Forum Widgets
Latest Discussions
Token replay question
I had a case of a user being phished and their token being used in a replay attack. The replay appeared in the sign in logs from a different IP address to the "true" users IP. I then saw activity on the account originating from the original IP until we killed the session a few hours later. I had someone suggest that in a token replay the M365 audit\activity logs and Entra ID signing logs will show the original persons IP, not the attackers. Can anyone confirm this?lfk73Jun 23, 2025Copper Contributor39Views0likes2CommentsBest setup for multiple machines
I have a live account for my email address as I have a surface and originally registered for an account to use for machine backups, browsing syncing etc. I also use onenote and wanted it syncing to a 365 onedrive account so I signed up for office 365 business basics so that I could sync onedrive and all of the associated attachments, audio records etc to it. I would love to use use the paid business account but I cant sign into the surface with the business account, only home accounts as I dont have pro. The next issue is that I use another laptop, android tablet and phone also signing into the business 365 account. These all used to sync fine but now, all other devices disconnect as the one you have signed into it connects. Not a major issue, you sign into the device you want to use, sync and then continue However i jump from device to device that often that it starts to grate on me that i cant just grab a device and sync. Is there any way I can register each device so that they are trusted and then more than one device can stay connected.devswap79Jun 23, 2025Copper Contributor46Views1like1CommentWeb Sign-In: Alert QR Code/Code for Mobile
Had 2FA turned off in the work account, on the web login screen a reminder only a few logins allowed without the Authenticator. Fair enough so instead of logging in, got out the Android tablet and installed the Authenticator and logged in with the account there, no problems. A few minutes later attempted to log in to the account on web, this time it presented a QR code with the link "phonefactor:/activateaccount .... mobileappcommunicator.auth ..." which didn't seem to go well in Android using QR scanner or camera. The web login suggested an alternative to the QR code, an 8? digit code, but nothing in the Authenticator app seemed to want it. All of a sudden everything seems to work fine, the web login (with a note that 2FA was used in the login) and the Authenticator on the tablet, thus turning out as a good news ending to a slightly shaky start. :)lmstearnMar 26, 2025Copper Contributor85Views0likes2CommentsEvolution with business account (oauth2)
Recently domainFactory migrated mail to Microsoft 365 business accounts. I used to use the Evolution mail client (Fedora Linux, flatpak version) for mail. Unfortunately I am not able to login to my account with Evolution. You can find my discussion here: https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/515#note_2384010 I also noticed that the login is no problem with a personal account. Does anybody have experience with this?fansariMar 22, 2025Copper Contributor471Views0likes5CommentsEntra-ID Privileged Identity Management for Groups
We have used PIM for groups to assign certain Azure Security groups to eligible users. For example a group which provides the contributor role to a certain subscription. This group is added in PIM for groups, and eligible users have been assigned to the group, in which they can provide themselves with the privileges if required to do so for maximum 8 hours. However, when we assign a user to a PIM protected group, then there is no way to tell from the user's properties, that the user has been assigned (eligible) to a PIM protected group. Therefore wouldn't it be better to create PIM groups and add the assigned user as a member of a PIM group, and assign the PIM group as eligible to the PIM protected group? Then you would able to see from the Groups list if the user is illegible for any PIM groups.TherealKillerbeMar 18, 2025Copper Contributor251Views0likes3CommentsCan't access Intune Company Portal from Android device after enabling Phishing resistant MFA
HI, Since I enabled Phishing resistant MFA in my tenant, I have been unable to access the company portal on my android phone. Login starts the auth process, but the app keeps telling me that it doesn't support pass keys. If this is the case, is the way that I can exclude the app from my CA policy to allow me to install apps that I have made available to the device? Kind Rgds Leeilmaestro7Mar 03, 2025Copper Contributor75Views0likes2CommentsForce additional MFA for PIN WH4B
so got a request from one of my clients and if you think about it, its on the verge of being valid but an edge case... Lets say you implement WH4B and leverage PIN, how do you prevent someone shoulder surfing and leveraging the PIN on that device if they take it? Or restrict pin patterns? (the patterns I am looking into) I know Fido2 is the best way along with biometrics...but they were wondering if there was a way to reprompt MS Auth App for a code after login/reboot... I couldnt find anything on this but I did find forcing a mfa device revalidation via graph api Any able to accomplish this with the entra joined device?RussMeyer-EpikFeb 27, 2025Copper Contributor61Views0likes1CommentMFA Rollout Question(s)
Hi All I hope you are well. Anyway, I'm normally more active in the Intune space but I have been tasked with rolling out MFA to a lot of non technical users. One of the questions is: What if I forget my phone with the MS Authenticator app on it? I can't seem to find any documentation or clear answer to this. Any ideas? SKStuartK73Feb 24, 2025Steel Contributor95Views0likes3CommentsDeactivating Option to change Profile Picture at myaccount.microsoft.com
As the title says. I would like to deactivate the option for users to change their profile picture at myaccount.microsoft.com. The profile picture at our company is synchronized to AD and via Entra Connect to Entra ID. Is there an option as an admin to deactivate that option without deactivating the entire portal? Kind Regards Christopher SiebertzSolvedCSIFeb 21, 2025Copper Contributor1.2KViews1like4CommentsAuthenticator App for visionOS Apple Vision Pro
Please add more options to visionOS version. I want to sign in with my personal account and synchronize my TOTP tokens and passwords into the visionOS so that I do not have to open my phone while wearing the headset (huge pain since the iphone app requires face unlock which does NOT work when wearing the headset). Also please support retina unlock in the visionOS app. Also support authenticator request approvals from inside the visionOS app.whatisinanameFeb 03, 2025Copper Contributor136Views1like3Comments
Resources
Tags
- Authentication328 Topics
- office 365214 Topics
- security155 Topics
- admin63 Topics
- Identity58 Topics
- multi-factor authentication49 Topics
- Azure AD43 Topics
- exchange42 Topics
- Microsoft 365 Apps37 Topics
- hybrid35 Topics