DiscoverEntra.Chat
Entra.Chat
Claim Ownership

Entra.Chat

Author: Merill Fernando

Subscribed: 20Played: 1,380
Share

Description

Entra Chat is a weekly podcast hosted by Merill Fernando and delivers practical insights for Microsoft administrators and security professionals through conversations with identity experts who've been in the trenches.

Episodes feature seasoned Entra practitioners sharing real-world deployment experiences and Microsoft Entra team members who build the features you use daily.

Get the inside track on best practices, implementation strategies, and upcoming capabilities directly from those who design and deploy Microsoft identity solutions.

Join us for actionable takeaways you can apply immediately in your Microsoft 365, Azure, and Entra environments.

---

Entra.Chat, its content and opinions are my (Merill Fernando) own and do not reflect the views of my employer (Microsoft). All postings are provided “AS IS” with no warranties and is not supported by the author. All trademarks and copyrights belong to their owners and are used for identification only.

entra.news
78 Episodes
Reverse
Conditional Access no longer begins and ends with identity signals.Microsoft Purview can now influence the controls Entra administrators are asked to implement. From insider-risk conditions in Conditional Access to inline protection for sensitive data moving toward unsanctioned AI apps. That means Entra teams need enough Purview knowledge to understand what triggers a policy, how users experience it, and who should respond when an alert fires.In this episode of Entra.Chat, Merill speaks with Ray Reyes, Principal Security Consultant at Engage Squared and author of Mastering Microsoft Purview Deployment in the Era of AI. Ray explains Data Loss Prevention and Insider Risk Management in plain language, then follows their integrations into Microsoft Entra ID, Microsoft Defender XDR, and Global Secure Access.The conversation moves beyond product configuration. A policy can be technically simple and still require identity, network, data-security, HR, management, and data-owner teams to agree on scope, ownership, education, escalation, and remediation. Ray’s practical advice is to understand the neighbouring Microsoft security products at a high level and deploy Purview gradually: start in audit mode or with a limited group, learn from the impact, and expand with the business.Ray also shares the story of the charity he and his wife started in Nepal, how it grew from supporting roughly 30 street children to reaching thousands, and how that chapter changed his perspective on work and stress. He and Merill close with an honest discussion about burnout, layoffs, gratitude, personal branding, and building a career safety net outside any one employer.Sponsored byRecent layoffs have left a lot of strong professionals in limbo.That’s why we built Sponsor a Seeker, a simple way for the community to lift each other up.For just $29, you can gift a full 3-month Job-Hunt Pass packed with: • Unlimited resume & job description scans • AI-powered rewrites that actually beat ATS systems • Professional cover letter generationEvery dollar goes directly to the seeker.You can: → Sponsor someone like Alex M. (recently laid off front-end engineer) → Or request sponsorship for yourselfEither way, you’re helping keep momentum alive in a tough market.👉 Take action here: pastthebots.com/sponsorLet’s turn “I was laid off” into “Someone had my back.”Thank you for being part of this community, Rod Trent Past the BotsSubscribe with your favorite podcast player or watch on YouTube.About Ray ReyesRay Reyes is a Principal Security Consultant at Engage Squared and the author of Mastering Microsoft Purview Deployment in the Era of AI. He previously worked at Microsoft, where he led data-security subject-matter expertise across Asia Pacific and Japan and helped customers deploy Microsoft Purview and Microsoft Defender XDR. His work now spans identity, data security, and the wider Microsoft security stack.* LinkedIn → linkedin.com/in/ray-reyes-598062125Related Links* Mastering Microsoft Purview Deployment in the Era of AI by Ray Reyes (mentioned at 00:00 and 02:25)* Microsoft Purview overview (discussed from 03:29)* Adaptive Protection in Microsoft Purview (discussed at 22:09)* Learn about Data Loss Prevention for Network Data Security (discussed at 33:31)* Configure Microsoft Entra Internet Access content filtering (discussed at 34:18)* The Resilience Project: Finding Happiness through Gratitude, Empathy and Mindfulness by Hugh van Cuylenburg (mentioned at 47:25)Related Entra.Chat Episodes* How Microsoft Is Securing AI Agents in Entra — Conditional Access, Zero Trust & the “Block” Debate* How to Migrate from Legacy VPNs to Entra Private Access* What’s New in Microsoft Entra — May 2026: Passkeys, Agents & Cloud SyncChapters00:00 Intro03:29 Why Purview Matters to Entra Admins05:39 How Microsoft Purview Evolved09:46 Data Loss Prevention Explained16:04 Insider Risk and