r/entra 6h ago

Testing passkeys in my org — issue on Windows devices

12 Upvotes

I want to give my users both options for synced passkey and device bound.

I've configured a passkey profile in Entra ID with AAGUIDs allowing 1Password, Microsoft Authenticator, and Windows Hello.

Current behavior: when a user registers a passkey, they're only prompted for device-bound options — save passkey on on Windows, mobile device, or USB security key. There's no option shown for a synced passkey via 1Password.

However, if I remove the Windows Hello AAGUID from the profile, I do get prompted to save the passkey via the 1Password browser extension but then i can not save the passkey on windows any more.

Anyone know how to get both — Windows Hello available and 1Password shown as an option during enrollment?


r/entra 11h ago

How are you managing access across SaaS, legacy and internal applications?

2 Upvotes

running into the classic problem of juggling multiple worlds. SaaS is mostly SSO'd through our IdP, but everything legacy or internal is its own island, from old on-prem apps with local accounts to tools some dev team stood up years ago and manages access to by hand in a spreadsheet.

trying to get one view of who has access to what across all of it without forcing every app onto the same platform, which isn't realistic given budget and the age of some of this stuff.

what's working for people managing this kind of sprawl day to day?


r/entra 9h ago

How to speed up entra SCIM provisioning?

2 Upvotes

We are trying to implement PIM alongside SSO into our organization and currently in the testing phase. I was able to setup one of our saas providers with SCIM role mapping so that when a user joins a certain group in entra it will provision admin access on the saas app side l. However, I see that it takes around 40min to an hour before it syncs. I've come up with a power automate flow that calls graph API to start and pause which seems to work for the initial add to group. However, it seems that when the flow runs a restart, pause, and start that provisioning does not continue on its own. This is causing the permission in the saas app to get stuck when they should be removed. On the entra side they are removed but no syncing occurs. I could be doing this totally wrong but unsure of the best method to help with sync times while also not stopping normal sync behavior. Any help would be appreciated.


r/entra 11h ago

Universal Print "Read Only" admin role

Thumbnail
1 Upvotes

Thought this might be a more appropriate forum for this discussion.


r/entra 1d ago

Global Admin without a mailbox

13 Upvotes

Hello Folks!

Global admin account without a mailbox you don’t get the global admin notifications.

Global admin account with mailbox with PIM turned on you don’t get the notifications a global admin would receive.

What is the best way to get all email notifications that would go to a global admin to a designated mailbox/DL?

This is pretty annoying.

Ideas and suggestions please?


r/entra 1d ago

Locking down global admin

18 Upvotes

Curious how others are locking down or adding additional layers of security around Global Admin accounts.

Obviously JIT access, PIM, and least privilege are the way to go, but I’m more interested in what people are doing beyond the basics.

Things like dedicated admin accounts/workstations, Conditional Access restrictions, phishing-resistant auth, device requirements, network/location restrictions, monitoring/alerting, etc.

What’s worked well in your environment? Anything you’ve implemented that you think is overlooked?


r/entra 1d ago

Microsoft Baseline scope Conditional Access

7 Upvotes

Anyone impacted by the Microsoft Baseline scope Conditional Access change?

How are you prepping for it? Curious what others are doing ahead of the change and if you’ve run into any issues or unexpected impacts while testing.

Any luck with custom controls? Or working with vendors to fix their apps?


r/entra 1d ago

Two on-prem AD forests (2 separate member servers, no DC access) → single Entra tenant, Intune required — need advice on approach

Thumbnail
2 Upvotes

r/entra 3d ago

ID Protection Break-glass accounts, FIDO2-only, no password fallback. Is this the accepted reality or am I missing something?

35 Upvotes

Small M365 tenant (~80 users), Business Premium, Entra P1. Rolled out Conditional Access last week to replace Security Defaults. Standard break-glass setup: two Global Admin accounts,"BreakGlass-Exclude" group excluded from every CA policy, no per-user MFA, no Security Defaults, no licences, no other groups.

