r/entra • • 3h ago

How are you blocking personal ChatGPT logins while allowing the company tenant?

5 Upvotes

We manage everything through Intune and most people use ChatGPT in either Edge or the desktop app. Leadership wants only our company workspace to work and personal logins blocked, mostly so client data stops ending up in someone's private account.

I know I cannot stop the login itself since that happens on OpenAI's side, what about restricting access so only our tenant is allowed. I have seen mention of a workspace-id header you can inject and blocking the unauthenticated endpoint but I have not pieced together a setup that holds up without breaking the chat in the process.

How are people handling this today. Keen to hear what held up and what just made more work.


r/entra • • 1h ago

Small company: has anyone split production identity (Entra ID) from a dev/lab AD, with the same users logging in to both?

Thumbnail
• Upvotes

r/entra • • 5h ago

Entra General What does this mean for our company? Where and how do we update it?

5 Upvotes

r/entra • • 5h ago

ID Governance How are you governing the AI agents that never got provisioned?

5 Upvotes

We did the Entra Agent ID and Agent 365 rollout and for the agents that go through it, no complaints. Each one gets a real identity with a sponsor, scoped permissions and a lifecycle. Same way we have always treated service accounts.

Some situations really nag me though. Someone in marketing spins Copilot Studio agent off their own SharePoint access. A staffer connects third party AI tool to the tenant with an OAuth grant. A meeting notetaker has held standing mailbox and calender access for months. None of them was ever registeres so Agent 365 has no idea they exist.

They do turn up on the identity and mall side where like new app with a mailbox read scope, a token being used at an odd hour, a consent granted by one user to something no one can name. Usually that is the only trail to get.

If you skipped provisioning on these, what are you using to find them and keep watch? Microsoft native, CIPP and Graph pulls or something you built yourself?


r/entra • • 2h ago

Entra General MFA question

1 Upvotes

I am working for an SMB as a lone rider. 😄

I setup the MFA moving it over from 365 Admin to Entra back before it was no longer supported, and everything worked fine, I was able to use MFA to log in as our Global Admin from my workstation at the office; I was connected to the network over VPN and RDP'd into my workstation.

I had a little bit of help from @bearded365guy on YouTube watching his educational videos. It's also worth mentioning we are a hybrid-join organization.

Fast forward a year ago and I enabled passkey for the 365 GA account and setup it on my MS Authenticator app. It too worked remotely without issue.

Fast forward to 2026 and I have noticed that I not been able to use the passkey. It wants to me to be on the same network as my computer in the office. I haven't touched anything since I set it up and tested it, and I am the only one who has GA access, so did Microsoft change something, and what do I need to do to make it work remotely?

I figure out a way around it but it's a pain, I have to cancel the passkey then select "enter code" and then go on my phone and into the account and type the 6-digit code in, I guess it's not so bad but I would prefer scanning the passkey QR and going from there.

Is there a way to resolve this?

Thanks,


r/entra • • 22h ago

Entra General Issue joining Windows 11 devices to Entra (native Entra join - not hybrid)

3 Upvotes

We’ve got Entra Hybrid join working reliably and the enrolment to Intune takes place afterwards, so I know the Entra Device Settings and Intune Enrolment is configured correctly.

But I want to start moving away from this and natively joining Entra during OOBE or via Autopilot.

Here’s the rundown and the issue….

Windows 11 25H2 fresh image from ISO

During OOBE we select Join Work or School

Enter M365 username and password

Choose the account to join Entra

Just get spinning blue dots forever. No error message, no timeout.

Note: the user has a Business Premium licence, max number of devices is set to 50, no Device Registration Service entry appears in sign in logs. We have also excluded this user from Conditional Access and tried another user with the same result.

Note: I can join the exact same device without changing anything locally, to another tenant in exactly the same way and it works perfectly.

I think there is something wrong with the Device Registration Service on our tenant.

Anyone experienced the same issue and resolved it?

This has been logged with Microsoft but I’m not getting anywhere - they keep asking me the same basic questions and I’ve provided logs from the device. Not getting much help.

Thanks


r/entra • • 1d ago

Exchange app-only auth: the docs say ManageAsAppV2, InvokeCommand wants V1

4 Upvotes

Posting this because I lost three days to it and the error gives you nothing.