Employee Departures22:09 Adaptive Protection Meets Conditional Access25:00 Education and Alert Ownership28:51 Breaking Down the Security Silos33:31 Network Data Security and Unsanctioned AI38:29 How to Roll Out Purview Safely41:20 Ray’s Charity Work in Nepal47:10 Resilience Burnout and a Career Safety NetPodcast AppsApple Podcast - https://entra.chat/appleYouTube - https://entra.chat/youtubeSpotify - https://entra.chat/spotifyOvercast - https://entra.chat/overcastPocketcast - https://entra.chat/pocketcastOthers - https://entra.chat/rssMerill’s socialsYouTube - youtube.com/@merillxLinkedIn - linkedin.com/in/merillTwitter - twitter.com/merillTikTok - tiktok.com/@merillfBluesky - bsky.app/profile/merill.netMastodon - infosec.exchange/@merillThreads - threads.net/@merillfGitHub - github.com/merill Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
Xbox Security runs a gaming-specific Microsoft Entra baseline across more than 70 tenants every night.The scale is striking: about 50 controls, dozens of independently operated game-studio tenants, and one parallel pipeline that checks whether each environment still matches Xbox’s security intent. When a Conditional Access policy moves to report-only or a required service principal loses a permission, the next run finds it.In this episode of Entra.Chat, Merill speaks with Audrey Long, Principal Cloud Security Architect in Xbox Security at Microsoft, and Sam Erde, SecureShield Architect at Patriot Consulting and a Maester maintainer. Audrey explains how Xbox Security extended Maester with custom PowerShell, GitHub Actions, a multi-tenant service principal, federated identity credentials, dashboards, ticketing, and time-bound exceptions.The result is more than a posture report. Findings flow into an operational lifecycle with owners and deadlines. Studios get readable reports, deep links to the affected object, and remediation guidance. Security teams can answer audit questions without interrupting all the tenant admins, while the Maester pipeline keeps read-only observability separate from remediation authority.The conversation also covers why a Microsoft-wide baseline needs adapting for gaming acquisitions, how custom tests encode an organization’s intent, why security configuration deserves regression tests, the Investigate status Audrey’s team helped introduce, and how administrators can use AI as a first-draft assistant for PowerShell and CI/CD without outsourcing validation.Subscribe with your favorite podcast player or watch on YouTubeSponsorMaester Cloud turns every Maester and Microsoft Zero Trust Assessment run into a durable evidence trail. See new failures, fixes, accepted risks, and posture changes across every tenant—without digging through old HTML reports.* Keep 5+ years of tenant history in your chosen Azure region* Compare runs, spot drift, and get change alertsMaester Cloud is in active development. Join the waitlist for hosted, self-hosted, or enterprise onboarding updates.About Audrey LongAudrey Long is a Principal Cloud Security Architect in Xbox Security at Microsoft. She focuses on Microsoft Entra and identity security, as well as securing Azure, AWS, and Google Cloud environments across Xbox and its game studios. In this episode, she shares how her team built a gaming-specific Entra baseline and operationalized it across more than 70 tenants.* LinkedIn - https://www.linkedin.com/in/aulong/About Sam ErdeSam Erde is part of the Maester core maintainer team, a Microsoft MVP, and a SecureShield Architect at Patriot Consulting. He focuses on Active Directory, Microsoft Entra ID, Microsoft 365 security, and practical PowerShell tooling for defenders.LinkedIn - https://www.linkedin.com/in/samerde/Related Links* Maester, installation guide, and source code (mentioned at 02:19) - Maester · installation guide · GitHub source* Continuous monitoring with Maester and GitHub Actions (mentioned at 14:38) - https://maester.dev/docs/monitoring/github/* Writing custom Maester tests (mentioned at 22:39) - https://maester.dev/docs/writing-tests/* Connect-Maester permissions and read-only access (mentioned at 24:38) - https://maester.dev/docs/connect-maester/* Zero Trust Assessment: Secure your tenant (mentioned at 25:46) - https://entra.news/p/find-your-tenants-hidden-flaws-in* Maester’s Investigate test-result status (mentioned at 34:02) - https://maester.dev/docs/writing-tests/formatting-test-results/* Making Security Invisible for Game Developers (mentioned at 45:52) - https://opsmatters.com/videos/making-security-invisible-game-developersRelated Entra.Chat Episodes* How to Secure Copilot Agents, Azure DevOps & Defender (+ more) with Maester 2.1 (Full Breakdown)* Zero Trust Assessment: Secure your tenant* How to Design Bullet-Proof Conditional Access Policies in Microsoft Entra IDChapters00:00 Intro00:42 Meet Audrey Long02:19 From 50 Controls to 70+ Tenants05:11 Making an Entra Baseline Gaming-Specific08:32 Why Custom Maester Tests Matter11:07 Governance and Nightly Automation15:27 