<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Entra topics</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-entra/bd-p/microsoft-entra</link>
    <description>Microsoft Entra topics</description>
    <pubDate>Wed, 29 Jul 2026 18:43:43 GMT</pubDate>
    <dc:creator>microsoft-entra</dc:creator>
    <dc:date>2026-07-29T18:43:43Z</dc:date>
    <item>
      <title>Verifying domain name issue</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/verifying-domain-name-issue/m-p/4541541#M10423</link>
      <description>&lt;P&gt;We're trying to verify our custom domain in Entra ID, but it turns out the domain is already claimed on another tenant that we have no access to (unknown account, no admin credentials). Because of that, verification on our own tenant fails.&lt;/P&gt;&lt;P&gt;Normally the fix for a claimed-domain conflict is to open a support request so Microsoft can help release it. The problem: doing that requires a support plan, and purchasing one doesn't work for us. "payment" always succeeds and we dont get an error, but we don't get charged and the account status doesn't change, we have nothing more to go on.&lt;/P&gt;&lt;P&gt;So we're stuck in a loop: we need support to release the domain, but we can't buy the support plan needed to reach support.&lt;/P&gt;&lt;P&gt;Has anyone dealt with a domain claimed on an inaccessible tenant? And is there another route to Microsoft support when the support plan purchase itself fails?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 11:34:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/verifying-domain-name-issue/m-p/4541541#M10423</guid>
      <dc:creator>I-Leadership</dc:creator>
      <dc:date>2026-07-28T11:34:53Z</dc:date>
    </item>
    <item>
      <title>Best practices: Open OneDrive/SharePoint sharing but restrict Teams guest access by domain</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/best-practices-open-onedrive-sharepoint-sharing-but-restrict/m-p/4540110#M10414</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Since SharePoint Online and OneDrive moved fully to Microsoft Entra B2B for external sharing, we've run into a policy conflict and would like to hear how others are handling it.&lt;/P&gt;&lt;H4&gt;Our requirements&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Enable OneDrive and SharePoint file sharing with external users, regardless of their email domain.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Restrict Microsoft Teams guest access to a predefined list of approved partner domains.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Continue allowing Teams external access (federated chat and meetings) for all domains.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;The problem:&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;Teams guests, SharePoint guests, and OneDrive guests are now governed by the same Microsoft Entra B2B invitation framework and the single&amp;nbsp;&lt;STRONG&gt;Collaboration restrictions&lt;/STRONG&gt; allow/deny list under:&lt;BR /&gt;&lt;STRONG&gt;External Identities → External collaboration settings&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;As a result, restricting guest invitations by domain also restricts OneDrive and SharePoint sharing for domains not on the allowlist.&lt;/LI&gt;&lt;LI&gt;According to Microsoft's response in the following Q&amp;amp;A, this behavior is currently &lt;STRONG&gt;by design&lt;/STRONG&gt;:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/5954975/onedrive-external-sharing-no-longer-working-with-a" target="_blank"&gt;OneDrive external sharing no longer working with "Allow invitations only to the specified domains" - Microsoft Q&amp;amp;A&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;Questions to the community&lt;/H4&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Has anyone implemented a solution where OneDrive/SharePoint sharing remains open to all domains while Teams guest access is restricted to approved domains only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there recommended approaches using Entitlement Management, Access Packages, Connected Organizations, or other Entra capabilities?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Is there any roadmap item for workload-specific collaboration restrictions (e.g., separate policies for Teams guest invitations and SharePoint/OneDrive sharing)?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any real-world experience or best practices would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bejhan&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 05:49:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/best-practices-open-onedrive-sharepoint-sharing-but-restrict/m-p/4540110#M10414</guid>
      <dc:creator>Bejhan</dc:creator>
      <dc:date>2026-07-24T05:49:11Z</dc:date>
    </item>
    <item>
