scale, and how AZTier helps defenders and pen testers understand privilege escalation risks across Entra ID, Azure, and Microsoft Graph.
    Together, these projects help security teams move from reactive log monitoring to a proactive defense strategy.
    What’s Breaking and Slowing Your Entra ID Environment?
    In Microsoft Entra ID, the same visibility gaps cause two problems:
    * Things break
    * Work slows down
    Expired client secrets disrupt integrations. Certificates lapse and authentication fails. New apps appear with excessive permissions and no clear ownership. At the same time, teams struggle to answer basic questions, which applications have access to Microsoft 365 data, whether that access is still required, and who is responsible for it.
    When answers are not immediate, reviews stall and projects slow down.
    ENow App Governance Accelerator Credential Guard helps identify expiring credentials and expose permission and ownership gaps.
    For organizations under 10,000 users, pricing ranges from $3,500 to $9,500 annually through March 31, 2026.
    Subscribe with your favorite podcast player or watch on YouTube 👇
    About Emilien Socchi
    Emilien Socchi is a Cloud Security Research Engineer at Storebrand (Oslo, Norway) focusing on the proactive discovery of security issues. With an extensive background in application and cloud penetration testing, Emilien has published practical research and tooling used by defenders. He also maintains several open‑source projects, including Azure administrative tiering models and Entra ID role‑monitoring utilities.
    LinkedIn - https://www.linkedin.com/in/emilien-socchi
    🔗 Related Links
    * CA Insight- https://github.com/emiliensocchi/entra-ca-insight
    * Azure Administrative Tiering (AzTier) - https://aztier.com
    * AzTier Source: https://github.com/emiliensocchi/azure-tiering
    * AzTier Deployer - https://github.com/emiliensocchi/aztier-deployer
    📗 Chapters
    00:00 The Story Behind CA Insights
    16:52 Why the ‘What If’ API Doesn’t Scale
    21:09 Building an Offline Evaluation Engine
    45:22 Deep Dive into AZTier: A Red Team Perspective
    Podcast Apps
    🎙️ Entra.Chat - https://entra.chat
    🎧 Apple Podcast → https://entra.chat/apple
    📺 YouTube → https://entra.chat/youtube
    📺 Spotify → https://entra.chat/spotify
    🎧 Overcast → https://entra.chat/overcast
    🎧 Pocketcast → https://entra.chat/pocketcast
    🎧 Others → https://entra.chat/rss
    Merill’s socials
    📺 YouTube → youtube.com/@merillx
    👔 LinkedIn → linkedin.com/in/merill
    🐤 Twitter → twitter.com/merill
    🕺 TikTok → tiktok.com/@merillf
    🦋 Bluesky → bsky.app/profile/merill.net
    🐘 Mastodon → infosec.exchange/@merill
    🧵 Threads → threads.net/@merillf
    🤖 GitHub → github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    From FIM/MIM to Cloud Sync: Complete Identity Journey with Australia’s Top Identity MVP Darren “Doc” Robinson

    21/03/2026 | 55 min
    Darren Robinson, Identity and Zero Trust Strategy and Architecture Capability Lead at Increment, shares his extensive experience in identity governance and administration.
    In this episode Merill sits down with Darren “Doc” Robinson – Microsoft MVP since 2017, former SailPoint Ambassador and one of Australia’s most experienced identity architects.
    Darren takes us on a 25+ year journey from Novell networks to modern Microsoft Entra ID, reveals why he’s building custom ECMA2 connectors, and shares the exact PowerShell tools he just open-sourced (Granfeldt uplift, ECMA2 Host Tools, Provision On-Demand module).
    We also compare Entra ID Governance vs SailPoint and dive into his latest obsession: MCPs for Entra News and personal AI agents.
    Whether you’re migrating legacy apps or levelling up your IGA strategy, this episode is pure gold.
    Sponsored by CoreView:
    Would you bet your reputation on your current Microsoft 365 security posture?
    Sure, you’ve checked Purview. Maybe tightened Conditional Access. We all do that.
    But it’s usually the quiet stuff that bites... permissions that expanded, policies that drifted, exceptions nobody revisited.
    You could assume it’s fine.
    Or you could run the Microsoft 365 Security Posture Check.
    It’s free.
    It runs locally.
    And no, it doesn’t send your tenant data back to us.
    We’ll even help you set it up.
    Subscribe with your favorite podcast player or watch on YouTube 👇

    About Darren Robinson
    Darren is highly accomplished in digital identity and cybersecurity specialising in Identity & Access Management for over three decades. Darren is renowned for driving Digital Identity innovation, building global offerings, and leading high-impact teams to deliver cutting-edge solutions that enhance security posture, operational efficiency, and business value.
    🔗 Related Links
    * Blog: https://blog.darrenjrobinson.com
    * GitHub: https://github.com/darrenjrobinson
    * LinkedIn: https://www.linkedin.com/in/darrenjrobinson/
    In this episode…
    1. Understanding the “Metaverse”
    The foundation of Microsoft’s identity strategy dates back to the acquisition of Zoomit in 2000. This introduced the Metaverse—not a VR world, but a “hologram” or central representation of a user that exists across multiple systems like SQL databases and LDAP directories. By correlating these identities into one object, organizations can maintain consistency across a fragmented environment.
    2. The Modern Bridge: ECMA and SCIM
    As organizations move to the cloud, the “heavy” sync engines like MIM (Microsoft Identity Manager) are being replaced by Entra Cloud Sync. The modern approach uses:
    * A Light Shim: A small on-premises component that acts as a member of the domain.
    * SCIM Instructions: The Entra provisioning service sends instructions via the SCIM protocol to this shim.
    * ECMA Connectors: The Extensible Connector Management Agent (ECMA) translates these cloud instructions into a language legacy on-prem apps can understand, such as SQL or Oracle updates.
    3. Scaling with PowerShell 7
    One of the biggest hurdles in legacy identity management was performance. Darren Robinson recently uplifted the popular Granfeldt PowerShell Management Agent to support PowerShell 7. This update allows for:
    * 64-bit Processing: Handling larger datasets with ease.
    * Parallelism: Sending multiple identity updates in parallel rather than waiting for individual “gets,” significantly speeding up sync times.
    4. Managing the “Cache”
    A common pain point for administrators is the lack of visibility into the ECMA host cache. To solve this, Darren developed a new module that allows practitioners to programmatically query the cache, back up configurations, and document every connector and parameter in the system.
    Key Takeaway: Whether you are migrating from legacy solutions like Novell or managing a complex hybrid Entra environment, the goal remains the same: automated, secure, and visible identity lifecycles.
    📗 Chapters
    00:00 Intro
    02:22 The Evolution of Directory Services and Synchronization
    08:05 Understanding Sync Engines and the Metaverse
    14:45 Modern Identity Provisioning with Entra
    17:39 Developing Custom PowerShell ECMA Connectors
    20:53 Automating Provisioning with New PowerShell Modules
    28:53 The Current Landscape of Identity Governance
    31:37 Solving the Disconnected Apps Challenge
    35:46 Exploring Model Context Protocol (MCP)
    45:34 Leveraging Local AI and LLMs for Identity Tasks
    Podcast Apps
    🎙️ Entra.Chat - https://entra.chat
    🎧 Apple Podcast → https://entra.chat/apple
    📺 YouTube → https://entra.chat/youtube
    📺 Spotify → https://entra.chat/spotify
    🎧 Overcast → https://entra.chat/overcast
    🎧 Pocketcast → https://entra.chat/pocketcast
    🎧 Others → https://entra.chat/rss
    Merill’s socials
    📺 YouTube → youtube.com/@merillx
    👔 LinkedIn → linkedin.com/in/merill
    🐤 Twitter → twitter.com/merill
    🕺 TikTok → tiktok.com/@merillf
    🦋 Bluesky → bsky.app/profile/merill.net
    🐘 Mastodon → infosec.exchange/@merill
    🧵 Threads → threads.net/@merillf
    🤖 GitHub → github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    How to Migrate from Legacy VPNs to Entra Private Access (Real Strategies from a Veteran)

    14/03/2026 | 42 min
    Richard Hicks wrote the book on DirectAccess. Then he wrote the one on Always On VPN. Now he’s here to tell you it’s time to move on from both (and other legacy VPNs). Over the last two years, Richard has helped numerous enterprise customers navigate the shift from legacy VPN to Microsoft Entra Private Access, and he’s collected some hard-learnt lessons along the way that most migration guides won’t tell you.
    In this episode, Richard - enterprise security consultant and early Entra Private Access insider - breaks down why traditional VPN is fundamentally broken for today’s threat landscape, how Entra Private Access works under the hood, and the exact crawl-walk-run playbook he uses to migrate enterprise customers without disruption. Plus: his hot take on the Microsoft E7 announcement and why it just changed the pricing conversation forever.
    In this episode you’ll learn:
    * Why your VPN tunnel is a security liability — and how a single compromised device can expose your entire corporate network
    * How Entra Private Access works differently to traditional VPN, and why that architectural shift matters for security
    * The “Quick Access” migration strategy that lets you get off legacy VPN fast, without locking everything down on day one
    * How to deploy the Global Secure Access client alongside your existing VPN — so you can migrate field-based workers without a single disconnection
    * What most teams get wrong about the Entra Private Network Connector — and the scaling pitfalls that catch enterprises off guard
    * Why Conditional Access knowledge, not connectivity, is the real key to a successful zero trust migration
    * The current limitations of Entra Private Access and how to plan around them
    * We also discuss the new ‘E7’ which includes Entra Private Access
    Subscribe with your favorite podcast player or watch on YouTube 👇

    About Richard Hicks
    Richard Hicks is the founder and principal consultant at Richard M. Hicks Consulting, Inc. A Microsoft Most Valuable Professional (MVP) with more than 30 years of experience implementing secure remote access and public key infrastructure (PKI) solutions, he is a widely recognized enterprise mobility and security infrastructure expert sought after by organizations worldwide. His mission is to help companies provide visibility, control, and assurance for their field-based users and devices, ensuring the highest level of security and productivity for today’s highly mobile workforce.
    LinkedIn - https://www.linkedin.com/in/richardhicks/
    🔗 Related Links
    * Richard’s Blog - https://directaccess.richardhicks.com/
    * Richard M. Hicks Consulting, Inc - https://www.richardhicks.com/
    * https://directaccess.richardhicks.com/always-on-vpn-vs-entra-private-access/
    📗 Chapters
    00:00 Intro
    01:10 The History of Direct Access and Always On VPN
    05:59 Transitioning to Zero Trust and Entra Private Access
    11:34 Seamless Side-by-Side VPN Migration
    17:37 Using Quick Access to Kickstart Zero Trust
    23:43 Changing Mindsets: Identity over IP Addresses
    27:55 The New Zero Trust Network Assessment Tool
    29:17 Avoiding Pitfalls with the Entra Private Network Connector
    33:11 Feature Wishlist: IPv6 and Process Binding
    38:46 Hot Takes on the New Entra E7 Suite
    Podcast Apps
    🎙️ Entra.Chat - https://entra.chat
    🎧 Apple Podcast → https://entra.chat/apple
    📺 YouTube → https://entra.chat/youtube
    📺 Spotify → https://entra.chat/spotify
    🎧 Overcast → https://entra.chat/overcast
    🎧 Pocketcast → https://entra.chat/pocketcast
    🎧 Others → https://entra.chat/rss
    Merill’s socials
    📺 YouTube → youtube.com/@merillx
    👔 LinkedIn → linkedin.com/in/merill
    🐤 Twitter → twitter.com/merill
    🕺 TikTok → tiktok.com/@merillf
    🦋 Bluesky → bsky.app/profile/merill.net
    🐘 Mastodon → infosec.exchange/@merill
    🧵 Threads → threads.net/@merillf
    🤖 GitHub → github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    Passkeys, Conditional Access, Hard-match updates, GSA BYOD: What Entra Admins Need To Know

    07/03/2026 | 1 h 9 min
    I am back home in Melbourne today, and joining me are Nathan McNulty from Alaska and Daniel Bradley from the UK as we dive into all the massive Entra updates that dropped last month. We are breaking down the controversial shift to syncable passkeys , why your Conditional Access policies might suddenly start blocking apps , and the absolute necessity of moving privileged accounts away from on-prem AD. We’re also geeking out over some incredible new Global Secure Access (GSA) features and how AI is completely transforming the way we work with Graph API. You won’t want to miss the under-the-radar changes that could impact your tenant’s security architecture overnight.
    Here’s a quick overview of all the topics we covered in this episode (links below).
    Sponsored by:
    Scan, Score, and Secure Your Applications in Entra
    Application identities represent one of the largest attack surfaces in Entra and are often among the least consistently governed. AppGov Score helps IT and Security teams understand where risk exists. The 24-check assessment evaluates Entra ID application integrations against Microsoft-recommended governance practices, analyzing:
    * App registrations and enterprise apps for excessive permissions
    * Expired or unmanaged secrets
    * Ownerless apps
    * Risky consent grants, and
    * Privileged service principals
    Results are delivered as a clear, defensible risk score with actionable findings. No scripts. No manual inventory. Just a fast, read-only scan that reveals app sprawl, identity misconfigurations, and blast radius so you can prioritize remediation and strengthen your security posture with confidence.
    Subscribe with your favorite podcast player or watch on YouTube 👇

    About Nathan McNulty
    Senior Security Solutions Architect at Patriot Consulting and Microsoft MVP in security. Nathan is the practice lead for identity and has extensive experience with endpoint deployments and everything Entra.
    LinkedIn - https://www.linkedin.com/in/nathanmcnulty/
    About Daniel Bradley
    Senior Solution Architect for CDW down in the UK and an MVP in Identity Security and M365 for Graph API. Daniel specializes in pre-sales, mergers, acquisitions, and the highly technical migration space.
    LinkedIn - https://www.linkedin.com/in/danielbradley2/
    🔗 Related Links
    * Entra What's New - https://learn.microsoft.com/en-us/entra/fundamentals/whats-new
    * Upcoming Conditional Access change: Improved enforcement for policies with resource exclusions - https://techcommunity.microsoft.com/blog/microsoft-entra-blog/upcoming-conditional-access-change-improved-enforcement-for-policies-with-resour/4488925
    * XDRInternals - https://github.com/MSCloudInternals/XDRInternals
    * Passkey Login - https://github.com/nathanmcnulty/nathanmcnulty/blob/main/Entra/passkeys/PasskeyLogin.ps1
    * Graph PM - https://graph.pm
    📗 Chapters
    03:01 Syncable Passkeys & Registration Changes
    18:10 Conditional Access Policy Updates
    26:35 Blocking Hard Match for Privileged Roles
    35:42 External Authentication Methods GA
    43:04 Lifecycle Workflows & Admin Units
    48:01 Global Secure Access (GSA) BYOD Preview
    53:06 New My Account Portal & Authenticator Updates
    58:43 AI Skills & Automating Graph API
    Podcast Apps
    🎙️ Entra.Chat - https://entra.chat
    🎧 Apple Podcast → https://entra.chat/apple
    📺 YouTube → https://entra.chat/youtube
    📺 Spotify → https://entra.chat/spotify
    🎧 Overcast → https://entra.chat/overcast
    🎧 Pocketcast → https://entra.chat/pocketcast
    🎧 Others → https://entra.chat/rss
    Merill’s socials
    📺 YouTube → youtube.com/@merillx
    👔 LinkedIn → linkedin.com/in/merill
    🐤 Twitter → twitter.com/merill
    🕺 TikTok → tiktok.com/@merillf
    🦋 Bluesky → bsky.app/profile/merill.net
    🐘 Mastodon → infosec.exchange/@merill
    🧵 Threads → threads.net/@merillf
    🤖 GitHub → github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe

Más podcasts de Noticias

Acerca de Entra.Chat

Entra Chat is a weekly podcast hosted by Merill Fernando and delivers practical insights for Microsoft administrators and security professionals through conversations with identity experts who've been in the trenches. Episodes feature seasoned Entra practitioners sharing real-world deployment experiences and Microsoft Entra team members who build the features you use daily. Get the inside track on best practices, implementation strategies, and upcoming capabilities directly from those who design and deploy Microsoft identity solutions. Join us for actionable takeaways you can apply immediately in your Microsoft 365, Azure, and Entra environments. --- Entra.Chat, its content and opinions are my (Merill Fernando) own and do not reflect the views of my employer (Microsoft). All postings are provided “AS IS” with no warranties and is not supported by the author. All trademarks and copyrights belong to their owners and are used for identification only. entra.news
Sitio web del podcast

Escucha Entra.Chat, Herrera en COPE y muchos más podcasts de todo el mundo con la aplicación de radio.es

Descarga la app gratuita: radio.es

  • Añadir radios y podcasts a favoritos
  • Transmisión por Wi-Fi y Bluetooth
  • Carplay & Android Auto compatible
  • Muchas otras funciones de la app
Aplicaciones
Redes sociales
v8.8.6| © 2007-2026 radio.de GmbH
Generated: 4/6/2026 - 1:54:41 PM