From Findings to Remediation18:07 Reports Studios Can Actually Use22:39 Building Custom Multi-Tenant Tests28:07 Security Intent as Regression Tests30:48 Catching Drift and Producing Audit Evidence41:39 CI/CD and AI for Security AdminsPodcast AppsEntra.Chat - https://entra.chatApple Podcast - https://entra.chat/appleYouTube - https://entra.chat/youtubeSpotify - https://entra.chat/spotifyOvercast - https://entra.chat/overcastPocketcast - https://entra.chat/pocketcastOthers - https://entra.chat/rssMerill’s socialsYouTube - youtube.com/@merillxLinkedIn - linkedin.com/in/merillTwitter - twitter.com/merillTikTok - tiktok.com/@merillfBluesky - bsky.app/profile/merill.netMastodon - infosec.exchange/@merillThreads - threads.net/@merillfGitHub - github.com/merill Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
Active Directory is not dead. It is nearly thirty years old, Microsoft is still shipping new capabilities and new telemetry for it, and most of the forests running today will outlive the people currently administering them. What has changed is that you can now test it the same way you test your cloud tenant.Maester, the open-source PowerShell testing framework, added Active Directory coverage: 269 opt-in checks across 19 areas, from users, groups, computers and service principal names through GPO state, DACLs, DNS, trusts, replication and schema. They run against your domain, not your tenant, and they are off unless you explicitly connect to Active Directory.Mike Soule, who wrote and validated that test suite, and Sam Erde, Microsoft MVP and author of DLLPickle, join Merill at HIP Conf in Nashville to go through what the tests cover, how to run them safely, and where the project is heading.Sponsored by: Is Each App in Entra ID Still Worth Governing?App registrations and enterprise applications accumulate. Owners change. Projects and pilots end. Credentials linger. And stale or unused apps and their permissions can continue adding risk and governance overhead long after their purpose is gone.ENow App Governance Accelerator helps you understand what’s in your Entra ID application estate, who owns it, which apps, permissions, and credentials need attention, and what can safely be cleaned up to reduce your attack surface on a continuous basis as your tenant grows and changes.Get the visibility and automated workflows you need to investigate application lifecycles at scale, clear out stale apps, and stop wasting time governing applications that shouldn’t still be there in the first place.Operational health is not the same as a security findingThe design decision that makes these tests usable is the split between operational patterns and security controls. Six groups nested in a row is not a vulnerability. Nesting is an intentional, functional capability. It is also nearly impossible to reason about when you are trying to work out where a permission actually comes from, and that is how incidents happen.So not every test is pass/fail. Some exist to be investigated and monitored, and Maester’s tagging lets you baseline them and watch whether an anti-pattern is spreading or receding over time. The underlying guidance is a blend: years of health checks across dozens of forests, community research from teams like Semperis and SpecterOps, and Microsoft’s own documentation — which, for a product people keep declaring dead, is currently some of the best documentation and logging Microsoft ships. The new NTLM auditing in Windows Server is the example: the who, the why and the where of every NTLM authentication, instead of replaying events and correlating them yourself.Maester is not trying to replace the likes of PingCastle, Purple Knight or Locksmith. Those tools offer real value, and the conversation now is about bringing those perspectives into one central platform.The permissions you actually needEverything the AD tests do is read-only. A plain domain user gets a surprising amount, because a directory is built to be readable — you will simply get a subset of the tests. The full set needs tier-zero read access, because some tests reach objects in the configuration container. In a tiered environment, that means running as a tier-zero admin from a privileged admin workstation.Interactively, there is nothing to set up beyond line of sight to a domain controller, the ActiveDirectory module and PowerShell. The AD tests are excluded by default and have to be requested by tag. For automation, run a local runner, or give a container runtime a path back to a domain controller. Today the tests run as the logged-in user’s domain credentials; alternate credentials and group managed service accounts are on the road map.Tiering, ESAE and the enterprise access modelThere are no explicit tiering tests yet, but they are coming now that Microsoft has published implementation guidance. The history is worth knowing. ESAE — the Enhanced Security Admin Environment, the red forest — solved a real problem: inside Active Directory, a domain admin is trusted implicitly, so