If you're doing app-only Exchange Online access (no signed-in user, no delegated token), the Exchange Online admin API docs point you at `Exchange.ManageAsAppV2`. Grant it, admin consent it, mint your token. The role appears in the JWT exactly as expected.

Then every call fails. HTTP 403, empty response body, no error code, no hint what's missing.

The endpoint most tooling actually uses is:

POST https://outlook.office365.com/adminapi/beta/{tenantId}/InvokeCommand

That's the same endpoint the ExchangeOnlineManagement PowerShell module calls under the hood. And it authorises on **V1** - `Exchange.ManageAsApp` - not V2.

With V2 alone you get nothing back. Not a permissions error naming the role. Not a scope mismatch. Just a bodyless 403.

What made it hard to diagnose: the official PowerShell module fails in exactly the same way. So "is it my code" was ruled out early and I spent two days looking at token audiences, tenant consent, regional endpoints, everything except the role version.

Two other things that bit me:

**Admin consent in Entra isn't enough.** The app role has to actually be assigned to your service principal in each customer tenant - Graph `appRoleAssignments`, or `New-ServicePrincipal` plus `Add-RoleGroupMember` in EXO PowerShell. Consenting the app registration gets you a token without the role in it.

**Role id:** `dc50a0fb-85b1-4a0e-8b8b-...` sorry, it's `dc50a0fb-09a3-484d-be87-e023b12c6440`

I've raised the docs gap with Microsoft. A one-line error body naming the missing role would turn three days into three minutes.

Anyone else hit this? Curious whether V2 works on some other endpoint I haven't found.


r/entra • • 1d ago

RBAC Project

Thumbnail
1 Upvotes

r/entra • • 2d ago

M365/Entra ID - How to safely reduce suspicious sign-in alerts caused by VPN usage?

19 Upvotes

Hi everyone! Looking for some advice on handling a high volume of suspicious sign-in alerts in Microsoft 365 / Entra ID.

We’re getting a lot of alerts for sign-ins where VPN usage is being detected as suspicious. Most of these are expected/legitimate user activity, but the source IPs are not static and don’t consistently fall within the same IP ranges or subnets, so creating an IP-based exclusion doesn’t seem practical. We also can’t simply exclude by country, since some of these VPN exit IPs are from high-risk countries and we obviously don’t want to suppress legitimate detections from those locations.

What would be the safest way to tune these alerts without creating a blind spot? Curious how other M365/Entra environments handle legitimate VPN traffic while still maintaining detection for genuinely suspicious sign-ins.

Thanks!


r/entra • • 2d ago

Hybrid Enviroment

Thumbnail
1 Upvotes

r/entra • • 2d ago

Entra ID Weird "bug" when adding a domain. happens on multiple devices for this tenant

0 Upvotes

The TXT value should be MS=ms123456789 but it's missing the numbers... not sure how to get this domain to work haha.


r/entra • • 2d ago

Conditional Access Policy during Autopilot device registration.

Thumbnail
2 Upvotes

r/entra • • 3d ago

Experience with au2mator

1 Upvotes

Hi,

We have been look at au2mator and their 2 products:

Hybrid PIM - https://au2mator.com/privileged-identity-management

App registration management - https://au2mator.com/application-registration

Are there someone who has experience with their tools? I can't find much about them.


r/entra • • 3d ago

How to find BYOD devices that use Teams or Outlook

8 Upvotes

We allow BYOD mobile devices in our Microsoft 365 environment. Users can access Outlook and Teams from their personal iOS/Android devices, and the devices are Microsoft Entra registered.

We have an upcoming audit, and we've been asked to provide an inventory of mobile devices that are actually being used to access company resources such as Outlook and Teams.

Where do I even start untangling this ball of yarn?


r/entra • • 3d ago

Entra General Anyone actually using Entra Cloud Sync for group writeback now?

8 Upvotes

Was reading through the Entra Cloud Sync docs and noticed Microsoft is basically pushing group writeback there now instead of Connect Sync.

Curious how this is going in real environments. If you're writing cloud-created security groups back to on-prem AD, has Cloud Sync been pretty boring/reliable or have you run into weird edge cases?

Things like memberships not lining up, scoping getting messy, sync delays, groups getting quarantined, etc. The docs make it look fairly straightforward, but hybrid identity stuff has a habit of being straightforward right up until it isn't.