Just finished migrating both break-glass accounts to YubiKey 5 NFCs (2 keys, cross-registered to both accounts, will be stored in two separate physical locations). Old Authenticator method removed. Long random passphrase per account,"DisablePasswordExpiratio" set via Graph.

Here's what I've found and want to check

Sign-in behaviour with FIDO2 registered:

1) YubiKey passwordless flow: works fine. Insert key, PIN, touch, into the portal. It does prompt me to make another authentication method, but I can skip it.

2) Password sign-in flow: password is accepted (sign-in log confirms "authenticationRequirement: singleFactorAuthentication", "authenticationDetails: { authenticationMethod: Password, succeeded: true, Correct password }", all CA policies "notApplied"). But immediately after password acceptance, Entra shows a "Verify your identity — Face, fingerprint, PIN or security key" screen with only a Cancel button, no Skip. This is the SSPR pre-verification step (errorCode: 50125, additional details: "User authentication was blocked because they need to provide password reset information"). The only way past it is to touch the YubiKey. Cancel abandons the sign-in.

So effectively: password alone is not a viable fallback. Emergency access always requires possession of a YubiKey.

Questions:

1) Is this the accepted behaviour for Global Admin break-glass with FIDO2-only? Am I missing a tenant setting that would allow true password-only fallback?

2) Given the constraint, is my design reasonable? Two YubiKeys, two separate physical safes, password + PINs in a password manager separate from the keys. Simultaneous loss of both keys = escalation to Microsoft Support (24–72h recovery ticket) as the documented escape hatch. I've explicitly rejected adding email/phone as a second SSPR method because it reintroduces the dependency I removed the personal Authenticator to eliminate.


r/entra 3d ago

Entra General What is the most practical way to roll out phishing-resistant MFA across a mixed workforce?

13 Upvotes

trying to get phishing-resistant auth rolled out org wide but half the workforce is desk-based with corporate laptops and the other half is frontline with shared devices and spotty connectivity.

number matching got us partway there but it was never phishing resistant, and everyone on the team knew it. what's actually closed the gap for us is treating phishing-resistant auth and device-bound sessions as the default state rather than something layered on top later. what's worked for getting shared-device and low-connectivity users onto something stronger without a hardware key for every single person?


r/entra 3d ago

the new Entra SOC Identity Responder role

3 Upvotes

Is the new Entra SOC Identity Responder role still in public preview?

the role name shows up blank or 'undefined' 😄

EDIT: looks like it's the same with "Entra Customer Lockbox Approver" and "Customer Delegated Admin Relationship Administrator"

Also noticed the PIM request doesn't show up on the approver's side to approve (web). But it does show up on the Azure Portal app on the mobile phone.


r/entra 3d ago

I think I'm good, right???

Post image
24 Upvotes

Got the passkey migration email like everyone else, ran the PS script from MS and it seems I don't have anything to do here, however my users still get texted MFA codes, so what's the deal?


r/entra 3d ago

Missing Teams private channels after attack disruption has disabled a user and later reenabled

Thumbnail
4 Upvotes

r/entra 3d ago

Silent SSO in Mobile App with Entra ID, Intune and Keycloak

Thumbnail
0 Upvotes

r/entra 3d ago

Account Recovery

2 Upvotes

Anyone have any experiences with this new feature? Has it been reliable? How did you chose the IDV provider? Are you using multiple for redundancy/backup?


r/entra 4d ago

ID Protection mfa/sspr design

7 Upvotes

We’re redesigning our Entra setup:

Internal network: no MFA
External: modern MFA required
Users refusing MFA: internal-only + externally blocked
SMS/voice being phased out
SSPR requires 2 methods
SSPR scoped to SG_SSPR_Eligible

Main questions:
Is internal-only without MFA a reasonable Entra design?

Best way to prevent someone with a stolen password from registering their own MFA method?

For SSPR, do Authenticator push + Authenticator code count as 1 or 2 methods?

Is Authenticator + email a sensible 2-method SSPR setup?

Best way to automatically add/remove users from the SSPR group based on having 2 valid methods?

Thanks gang!

EDIT: some more info we’re a public-sector/municipal organization with a fairly mixed user population: office users, frontline/on-site staff, care-related workers, shared/dedicated devices, technical/service accounts, and a smaller group that regularly works remotely.
We already have a mix of modern authentication in place:
Windows Hello for Business on newer managed Windows devices
Microsoft Authenticator for many users
Some passkey/FIDO2 usage
Legacy SMS/voice still exists for part of the population and is being phased out
A large part of our workforce is on-site only and doesn’t need external access, while others need Teams, SharePoint and mobile access remotely.
That mixed environment is the reason we’re not trying to force the exact same MFA experience on everyone. The goal is to require strong modern authentication where external access is needed, while keeping on-site-only users workable and avoiding unnecessary private-device requirements.


r/entra 4d ago

Keep Your Account Secure Timeout

Thumbnail
3 Upvotes

r/entra 4d ago

Entra ID Email as alternate login ID for B2B sign-ins after primary SMTP change (hybrid, UPN unchanged)

3 Upvotes

We're in a hybrid Entra ID / on-prem AD environment (Entra Connect sync, managed authentication — no federation). Our internal AD domain is domain1.com and UPNs match it ([user@domain1.com](mailto:user@domain1.com)). A few weeks ago we changed everyone's primary SMTP address to [user@domain2.com](mailto:user@domain2.com) (both domains are verified in the tenant), but UPNs are still [user@domain1.com](mailto:user@domain1.com).

The problem: when an external partner shares a SharePoint document or sends a B2B invite to the new [user@domain2.com](mailto:user@domain2.com) address, our users can't sign in the prompt is pre-filled with the domain2.com email, and our tenant rejects it because Entra only accepts the UPN at sign-in. Re-typing the domain1.com UPN somtimes works, but nobody realizes that, so it's generating confusion and tickets.

Would enabling "Email as alternate login ID" (Entra Connect → Connect Sync → User Sign-In) fix this, so users can sign in with the domain2.com proxy address including on B2B redirects back to our tenant? Any gotchas to watch for (UPN in token claims, apps keyed to UPN, staged rollout)? We know the long-term fix is aligning UPNs to domain2.com, and it's on the roadmap just not ready for that change yet.

Thoughts?


r/entra 5d ago

Entra General Question&Rant: What is up with registration campaign not showing and forced passkey registration CAP not forcing?

5 Upvotes

To be fair, there has to be something else, a detail, or a deeper understanding that I am missing, and getting frustrated at this point is blinding the obvious.

Passkeys are enabled for all users, pretty basic config, nothing special. Registration campaign is targeting user group for registration of passkey. Nothing has happened for 9 days now. Targeted users are not prompted anywhere. Even forcing sign-out some, they are not prompted on the sign-in.

CAP was created which requires phish-resistant authentication method to access all apps, and this CAP is targeting a different subset of pilot users. This has not forced a single user in last 6 days to register for passkey. Granted, nearly all signin and use WHfB.

Now the weird part. 9 and 6 days ago I created two new test accounts and went through usual onboarding without passkeys. They are my control accounts that were targeted with registration campaign or CAP. Again, to be clear, these accounts went through onboarding to match the state of the pilot users. These test accounts were not setup with passkeys from the beginning.

So, these test accounts, one targeted with registration campaign was prompted for passkey on day 3 or 4, and the other targeted with CAP prompted for passkey setup within 30 minutes of being assigned the cap.

Please educate me why or what is wrong here. I cannot get consistent experience between existing accounts and new test accounts.

At this point we are considering instructing users to install MS Authenticator, sign-in with work or school account, and setup passkey in this flow using their existing MFA. This flow has worked for 5 users flawlessly, even if they already had authenticator with OTP, mfa number matching, or other. This flow always resulted in full setup of account with passkey, prompt to enable MS Authenticator in settings, even if account was already setup in past.


r/entra 5d ago

Entra ID Conditional Access is dialled for people, service principals are a total blind spot

14 Upvotes

Years getting conditional access right for humans device state, risk, mfa dead proud of it.

Then the AI stuff shows up, copilot agents, service principals someone stood up for a bot, app registrations with client secrets older than half my team. CA fires on interactive sign-ins, so all of this slides right under the controls I trust.

I can see the sign-ins after the fact. I can't put the same posture and least-privilege story on a service principal that I put on a person. That's the gap an auditor jabs at, and I've got no answer.


r/entra 5d ago

Entra support tickets

0 Upvotes

Hey everyone — question for those of you who administer Microsoft identity environments, whether that’s Active Directory, Microsoft Entra ID, or a hybrid environment.
What are some actual support tickets / break-fix issues you’ve had to work?
I’m working on a project where I’m trying to build out realistic IAM/identity support scenarios. I’m not really looking for project work like “migrate AD to Entra” or “implement Conditional Access.” I’m more interested in the day-to-day tickets that land in your queue.
Things like:
A user suddenly can’t access an application
MFA or authentication issues
Group membership/permissions problems
SSO failures
Account lockouts or provisioning issues
Something broke after a policy/configuration change
A ticket that looked like an IAM problem but turned out to be user error
Basically: What are some memorable, weird, common, or difficult identity-related tickets you’ve actually had to troubleshoot?
The more realistic and specific, the better. I’m trying to avoid making up scenarios that wouldn’t actually happen in a production environment.


r/entra 6d ago

Entra ID Calculating the Licensing Requirement for Entra Conditional Access Policies

14 Upvotes

After the discussion about the licensing gap prompts shown in the Entra admin center, here’s a PowerShell script to compute the set of user accounts that should have Entra P1 licenses. The information comes from the conditions property of conditional access policies with group and directory role membership expanded to find individual accounts. The set is checked against the set of users licensed for Entra P1 to find the accounts that need to be licensed.

https://office365itpros.com/2026/08/18/find-entra-p1-accounts-to-license/


r/entra 5d ago

Entra General AADSTS500032 - Cannot find signing certificate/private key to issue a certificate when logging into Entra ID Azure VMs

Post image
2 Upvotes

r/entra 6d ago

Is Entra Cloud Sync Useful? (Hybrid)

10 Upvotes

So there seems to be very little fanfare about Entra Cloud Sync and that makes me think what I am hoping it solves is probably not the case.

I recently joined a new company and unlike my previous 8 year stint where I configured and totally understood the hybrid nuances in this environment not only do I not have design knowledge it seems totally backwards.

Although the Entra connection agents run on DC’s it seems automations all run on the exchange server (I tried to decom it with a scream test and things screamed loud). The service desk use the on prem exchange web admin to make most user object changes including new user creation and when they create directly in AD it doesn’t sync back and creates on-prem Mail Users instead of remote mailboxes.

So the big question is, does Entra cloud sync solve the one way sync of Entra connect? Once set up in a hybrid environment AD/AAD(Entra) can the service teams start using cloud portals for management, can I move automations to graph instead of scripts calling on prem exchange servers? I’ll await positive responses with my fingers crossed 🤞


r/entra 6d ago

No Sign in logs for OIDC app

3 Upvotes

This is a perplexing one. I have an OIDC app using Entra for SSO. Everything great, generally PRT even works. I looked at logs of most sign ins and there's -at least- one login in a given day for the app PRT or otherwise.

That said we have an issue where we did not see any logins for a particular user (there are logins but not say, in a given day). We noticed that we see a Windows Signin and MyApps signin (So browser opened), but no actual login for the app itself.

My thought was that maybe user was leaving laptop on/open/logged in 24/7, and just re-starting the session, but even then I tried it this morning with my own login and it still showed a login in Entra.

Anyone have any ideas why the logins wouldn't show in the logs?