Identity
57 TopicsDeactivating Option to change Profile Picture at myaccount.microsoft.com
As the title says. I would like to deactivate the option for users to change their profile picture at myaccount.microsoft.com. The profile picture at our company is synchronized to AD and via Entra Connect to Entra ID. Is there an option as an admin to deactivate that option without deactivating the entire portal? Kind Regards Christopher Siebertz186Views1like4CommentsUnlink a users workplace join account while device is also Entra ID joined
We have a number of users on Entra ID joined devices that were prompted to register their devices when signing into teams with another org account. My question has two parts - how can we programmatically remove the Workplace Join account and how do we avoid users from doing it again?1.2KViews0likes4CommentsForce additional MFA for PIN WH4B
so got a request from one of my clients and if you think about it, its on the verge of being valid but an edge case... Lets say you implement WH4B and leverage PIN, how do you prevent someone shoulder surfing and leveraging the PIN on that device if they take it? Or restrict pin patterns? (the patterns I am looking into) I know Fido2 is the best way along with biometrics...but they were wondering if there was a way to reprompt MS Auth App for a code after login/reboot... I couldnt find anything on this but I did find forcing a mfa device revalidation via graph api Any able to accomplish this with the entra joined device?23Views0likes1CommentMFA Rollout Question(s)
Hi All I hope you are well. Anyway, I'm normally more active in the Intune space but I have been tasked with rolling out MFA to a lot of non technical users. One of the questions is: What if I forget my phone with the MS Authenticator app on it? I can't seem to find any documentation or clear answer to this. Any ideas? SK44Views0likes3CommentsUser with hundreds of Interactive Sign-In log entries that are "Interrupted"
I have one user in our organization that has hundreds of Interactive Sign-in logs in EntraID that are marked as "Interrupted". I don't even know where to start with the user. Does anyone have a recommendation for isolating the cause of these logs? Recent entries are 95% related to Office Online Core SSO application.290Views0likes4CommentsProvide accounts for Microsoft Authenticator centrally
In our IT department, we manage our mobile devices with Microsoft Intune. We have a group of maintenance employees who need access to production machines on the shopfloor using mobile devices. The access to these machines are static users or OTP-based access. Now I would like to provide all maintenance employees and their mobile devices with the Microsoft Authenticator and provide all accesses for these machines as preconfigured accounts. Is this possible with Intune or another option? I don't want to make the Microsoft Authenticator app available to the maintenance staff (we've already managed that), but rather defined accounts for all Microsoft Authenticator clients.34Views1like1CommentCA policy for corporate devices
I would like to create a conditional access policy to block all non corporate devices from accessing Office 365 resources. I created a policy: Applies to -> User Group Applies to -> all resources Applies to -> Win 10 Filter for devices exception-> Ownership: company & trust type: Entra Hybrid joined. Action: block The above works fine for office desktop login, i.e. blocks non corporate devices and allows corporate devices. However, a side effect is that sign ins from browser on a corporate device is still blocked.76Views1like7CommentsMicrosoft Authenticator Passkeys for Entra ID on unmanaged devices
Hello, has anyone successfully registered passkeys on an unmanaged phone in an organisation with device compliance policies? Use case is to provide a phishing-resistant MFA option via Authenticator app for logging into apps on their desktop. Users already have authenticator app on their phone and do number matching MFA. https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-register-passkey-authenticator?tabs=iOS When I select "Create a passkey" - I need to log into my account. However I'm blocked from successful authentication because I have conditional access policies to require compliant devices. As my mobile phone is not enrolled into Intune, I never get to the step where the passkey is created and registered. Based on the constraints - it seems like passkeys cannot be used for unmanaged/BYOD devices for organisations that have device compliance policies. It can only be used for users who have enrolled their mobile phone. Looking to see if anyone has tips or different experience using passkeys on unmanaged mobile phones to log into Entra?82Views0likes0CommentsHow to add Passkey for Entra ID / M365 Identity to Windows Hello or third-party password manager?
I manage many M365 tenants and can't add all of them to Windows as an account. Because of this I would like to add passkeys for those accounts to either a third-party password manager or (preferred) Windows Hello. So far I haven't found a way to do this. The passkey dialog at https://mysignins.microsoft.com/security-info only allows me to add a passkey to a physical key. So: So how can I add M365 passkeys to Windows Hello?99Views1like3CommentsTicketing System for Clients
Hello everyone and greetings from Portugal! So, I work at a startup that at the moment has a nice number of clients, both in Portugal and in the US. We're feeling the need to have a ticketing system and I was wondering if anyone can give some suggestions. Not a lot of requisites but would be great if it integrates/allows multi-tenant support so users from different oganizations can SSO. And the ability for the system to get user information from Entra ID (like UPN, etc) and associated device (managed by Intune) would be great. And...writing this post I got wondering if I should be looking only for ticketing system or other tool with more features. All my clients are "cloud native", no physical servers, and all devices managed via Intune. Thanks to all in advance!Solved2.1KViews0likes5Comments