the source of authority needs to sit somewhere that is not self-referential. A separate management forest achieves that, at a cost in operational complexity that most organisations could not sustain. Microsoft has since moved to the enterprise access model, and in practice most teams landed in the middle: tiering based on access control, with tier zero for core identity infrastructure, tier one for servers, databases and applications, and tier two for workstations and the workforce.The advice is not all-or-nothing. Any amount of effort you put into tiering is a good investment. Where Maester helps is codifying Microsoft’s recommended implementation as tests you can actually check yourself against, including the DACL and inheritance anti-patterns that accumulate through ordinary operations.What is coming nextThe dependency on the ActiveDirectory PowerShell module is on its way out. Almost all of this work is LDAP-level, so a .NET-based approach covers the vast majority of tests with no module dependency — which opens up Linux, macOS and non-domain-joined machines. Multi-domain aggregation is in progress; today a run covers a single domain at a time. And Maester 3 is being planned around a new engine for the built-in tests, with multi-threading and parallel execution, licensing handled centrally instead of inside every test, and Pester retained for backward compatibility and custom tests.Subscribe with your favorite podcast player or watch on YouTubeAbout Michael SouleMike Soule is a Maester co-maintainer and National Director of Enterprise Architecture at Sentinel Technologies, where he works with enterprise customers on identity, cloud and security. He wrote and validated the Active Directory test suite that shipped in Maester 2.2 — 269 opt-in checks across 19 areas — and has been the project’s leading test contributor since the night after Maester’s launch talk at the PowerShell Conference, when he turned up the next morning with roughly thirty CISA tests already written.LinkedIn - https://www.linkedin.com/in/mikesoule/GitHub - https://github.com/soulemikeAbout Sam ErdeSam Erde is a Maester co-maintainer and a Microsoft MVP, working at Patriot Consulting. He has spent more than twenty years in PowerShell, Active Directory, Group Policy, Exchange and Microsoft 365, contributes to open-source defensive tooling including Locksmith, and wrote DLLPickle, the module that gets you out of assembly version conflicts when several Microsoft modules are loaded in one session.LinkedIn - https://www.linkedin.com/in/samerde/GitHub - https://github.com/SamErdeRelated Links* Maester - open-source PowerShell test automation for Microsoft 365, Entra and now Active Directory (mentioned at 00:21) - https://maester.dev* Introducing Maester 2.2 - the release that added 269 opt-in Active Directory checks across 19 areas (mentioned at 04:50) - https://maester.dev/blog/maester-2-2/* Active Directory security testing in Maester - what the tests cover and how to run them (mentioned at 04:50) - https://maester.dev/blog/active-directory-security-testing/* Maester on GitHub - source, tests and contribution guide (mentioned at 03:44) - https://github.com/maester365/maester* Locksmith - Jake Hildreth’s AD CS assessment and remediation tool (mentioned at 05:11) - https://github.com/jakehildreth/Locksmith* NTLM auditing enhancements in Windows 11 24H2 and Windows Server 2025 (mentioned at 09:53) - https://support.microsoft.com/en-us/topic/overview-of-ntlm-auditing-enhancements-in-windows-11-version-24h2-and-windows-server-2025-b7ead732-6fc5-46a3-a943-27a4571d9e7b* AD DS tier model for privileged access security (mentioned at 24:47) - https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/tier-model* Securing privileged access - the enterprise access model that replaced ESAE (mentioned at 25:23) - https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-access-model* DLLPickle - Sam Erde’s module for PowerShell assembly version conflicts (mentioned at 16:16) - https://github.com/SamErde/DLLPickle* HIP Conference - Hybrid Identity Protection, Nashville, where this episode was recorded (mentioned at 01:18) - https://www.hipconf.com/* PowerShell DSC (mentioned at 31:34) - https://learn.microsoft.com/en-us/powershell/dsc/overviewChapters00:00 Intro00:40 Is Active Directory dead?01:41 How Maester started and Mike’s overnight tests04:50 Active Directory tests in Maester 2.x05:03 How Maester compares to PingCastle and Locksmith07:03 Operational health checks vs security findings08:43 Where the AD guidance comes from11:12 Running the tests and the permissions you need13:53 Dropping the ActiveDirectory PowerShell module15:18 One report for AD and cloud plus a Maester 3 teaser17:20 Performance and memory in very large forests20:23 Never run it on a domain controller23:03 Multi-domain and multi-forest scans24:14 Testing AD tiering and the enterprise access model28:02 Beyond AD: DNS and Windows Server roles28:50 Validating GPOs and desktop builds with Maester31:25 Maester vs DSC and config-as-code35:49 AD is not deadPodcast AppsEntra.Chat - https://entra.chatApple Podcast - https://entra.chat/appleYouTube - https://entra.chat/youtubeSpotify - https://entra.chat/spotifyOvercast - https://entra.chat/overcastPocketcast - https://entra.chat/pocketcastOthers - https://entra.chat/rssMerill’s socialsYouTube - youtube.com/@merillxLinkedIn - linkedin.com/in/merillTwitter - twitter.com/merillTikTok - tiktok.com/@merillfBluesky - bsky.app/profile/merill.netMastodon - infosec.exchange/@merillThreads - threads.net/@merillfGitHub - github.com/merill Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
At Black Hat USA 2026, Microsoft’s David Weston put three numbers on a slide that anyone still running domain controllers should sit with. The Microsoft Security Response Center went from 80 patches in February to 1,142 at the July Patch Tuesday. The fastest observed breakout time dropped from 98 minutes to 27 seconds. And mean time-to-exploit flipped from 63 days after a patch shipped to seven days before the patch existed.Tarek Dawoud, Lead Architect on the Technical Excellence Team in Microsoft Security, walks Merill through those slides and then draws the conclusion for identity teams in his own words: “Active Directory is like 10x harder to defend than Entra.” If you do not already have a plan to move off AD, he says, sit down and write one.He also says how Microsoft handles this itself. Most of Microsoft’s own servers run in the cloud, its front ends run with no domain at all, and on-prem AD survives mainly as a dial-tone service: the thing they need to bring Azure up from scratch, and not much else.Tarek is back on Entra.Chat, and he was privy to a small part of Project Glasswing, where Microsoft got early access to Anthropic’s Mythos-class models to find vulnerabilities in its own products before attackers could. The red-team community was cynical at the time; what Microsoft saw internally was, in his words, “very concerning. Those things were damn good.” From there he builds Weston’s argument: the whole security industry rests on an assumption of scarcity. Vulnerabilities are rare, exploits are expensive, and attackers have recognisable tactics, techniques and procedures. Patch-and-pray works when bugs arrive slowly. TTP-based detection works when a human crew reuses its playbook. When a risk is small, driving it smaller is worth the money; as Tarek puts it, “if something has a 95% possibility of happening, pushing it down to 80% doesn’t change anymore.” The Hugging Face intrusion (an OpenAI agent, and not a deliberate attack, as Merill is quick to note) showed what happens when the old assumptions fail: the agent landed on one server and looped, try an exploit, fail, write a new tool, try again, with no attempt to hide and no signature to match. Hugging Face survived by repeatedly tearing down and rebuilding core infrastructure. Tarek’s question for listeners: “Does your AD team have that skill?” Tearing down and rebuilding domain controllers, he notes, is not a thirty-minute operation.Hence the pitch: “Where you don’t need to own infrastructure, you shouldn’t manage infrastructure.” Tarek is explicit that this is his read of the moment rather than a mandate, and that it does not apply everywhere. Disconnected environments, military and intelligence, some manufacturing and IoT, and shielded OT networks such as utilities and remote mine sites are carved out; nobody is going to win the argument to punch a hole in an isolated OT environment to reach Entra. But for the ordinary case, collaboration, email, SharePoint, file shares, and apps that already live in Azure or AWS or even on-premises, he calls running your own identity infrastructure a losing battle. The minimum step is a strategy memo for your board that says what you are facing and why identity infrastructure investment needs to shrink.Merill raises the two objections he hears most. First: you are just trusting Microsoft, and Entra ID has bugs too. Tarek’s answer is about who is on the hook. Microsoft owns and patches the Entra infrastructure; the service deploys roughly every 10 business days and can push a critical hotfix worldwide within a day or two, across a fleet that was already more than 100,000 compute nodes five years ago. You still have to handle Entra bugs, but the work looks like a Conditional Access policy to block a risky flow such as device code flow, not patching every server yourself. One customer he worked with had about 12 people in IAM for more than 200,000 employees; Entra has over 2,000. Second: this is licensing revenue and cloud stickiness dressed up as security. Tarek does not pretend to know the CAL math. “Assuming good intentions,” he says, the case is defensibility: the ports, the legacy protocols, the sheer number of things to watch, and the amount of legacy that is indefensible. That is where the “10x” line comes from: an architect’s rough comparison, not a measurement.The back half is the path, using the Road to the cloud model at aka.ms/ad2entra. Map yourself to one of five states first: cloud attached, hybrid, cloud-first, AD minimized, cloud only. Then the moves that matter most. Decide, as a business, to stop buying apps that only run on-prem and make OAuth or SAML support a checkbox in the security review, because you will never turn off AD while a single LDAP app remains. Move devices to cloud management and out of hybrid join. Do not extend your domain into the cloud to manage servers; every cloud can patch and maintain a server without one, Microsoft’s own front ends run with no domain, and a domain you rely on becomes an attack vector for every server that trusts it. At the AD-minimized stage, HR provisions to Entra first (cloud HR, or API-driven inbound provisioning if your HR system is on-prem or file-based) and only the subset of users who need a stubborn legacy app is brought down to AD. The order of operations is apps first, then users and groups, with the Zero Trust Workshop identity pillar as the tracker for every box.Tarek is honest about what is not solved. Intune does not manage servers today (Azure Arc is one approach), and some on-prem cases, such as retail stores that need local servers to keep point of sale running when the internet drops, still need a domain controller. The identity data warehouse, the layer that normalises HR data before it reaches the directory, is something SailPoint does well and Entra “doesn’t quite do yet,” so expect that MIM, SailPoint or Saviynt-style layer to persist. And the last two Exchange servers: object-level Source of Authority transfer exists now, but the attribute-level transfer that would let you switch just the mail properties to cloud management is still in progress. Tarek has met maybe five customers at stage 5. He still closes with hope. If the last thing standing before your domain controller is those two Exchange servers, you have succeeded, and “as someone who owns identity infrastructure, you do have a path out. There are people who have no path out.”If you still own domain controllers and there is no written plan to stop, this episode is the memo.What you will learn* Why the scarcity assumption behind patching and TTP-based detection is breaking, and what the numbers on Weston’s slides (80 to 1,142 patches, 27-second breakout, exploits seven days before the patch) mean for anyone who owns servers.* What the Hugging Face intrusion showed about how an AI agent actually attacks, and the one question to ask your AD team.* How Tarek answers “Entra ID has bugs too” and “this is just licensing,” and what your residual burden looks like on an IDaaS.* The five states of the Road to the cloud model, and why mapping where you are comes before any migration work.* Why you do not need a domain to manage servers in the cloud, and where a domain controller is still legitimately needed.* What changes at the AD-minimized state: HR to Entra first, API-driven provisioning for non-cloud HR, and why an identity data warehouse still exists.* What actually keeps the last two Exchange servers alive, and how object-level versus attribute-level Source of Authority changes that.* Which legacy protocols are the real blockers (NTLM and LDAP) and the options on the table: App Proxy, Entra Domain Services, Universal Print.* How to use the Zero Trust Workshop identity pillar to track every step and stop the on-prem estate from growing.Subscribe with your favorite podcast player or watch on YouTube 👇About Tarek DawoudTarek Dawoud is Lead Architect on the Technical Excellence Team in Microsoft Security, part of the Microsoft Security Customer Value Program. A Microsoft veteran of more than 18 years, he previously led the architecture team in Microsoft’s customer engineering (CXE) organization for Microsoft Entra, and has worked with Microsoft’s largets enterprise customers on identity for years. He is a returning Entra.Chat guest; his earlier episode, From Active Directory to AI Agents: The 25-Year Saga of Microsoft’s Identity, is at https://entra.news/p/from-active-directory-to-ai-agents.LinkedIn - https://www.linkedin.com/in/tarekdawoud/Related Links* David Weston’s Black Hat USA 2026 keynote, The End of Rare: Defending When Offense Is Cheap (mentioned at 05:42; Tarek suggests skipping the first 14 minutes to get to the talk) - * Hugging Face: Anatomy of a Frontier Lab Agent Intrusion, a technical timeline of the July 2026 incident (mentioned at 13:51) - https://huggingface.co/blog/agent-intrusion-technical-timeline* OpenAI: The Hugging Face incident and the road ahead (companion post to the Hugging Face timeline) - https://openai.com/index/hugging-face-incident-and-the-road-ahead/* Road to the cloud: moving identity and access management from Active Directory to Microsoft Entra, aka.ms/ad2entra (mentioned at 26:14) - https://learn.microsoft.com/entra/architecture/road-to-the-cloud-introduction* Cloud-based management of Exchange attributes for Remote Mailboxes in hybrid environments (mentioned at 51:08) - https://learn.microsoft.com/en-us/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management* Decommission the last Exchange Server after transferring SOA to cloud (mentioned at 51:08) - https://learn.microsoft.com/en-us/exchange/hybrid-deployment/decommission-last-exchange-server* Microsoft Zero Trust Workshop video playlist, including the identity walkthrough (mentioned at 57:51) - https://www.youtube.com/playlist?list=PL3ZTgFEc7LyuZlK_W0nUN_VV6hscz-rQP* Zero Trust Workshop guided videos (mentioned at 57:51) - https://microsoft.github.io/zerotrustassessment/do
