Merill Fernando :verified: :donor:

Product Manager @microsoft | entra.news CxP #identity #entra #graphpowershell
Dad • Dev • He/Him • 🇦🇺 • 🇱🇰 • Wurundjeri Country • Toots are my own. @merill on Twitter

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-20

Learn more at aka.ms/EntraAgentId

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-20

ICYMI Microsoft just announced Agent ID at Build today.

Now a single place to start managing access controls for the agents in your organization!

This is just the start folks 🦾

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-19

👋 Check out this new Microsoft Entra blog post 👇

Announcing Microsoft Entra Agent ID: Secure and manage your AI agents

techcommunity.microsoft.com/t5

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-18

We just sent out this week's Entra newsletter!

Get the latest at entra.news

From the community…
🚀 Most popular posts from last week
🥇Taming Guest User Chaos in Entra ID • Sandra Saluti

🥈Register Yubikeys on behalf of your users with YubiEnroll • Jan Bakker

🥉The state of the (Passkey) union, May 2025 • Per-Torben Sørensen
Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-13

Have you had a chance to check out the latest news on Microsoft Entra this week?

Subscribe today and read at entra.news

👩‍✈️ AI & Copilot
Azure & Microsoft Graph MCP • Brian Veldman

🧰 Workload ID
Practical Graph: Use App Management Policies to Control App Credentials • Tony Redmond

👮‍♂️ ID Governance
Use Custom Extensions for Access Package approval in Entra • Daniel Bradley

Finding Resources in Microsoft Entra ID Governance Access Packages using PowerShell • Christian Frohn

🌐 Private Access & Internet Access (GSA)
Introduction to Microsoft Global Secure Access (GSA) • Niklas Tinner

Securing Microsoft 365 Apps with Microsoft Entra Global Secure Access • Oliver Müller

📦 Apps
Practical Protection: Protecting Your Tenant by Restricting Applications • Andy Schneider
Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-10
Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-10

Simon wanted his devs to securely impersonate service principals in Azure when building their apps.

In this week's Entra Chat podcast, Simon shows how he went about building it.

We also deep dive into Entra/Azure's ABAC permission model, PIM for devs and more...
👇

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-08

👋 Check out this new Microsoft Entra blog post 👇

Enhance identity security and resilience to minimize operational disruptions

techcommunity.microsoft.com/t5

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-08

Earlier today I joined Dom on The Game @ Pax8 to talk about the features in Entra ID P2 as well as a quick update on the upcoming Maester release.

Check it out at 👇

youtu.be/kmegnNSM0KM?t=275

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-04

Have you checked out this week's Entra newsletter?

Get the latest at entra.news

#entraid #cybersecurity #iam

⚡️ Microsoft
🏆 General Availability
Use managed identities as credentials in Microsoft Entra apps • Microsoft Learn

🔥 Public Preview
Microsoft Entra Conditional Access optimization agent • Microsoft Learn

Conditional Access What If evaluation API • Microsoft Learn

Manage refresh tokens for mover and leaver scenarios with Lifecycle Workflows • Microsoft Learn

🏁 Plan for change
Roll out of Application Based Authentication on Microsoft Entra Connect Sync • Microsoft Learn

📖 Read
Pushing passkeys forward: Microsoft’s latest updates for simpler, safer sign-ins • Joy Chik, Vasu Jakkal
Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-03

Hmm...

Guess, I'll need to add Guiness World Record holder to my LinkedIn bio 😂

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-02

What better person to answer the 100+ questions I had about this feature than Anju Singh herself, the Product Manager for the QR code feature at Microsoft.

Get it on your favourite podcast player @ entra.chat/ or search for Entra Chat to watch on YouTube.

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-02

Folks, this week's Entra Chat 🎙️ podcast episode is out and it's all about QR Code auth.

The newest kid on the block when it comes to Entra's Authentication methods!!

🧵👇

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-02

Please re-share. Let's make our repos safer.

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-02

It stops anyone from accidentally pushing secrets into your repo which could result in their/your org being compromised.

For more details about this feature see docs.github.com/en/code-securi

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-02

PSA: Every open source project you work on should have GitHub's

🛡️ Secret Protection and
🛡️ Push Protection

Set to Enabled ✅

Why do this? 👇

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-05-01

Are you using all of the Microsoft 365 P2 features you are licensed for?

I'll be joining Matt & Dom next week to share some tricks and tips to help you get the most out of your Entra P2 license.

Hit the Notify button to cue this up when it lands.

youtube.com/live/kmegnNSM0KM

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-04-30

The #1 ask has been for you to be able to define your own Severity levels and override the default.

It's going to be as simple as providing a json file with your custom ratings.

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-04-30

Using AI to do the first round Severity ratings for 🔥 Maester tests.

Merill Fernando :verified: :donor:merill@infosec.exchange
2025-04-29

This is what I love about 🔥 Maester and having the tests be open source.

Matthias, noticed the test failing and helped improve it when admins accounts are set up with least privilege.

MS.AAD.2.2 tests that RiskyUserAlerts are sent to administrator.
We got that reported as failed although we have multiple administrators configured.

Actual Behaviour

Test-MtCisaNotifyHighRisk.ps1 checks Graph URI "identityProtection/settings/notifications"
it only checks the response property notificationRecipients [Array] to be greater / equal 1
notificationRecipients is managed automatically by Entra based on Role assignments
in our environment these priveleged roles are assigned to separate accounts based on a user account tiering model which are not used for notification triggers / communication
hence we disabled all these entries --> policy is failing
Expected Behavior

There is an additional property called additionalRecipients that has the same structure and should be considered in the test as well. The test is about having administrator notified and not only about "having role owners notified" ;-)

Best,
Matthias

P.S.: handed in PR #861

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst