Recent Posts
Should ‘Do not allow user consent’ be the new Microsoft recommendation to tackle Malicious OAuth apps?
March 25, 2025 •Sander Berkouwer
Integrating applications, services and systems with Microsoft Entra ID brings organizations many benefits. People who need apps for their...
Read MoreUpdate Your OneNote API Permissions Before March 31, 2025, to Prevent Outages
February 27, 2025 •Sander Berkouwer
Microsoft plans to disable OneNote’s app-only permissions to improve security to its advanced note-taking app. When your Entra apps rely on this...
Read MoreEntra ID Application Credential Challenges - Have they been Solved with Managed Identities as Federated Identity Credentials?
December 27, 2024 •Sander Berkouwer
In the days of Azure Active Directory (Azure AD), applications could authenticate to back-end services using a secret or a certificate. This past...
Read MoreBlack Hat Sessions Highlight Key Challenges in Microsoft Cloud Security
September 11, 2024 •Sander Berkouwer
If you kept up with Microsoft vulnerabilitiesthis past month, there were quite a few to read up on. In addition to these and general industry news, ...
Read MoreSix Considerations Identity Admins Should Be Aware of Around Scripting
March 12, 2024 •Sander Berkouwer
*NOTE: This article was originally published on Thursday, 2/29/24. After receiving feedback from the MVP Community, we decided to unpublish on...
Read MoreAfter Attackers Force Their Way in - They Stay in Through Malicious Entra ID Apps
December 13, 2023 •Sander Berkouwer
Before Multi-Factor Authentication (MFA) existed, user credentials were cracked, stolen, intercepted, eavesdropped upon or phished. Valid user...
Read More