Microsoft starts making passkeys the default in Microsoft Entra ID on 1 September 2026, and retires Microsoft-provided SMS and voice MFA on 1 February 2027. Every organisation with a large, messy population now has to answer a question that has nothing to do with passkey technology itself: how do you move a hundred thousand real people - office workers, factory floors, call centres and guests - without locking someone out?In this episode, Merill sits down with the person who has already done it. Andrew Cameron is a Distinguished Engineer for Identity and Cybersecurity at General Motors, and he has spent roughly 25 years there, long enough to have started on the employee portal as a web architect in 2000, and then helped build the identity function that now carries one of the world’s largest passwordless deployments.The single biggest lever, Andrew says, was almost embarrassingly simple. GM treated Windows Hello as an optional convenience for years, then realised that an already-managed Windows device is a passkey. About 100,000 people were enabled through Windows Hello alone - no roaming key, no phone, no authenticator juggling. Platform SSO now extends the same idea to Mac through the secure enclave.The sequence matters as much as the tools. Admin roles came first, required to carry a device-bound passkey with Azure PIM forcing the stronger method through activation. Then Conditional Access did the rollout: a small group of eager users, audit mode, and then add apps and expand outward. Andrew’s practical tip is to target the big, heavily used apps before chasing every user - it often gets you to 80% coverage faster.Then the conversation turns to the corners most passkey explainers skip. Manufacturing workers who cannot use a phone and do not have a keyboard. Guest accounts - suppliers, dealerships and contractors - whose source tenant must also enable passkeys before the journey can complete. Call-centre users on unmanaged devices. And VDI, where certificate auth or Azure Virtual Desktop fills the gap.Andrew also walks through the synced-versus-device-bound decision, and lands on the unglamorous first step of the whole thing: before you retire anything, know which authentication methods are actually in use.If your plan for the SMS/voice deprecation is “we’ll deal with it in February,” consider this episode your head start.What caught GM’s identity team by surpriseAndrew was candid about the corners that bit them - the ones most admins only discover after the weak method is already gone:* SMS was the onboarding bootstrap. A new starter was never expected to have a passkey, so onboarding simply defaulted to an SMS code. Remove SMS and you have also removed the way people got in on day one. GM’s fix: issue a Temporary Access Pass (TAP) for onboarding, then register a strong method immediately.* A new phone defaulted to SMS again. The “I just got a new phone” recovery path sent a code to the number by default. That whole flow had to be redesigned too, not just the sign-in policy.* Guests were the hard problem. Several hundred thousand suppliers, dealerships and contractors can only finish a passkey sign-in if their own source tenant has also enabled passkeys. Enforce on your side and a guest can still get blocked upstream through no fault of yours.* Factory floors have no phones and no keyboards. Manufacturing workers could not use a phone or type a password, so GM built custom non-password methods and used hardware keys for robots and other physical assets.* Call-centre users are not on managed devices. Tens of thousands of users were remote or unmanaged, so GM folded device posture and network location into the risk evaluation.* VDI was a fresh corner. Certificate auth and Azure Virtual Desktop SSO replaced SMS as the way into a virtual desktop.* Hardware-key attestation had to be unwound. GM had registered AAGUIDs for hardware keys; when synced passkeys arrived, those old attestation requirements no longer applied and had to be revisited.GM’s secrets: don’t repeat the mistakes* Your managed device is already a passkey. The light-bulb moment was realising Windows Hello turns an already-managed Windows device into a passkey — no phone required. It became the fast path for roughly 100,000 people, and Platform SSO does the same on Mac.* Privileged roles first, then everyone else. Admin roles carried device-bound passkeys, with Azure PIM forcing the stronger method through activation.