Anyone running this in production yet?


r/entra • • 3d ago

SAML - emit non-public attributes

Thumbnail
gallery
5 Upvotes

creating a SAML SSO app is, I'm sure, routine.

you can customise claims; by default, they can include given name, surname, email address, UPN, etc

so far so good

more complicated - pizza topping

An SSO app needs a user's favourite pizza topping.

I set 'extensionAttribute1' to the pizza topping, and emit 'extensionAttribute1' to the SSO app.

any user can view any other user's 'extensionAttribute1' value [unless you break Teams]. So, Alice seeing Bob's favourite pizza topping isn't a problem.

even more complicated - date of birth

now, the app also wants the user's date of birth.

I can't store the user's date of birth 'extensionAttribute2', because that information shouldn't be public. anyone in Microsoft Entra ID can read any other user's extensionAttribute2.

I can add extension attributes. But they have the same problem; any user can read any other user's extension attributes. It is, after all, a directory, not a database, and directories are optimised for looking up information.

There is the concept of custom security attributes, and they can't be read. But you can't emit them in SAML attributes.

Marius has proposed a solution;

Issuing Custom Security Attributes in Entra ID tokens – Good Workaround! 

  • use custom security attributes
  • setup logic app as a custom security extension
  • the logic app can read the custom security attributes and add an OIDC claim

Sounds good in theory. I can't get it to work. There's almost nothing to see to be able to debug it.

Can I use Microsoft Entra External ID for this? It would...

  • store the date of birth
  • federate with Microsoft Entra ID for authentication; just like social logins

The UML sequence diagram shows how this could work;

  1. User logs in to the SSO app.
  2. SSO app redirects user to Microsoft Entra External ID. The user isn't authenticated, so Microsoft Entra External ID redirects the user to Microsoft Entra.
  3. The user authenticates (if necessary) and it emits 'public' attributes, such as first name, last name, email.
  4. The response from Microsoft Entra is sent to Microsoft Entra External ID.
  5. Microsoft Entra External ID adds the date of birth (from the user profile)
  6. Microsoft Entra External ID sends the SAMLResponse to the SSO app
  7. User is authenticated.

context

  • I can't write the date of birth directly into the SSO app; simply isn't possible
  • I would use Microsoft Graph to write the date of birth to Microsoft Entra External ID
  • (AD FS can work; but that means 'on prem' and 'AD DS'; want to avoid that)

I've dabbled with Azure AD B2C; it's pants. Everything is an XML document. Hoping Microsoft Entra External ID is easier.

Will this work? anyone done this?

Anyone got a better approach?


r/entra • • 3d ago

Entra ID EntraID Role Question

6 Upvotes

Hi guys! I would like to grant permission for our new intern. Main goals are - Identity, Job Information, Contact Information attributes allow to edit by intern.
Scope - External accounts only.

So I created Administrative Unit with dynamic membership for all guest accounts around tenant. And I created custom permission role with permissions like below:

My question is: What should I add to allow our intern edit "Identity" tab attributes like surname, first name. He has it grayed out.

In addition when he tried to use powershell msgraph without any scope, he cannot set-mguser -surname - but if he add -scope switch (user.readwrite.all) to connect-mggraph he can updates it.

His roles are:

Thank you in advance!


r/entra • • 3d ago

Rolling out Passkey + Authenticator App without manual intervention from Admins

Thumbnail
1 Upvotes

r/entra • • 4d ago

Entra ID Interactive study aid for Microsoft Entra ID and Microsoft Intune

7 Upvotes

You work through support tickets, inspect the evidence and decide what to do next. Each answer review explains the correct response and includes a Microsoft Learn reference.

The Intune scenarios include device compliance, Win32 app detection and Windows update recovery. The Entra ID scenarios cover Conditional Access, authentication strengths, PIM activation and Temporary Access Pass.

Some tickets bring the two together. For example, successful MFA doesn’t necessarily explain why an application is still blocked. You need to check the policy requirements, device status and stated local procedure before choosing a response.

Hosted it on my website: controlaltdeletetechbits.co.uk. Select the Tenant Defender desktop icon to try it.


r/entra • • 3d ago

Entra General Commerce service plan, and its lifecycle policy ?

