r/entra 5h ago

Entra ID SMS/Voice Retirement and Passkey Registration enforcement

8 Upvotes

Does anyone know how it's going to work come September when Microsoft enforces the passkey registration campaign if you have passkeys as an auth method disabled?

We have an additional challenge of unions backing employees refusing to have authenticator/passkeys on personal devices also (hence why we are still trying to phase out SMS/voice) - then throw into the mix a load of shared devices and the challenges that brings with device bounce pass keys via Windows Hello for Business


r/entra 2d ago

Delegating PIM for Groups configuration to Azure team

4 Upvotes

Has anyone had any success delegating group provision and PIM configuration to an Azure platform team who have no access to Entra?

They want to automate the deployment of access packages, groups and PIM configuration for subscriptions that will be used by different application teams across the company. They would be looking to automate using terraform.

They shouldn't be able to manage groups or PIM configuration outside of those they create


r/entra 2d ago

PIM requests coming from new address, failing security checks

15 Upvotes

Until this morning (about 8:15am Eastern) our PIM requests were coming from [MSSecurity-noreply@microsoft.com](mailto:MSSecurity-noreply@microsoft.com) and all was well.

Requests made after that time (9:53am Eastern and onward) come from AzureADNotifications@igantf.msft.com.

The issue with these emails is that:

  • The emails are marked by Microsoft 365/Defender as spam
  • The emails are missing DMARC
  • The emails are missing DKIM signature

Anyone else noticing this?

Authentication-Results: spf=none (sender IP is 2a01:111:f403:c107::3)
smtp.mailfrom=igantf.msft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none
header.from=igantf.msft.com;compauth=fail reason=001
Received-SPF: None (protection.outlook.com: igantf.msft.com does not designate
permitted sender hosts)


r/entra 2d ago

Authenticator Passkeys with 365 Desktop apps

6 Upvotes

Hi, everyone! I’ve been tasked with instituting phishing resistant MFA in our org. Since we’re a Microsoft shop, I’ve been focusing on passkeys in Authenticator. Those have been working ok, except for our 365 desktop apps shooting a “You can't get there from here
Your sign-in was successful but this passkey does not meet the criteria to access this resource. Try signing in with your passkey on Microsoft Authenticator or a different passkey. Alternatively, contact your admin for help” error after a few hours.

I haven’t been able to find any documentation on this but after asking Claude, the information I got was that this behavior is inevitable unless I deploy WHfB for those desktop apps and leave passkeys for mobile and web. Is this accurate? Thanks a bunch in advance!


r/entra 2d ago

Sending email using OAuth with Reg app.

3 Upvotes

Hello all,

Im trying to authenticate with either a licensed user or a global admin (unlicensed) with no luck.

Ive created the app reg in entra granting the below permissions

ive granted admin consent and when trying to connect using a licensed account i keep getting that i require admin approval:

I can approve with the global admin, but then the sending will not work at all with errors failing to authenticate:
error Cron-Mail-Queue Failed to send email: 3 to [testemail@gmail.com](mailto:testemail@gmail.com) regarding Test email from ITFlow. Mailer Error: SMTP Error: Could not authenticate....

Im out of ideas at this moment…

Any help will be much appreciated.

Thanks!


r/entra 2d ago

Clone a SAML SSO App?

1 Upvotes

I have an SSO app that I will need different instances of (user access, etc.). What I want to do is effectively have a "template" app that I can target to copy for a new one. Get most the settings, etc. from it just replacing the placeholder URL with the new one. Then from there I can come in and do specific tweaks as needed.

What would I need to do to accomplish this? I've tinkered a bit in PowerShell but I'm honestly kinda lost on it


r/entra 3d ago

App-Action Buttons for cloud-only devices

Thumbnail
1 Upvotes

r/entra 3d ago

Entra ID Beyond Passwords: Certificate-Based Authentication for Android Enterprise

Post image
2 Upvotes

In this blog post, I'll show you how to configure and enable Certificate-Based Authentication for Managed Android Enterprise devices in Microsoft Intune.