* Use Conditional Access as the rollout engine. Small pilot group → audit mode → add apps → expand. No big bang.* Target the big apps, not every user. You reach ~80% coverage faster by protecting the heavily used apps first, then adding more to the same policy.* Know your authentication methods before you retire anything. Monitoring and visibility come first — the deprecation clock is not the plan.Sponsored by:Scan, Score, and Secure Your Applications in EntraApplication identities represent one of the largest attack surfaces in Entra — and often one of the least consistently governed. AppGov Score helps IT and security teams understand where that risk sits.The 24-check assessment evaluates your Entra ID application integrations against Microsoft-recommended governance practices, analyzing:* App registrations and enterprise apps for excessive permissions* Expired or unmanaged secrets* Ownerless apps* Risky consent grants* Privileged service principalsResults are delivered as a clear, defensible risk score with actionable findings. No scripts. No manual inventory. Just a fast, read-only scan that reveals app sprawl, identity misconfigurations and blast radius — so you can prioritize remediation and strengthen your security posture with confidence.Subscribe with your favorite podcast player or watch on YouTube 👇About Andrew CameronAndrew Cameron is a Distinguished Engineer for Identity and Cybersecurity at General Motors. He joined GM in 2000 as a web architect working on the employee portal, then moved into directory services and helped stand up GM’s identity and access management team in 2004. He has spent the past quarter-century building and leading identity and security at one of the world’s largest manufacturers from early SAML and OpenID Connect standardisation and Azure AD adoption, to GM’s current passwordless rollout across roughly 200,000 people.LinkedIn - https://www.linkedin.com/in/kandrewcameron/Related Links* Passkeys by default and retirement of Microsoft-provided SMS and voice authentication (mentioned at 13:23) - https://learn.microsoft.com/entra/identity/authentication/concept-sms-voice-retirement* Passkeys (FIDO2) authentication in Microsoft Entra ID (context throughout) - https://learn.microsoft.com/entra/identity/authentication/concept-authentication-passkeys-fido2* Synced passkeys, device-bound passkeys and passkey profiles (discussed at 33:57) - https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-passkeys-fido2* Deploy phishing-resistant passwordless authentication (context at 28:38) - https://learn.microsoft.com/entra/identity/authentication/how-to-deploy-phishing-resistant-passwordless-authentication* Configure a Temporary Access Pass (discussed at 12:48 and 33:20) - https://learn.microsoft.com/entra/identity/authentication/howto-authentication-temporary-access-pass* Windows Hello for Business (the fast path discussed at 09:32 and 26:24) - https://learn.microsoft.com/windows/security/identity-protection/hello-for-business/* Configure Platform SSO for macOS devices (discussed at 27:23) - https://learn.microsoft.com/intune/device-configuration/settings-catalog/configure-platform-sso-macos* Require device compliance with Conditional Access (unmanaged-device discussion at 41:35) - https://learn.microsoft.com/entra/identity/conditional-access/policy-all-users-device-complianceRelated Entra.Chat Episodes* 5 Lessons from Rolling Out Passkeys to Millions of Users - https://entra.news/p/5-lessons-from-rolling-out-passkeys* From SMS MFA to Passkeys: A Practical Microsoft Entra Migration Plan - https://entra.news/p/from-sms-mfa-to-passkeys-a-practical* Mastering Microsoft Entra ID: Real-World Passkey Deployment Tips - https://entra.news/p/mastering-microsoft-entra-id-realChapters00:00 Intro00:27 Meet Andrew Cameron01:34 25 years of identity at GM07:34 200,000 people and their personas08:24 The strategy: passkeys over weaker MFA09:32 Windows Hello: the fast path10:06 Factory floors and hardware keys11:20 Sponsor: AppGov Score13:23 The SMS and voice deprecation14:20 The guest-account problem20:30 Roadblocks: onboarding and new phones23:30 Conditional Access: small groups first25:02 VDI, certificate auth and Azure Virtual Desktop27:23 Platform SSO on Mac28:38 The playbook: monitor, target, measure33:57 Synced vs device-bound passkeys35:35 Privileged roles first and Azure PIM38:54 Final thoughts and wrap-upPodcast AppsEntra.Chat - https://entra.chatApple Podcast - https://entra.chat/appleYouTube - https://entra.chat/youtubeSpotify - https://entra.chat/spotifyOvercast - https://entra.chat/overcastPocketcast - https://entra.chat/pocketcastOthers - https://entra.chat/rssMerill’s socialsYouTube - youtube.com/@merillxLinkedIn - linkedin.com/in/merillTwitter - twitter.com/merillTikTok - tiktok.com/@merillfBluesky - bsky.app/profile/merill.netMastodon - infosec.exchange/@merillThreads - threads.net/@merillfGitHub - github.com/merill Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
loading
Comments