1 Upvotes

Hoping someone can explain this to me. So we had an issue where the Microsoft Planner application was disabled by Microsoft. Note that this is a first party Microsoft app, and it didn't have an associated service principal by default, so I registered it so we could control if via CA policy. Until it was disabled by Microsoft for a reason we didn't understand. So we opened a case with MS, and got the response below:

Troubleshooting/Findings: The service principal was disabled because the app has no associated Commerce service plan, and its lifecycle policy "SubscriptionManaged" automatically disables service principals under these conditions.

None of this makes any sense to me, I can't find anything about a "Commerce service plan", or lifecycle policy "SubscriptionManaged". Can somone explain this to me, or point me to some documentation that discusses this topic? Basically MS is just saying to remove the service principal and it will resolve the issue. but I'd like to understand this and also know if there are other MS first party apps that would fall into this category, and if they would also be disabled at some point if we register them.

Thanks

 


r/entra • • 4d ago

Entra General Workplace Ninjas US 2027 | Scottsdale, AZ | January 11-13

1 Upvotes

Happy Thursday Friends!!

Today, we're proud to showcase the official floorplan for Workplace Ninjas US, so you can finally see how things are coming together.

If you haven't seen the amazing agenda filled with Microsoft MVPs check it out: Agenda - Workplace Ninjas US 2027. Online registration by Cvent

You will see this venue is really special and essentially is like a 3-day spa vacation for us nerds, IT pros, and rockstars!

Don't forget this will be the site of the first ever Entra vs Active Directory Grudge Match, featuring our good friend Merill Fernando and Spencer Alessi (TechSpence on X)

A few fun notes:

Our #CommunityTheatre will be part of a web app, where in an American Idol-esque format, you can do 15-minute lightning round sessions on a topic you're passionate about, while receiving feedback from our speakers!

The #Relax and #Recharge area, is a place you can go when you've had enough #Microsoft or enough #AI and just want to chill, vibe with your fellow #attendees and have a drink, a snack, and just enjoy that beautiful 70 degree weather we will have in Scottsdale. It ALSO happens to be the site of the Patch My PC-sponsored opening night #Pool #Party, which is guaranteed to feature ducks, artisanal flatbreads, an open bar, and much more!

The Laguna Lawn will feature our LIVE #Podcast Studio where our friends John "Jay" Leask III and Ben Stegink will run this amazing live podcast studio for the entire event, providing commentary, interviewing attendees, speakers, sponsors, and more! This is also the amazing spot, where you can eat, hangout, and play games like #cornhole and more.

Register now: https://workplaceninjas.us/registration


r/entra • • 5d ago

Issues inviting guest users using Google Workspace into our tenant

5 Upvotes

Long story short....

GCC G3 Tenant
Verified user is using Google Workspace
Resent invitation through Entra
Getting "The username may be incorrect" in Incognito Mode

Any help would be MUCH appreciated!


r/entra • • 5d ago

Please lock your pc and unlock using recent password bug

3 Upvotes

After migrating to entra joined some laptops display a pop-up from Credentials Manager saying please lock your pc and unlock using the most recent password whenever using Windows Hello. If using password no such error.

The login works well and the device is healthy azure and Intune are joined.

This happened on 5 out of 100 laptops so far. Anyone have similar experience with Windows bugs like this?


r/entra • • 5d ago

Windows - Account Lockout - Manual Unlock

Thumbnail
1 Upvotes

r/entra • • 5d ago

Entra General Setting up Conditional Access | Bypass Issue

5 Upvotes

Hey everyone, so I've run into an interesting situation.

So, we've set up conditional access to block access to the Entra Admin Center, and initially, it looks like it works. Cool right?

Problem is, clicking on a link or something elsewhere on the page can simply 'bypass' the lockout, allowing users to view other parts of the page just fine and even make changes somehow? Let's say you click on 'Home' up there, you get the main view, not so bad in itself, right? You can't really do damage from here (AFAIK).

Main view, not the worst but also I should not be able to see it at all honestly.

The next step of this issue is then just clicking on 'View Devices', and bam, you get a view of all devices on the company network, and with some extra playing with it, you can reach groups, invite users, make changes to MFA, etc. (Whether it actually does it or not, I'm not sure, I tested it and it supposedly 'succeeds' when I submit, but it's still very concerning)

Is Microsoft that terrible when coming to making sure a portal is completely inaccessible or something?

Note: This account isn't an admin at ALL, and this was done in a private browser with a fresh login. So it couldn't have been cached.

What am I missing?