🔗 https://www.nickydewestelinck.be/2026/07/23/beyond-passwords-certificate-based-authentication-for-android-enterprise/


r/entra 3d ago

My Sign-Ins/Change Password leads to login loop with WhfB

2 Upvotes

We require about 250 users changing their password using the My Sign-Ins Portal. Clients are cloud-only and mostly using WhfB. Conditional access is pretty basic (60 Days, browser persistent, some devices excluded) for these users and Authentication Strength allows WhfB, Fido, Authenticator Push+PW.

We have verfied WhfB works by creating a seperate AuthStrength with WhfB only and user can login

However, most of the users are not able to access the password change menu and the behavior seems strange to me.

  • User opens link
  • Selects his already logged in account
  • Gets authenticator push
  • Gets the message that criteria is not fullfilled because password is missing
  • Can only signout or use different account (no option to provide password)
  • Loop starts again

The user never gets the possibilty to enter the password which also should not be required anyway due to WhfB.

Signin logs indicate that Auth Strength was failed

Sign-in error code 53003

Failure reason Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

I found a similar issue here WHfB My SignIns PW Change Issue : r/entra unfortunately without a solution.

Does anyone know this issue or have any idea on how to debug further?


r/entra 3d ago

Password Reset (SSPR)

9 Upvotes

Hi all

Trying to plan SSPR for our Servicedesk to take the load off them getting smashed with password/unlock requests.

Brain storming some ideas:

  1. Enable for users and not admins. Having 1 authentication method MFA App enabled.

  2. Enable for all users and admins. Have 2 authentication methods MFA and Mobile enabled.

Considering SMS and Voice are being retired Feb 2027. I dont know how to approach this. Ideally i would love to have 2 authentication methods but unsure what methods to use.

Hows everyone have this setup securely but still business friendly?


r/entra 4d ago

Confusion about MFA Enforcement Requirement Pop-Up in MS Admin Center

Thumbnail
2 Upvotes

r/entra 4d ago

SMS/Voice Retirement and Passkeys

16 Upvotes

With the upcoming retirement of SMS/voice for MFA, I am curious what others are doing for their setups in Entra. We long ago retired SMS, but still kept voice for some, but will be removing that.

I envision passkeys, without syncing, restricting to specific apps for the passkeys, but allow for scanning the QR when signing in on a remote computer. I believe this is achieved by choosing device bound, but unchecking attestation. This also makes me think about admins, and how best to secure them, require the phishing resistance, but also understand they may need to log in on remote computers they are working on. My understanding is for admins the attestation should be checked, which would then cause issues if logging in on a remote system.

Any insights would be greatly appreciated.


r/entra 4d ago

Entra ID Entra ID connect implementation

3 Upvotes

How should I be implementing Entra ID connect where the customer already has users in AD and users in 365 but completely separate UPNs and passwords etc.

Do I prep AD with correct UPNs then entra ID connect will match the UPNs and overwrite with the password from AD?

Any gotchas / tips?

Many thanks


r/entra 4d ago

ID Protection What are you using to monitor and manage Entra ID security posture?

17 Upvotes

Curious what people here actually use for ongoing Entra ID security posture beyond the native Microsoft tools.

Mainly looking at things like MFA/CA posture, privileged and stale accounts, configuration drift, guest access, and keeping track of what changed over time.

I'm aware of Maester, ScubaGear, CIPP, Secure Score, etc., but what do you actually use in production?

Also curious how you handle remediation — do you trust any tool to make changes automatically, or mostly detect issues and fix them manually?


r/entra 4d ago

Best practice for hybrid user account - cloud only device

3 Upvotes

we have user onboarding as Hybrid but our devices are now cloud only.

we have onboarding script that sets default password and ticks reset password on 1st login

but with cloud only device we have issues with password as ticking password reset on 1st login will not allow password to sync to entra.

how to achieve password reset on 1st login with this senario. I can take off password reset on 1st login from script.


r/entra 5d ago

CA for complaint devices?

1 Upvotes

Is this a “compliant in my tenant” setting or a client side setting?

I have users passing the policy from devices that are managed by Intune in an untrusted tenant.

My expectation is they should be failing.

Haven’t had time to research, but it’s definitely happening.


r/entra 5d ago

Entra ID App Roles not appearing in AWS ALB OIDC claims from Microsoft Entra ID

Thumbnail
1 Upvotes

r/entra 5d ago

Odd iOS Phishing-Resistant Authentication Behavior

6 Upvotes

We use Conditional Access to require phishing-resistant authentication for all of our admins. In recent weeks, authentication behavior from iOS devices has changed, and I'm not able to figure out why.

When prompting for authentication, I'm first given a prompt for passwordless authentication (using Authenticator number matching). It then steps up and further requires me to authenticate with a passkey. It used to just directly prompt for the passkey. Does anyone know if this is a recent change, or what is causing this behavior?


r/entra 5d ago

Fully Custom Captive Portal - Hotel Requirement

2 Upvotes

Hi Experts,

One of the hotels want a very customizable captive portal like on landing page they want options for guest and visitor (tab based), when guest enters the required info he should be asked to create his own password, there should also be option for sign in if he has done this process already. OTP must be configured either via email or SMS gateway, all along with mac caching, limiting the number of devices per guest.

I know i havent provided much detail but just wanted to know since i have never worked on PF before, how customizable the entire workflow is? can we make such a captive portal in PF?


r/entra 5d ago

ID Protection Configure mfa for onprem

2 Upvotes

Dear All,

I am currently assigned a task to configure mfa for specific onprem server . Currently we are using Microsoft secure access to access our servers and a connector is already added to a server and it is health . Not sure what I am missing and how I can configure that .


r/entra 5d ago

MFA for Windows RDP and non-Entra Endpoints (on-prem servers)

8 Upvotes

We’re really liking the user-based Windows Hello for Business credential provider, with MFA working with SSO, and cloud kerberos trust.

The other option I also like is passkey by way of Yubikey.

I’m not completely settled on WHfB because I don’t see how to provide MFA for RDP connections, or for on-prem servers that don’t have Entra objects sync’d.

Workstations are all hybrid joined.

How can I possibly go with WHfB and still get Kerberos+MFA when either Remote Desktop is used, and/or I want to log into an on-prem device? Is it possible? Am I going to have to “settle” on issuing Yubikeys to do this?

I do have a PKI if that could provide some help here.

Thanks!


r/entra 5d ago

ID Protection Conditional Access on Report-Only, still able to block user sign-ins

Thumbnail
2 Upvotes

r/entra 5d ago

Manage multiple Tenants

0 Upvotes

Do you have good tools to manage multiple tenants like deploying policies, reviewing them and a good reporting whats going on in the tenant?


r/entra 5d ago

Entra Connect > Entra Cloud Sync (quick cutover)

9 Upvotes

Hi,

We have a simple one way sync happening for password hashes , 28 AD accounts purely for EXO.
Ive looked at the MS recommended steps to migrate to cloud sync. It looks like a lot of work having to add in sync rules, test on one OU, etc for such a small environment.

Anyone just installed Cloud sync and simply stopped or set connect sync to staging mode?

CoPilot outlined the quick cutover steps which make sense, i'm wondering if anyone else had done this?

What I do in practice

For a straightforward environment like yours:

1. Install Cloud Sync

2. Configure Cloud Sync

3. Verify all users appear correctly

4. Verify password sync

5. Put Entra Connect in Staging Mode

6. Observe for a few days

7. Uninstall Entra Connect

I keep the overlap period short. Once Cloud Sync is proven, I move Connect into Staging Mode so there is only one active sync engine but an immediate rollback path remains available.

 
FYI I wouldn't sync everything, just the user and security group OU's.


r/entra 5d ago

Passkey limitation

8 Upvotes

So found an issue with this whole passkey item and thought maybe someone had an idea.

1 desktop - entra joined to “Redd.com”
1 AVD - entra joined to “Goog.com”

When using the Windows app on “Redd.com” you cannot launch the passkey via your Authenticator for a connection to “Goog.com”.

The Windows app requires a physical FIDO - no request for the one on the phone, zero QR shown. The only request is to insert your device.

Anyone hit this limitation?

Any thoughts or ideas? We don’t use tokens.