      <title>Is system-preferred first factor overriding Single Sign-On?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/is-system-preferred-first-factor-overriding-single-sign-on/m-p/4538363#M10396</link>
      <description>&lt;P&gt;My colleagues and I have noticed that we've started being prompted to perform a Windows Hello for Business authentication when we use Edge to access web resources that are authenticated with Entra. Previously, this authentication occurred silently through Single Sign-On with the PRT, per&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa" target="_blank"&gt;Understanding Primary Refresh Token (PRT) in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;While investigating what might have caused this change in behavior, I found&amp;nbsp;&lt;A class="lia-external-url" href="https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1411574" target="_blank"&gt;MC1411574&lt;/A&gt; in the M365 Message Center, which talks about a change to system-preferred authentication that started rolling out in late June 2026, whereby it now applies to the first factor as well as multi-factor authentication.&amp;nbsp;I excluded myself from system-preferred authentication and sure enough, that seems to have restored the previous behavior.&lt;/P&gt;&lt;P&gt;Is it intended that this change to system-preferred authentication will disable SSO, or do we have something misconfigured?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2026 23:02:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/is-system-preferred-first-factor-overriding-single-sign-on/m-p/4538363#M10396</guid>
      <dc:creator>RyanSteele-CoV</dc:creator>
      <dc:date>2026-07-17T23:02:31Z</dc:date>
    </item>
    <item>
      <title>Looking for an on-prem MFA solution for Active Directory and RDP</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/looking-for-an-on-prem-mfa-solution-for-active-directory-and-rdp/m-p/4537446#M10388</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We're reviewing options for adding MFA to our on-premises Active Directory environment.&lt;/P&gt;&lt;P&gt;Most of our users authenticate with Active Directory, while administrators also use RDP for managing Windows servers.&lt;/P&gt;&lt;P&gt;Because part of our infrastructure is isolated from the Internet, we'd prefer an on-premises MFA solution instead of relying on a cloud-only service.&lt;/P&gt;&lt;P&gt;Has anyone implemented something similar recently?&lt;/P&gt;&lt;P&gt;I'm interested in hearing:&lt;/P&gt;&lt;P&gt;Which solution did you choose?&lt;BR /&gt;How difficult was the deployment?&lt;BR /&gt;Did you run into any compatibility or performance issues?&lt;BR /&gt;Is there anything you'd do differently if you were deploying it again?&lt;/P&gt;&lt;P&gt;Any real-world experience or recommendations would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2026 18:07:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/looking-for-an-on-prem-mfa-solution-for-active-directory-and-rdp/m-p/4537446#M10388</guid>
      <dc:creator>Grey_ai1</dc:creator>
      <dc:date>2026-07-15T18:07:23Z</dc:date>
    </item>
    <item>
      <title>Can the built-in "No account? Create one" link redirect to a custom sign-up page?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/can-the-built-in-quot-no-account-create-one-quot-link-redirect/m-p/4536451#M10386</link>
      <description>&lt;P&gt;I'm using Microsoft Entra External ID with a built-in sign-in/sign-up user flow.&lt;/P&gt;&lt;P&gt;On the Microsoft-hosted sign-in page, the "No account? Create one" link always redirects users to the default Entra sign-up page.&lt;/P&gt;&lt;P&gt;I already have a custom registration page and would like this built-in link to redirect to my custom URL instead.&lt;/P&gt;&lt;P&gt;Is there any supported way to customize the destination of this link in a built-in user flow? If not, could someone confirm whether this behavior is fixed by design?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 10:13:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/can-the-built-in-quot-no-account-create-one-quot-link-redirect/m-p/4536451#M10386</guid>
      <dc:creator>Lipikasree</dc:creator>
      <dc:date>2026-07-13T10:13:42Z</dc:date>
    </item>
    <item>
      <title>Using Cloud sync to sync AD to existing Entra Accounts</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/using-cloud-sync-to-sync-ad-to-existing-entra-accounts/m-p/4535450#M10369</link>
      <description>&lt;P&gt;I want to sync in premise AD accounts with existing Entra accounts. The email on both accounts is the same, and I added the Entra/o365 suffix to the domain and set the UPN to that suffix, making both UPN(s) the same. It did not sync. It created a NEW Entra account. I thought I covered all my bases.&lt;BR /&gt;&lt;BR /&gt;How can I get on premise AD and existing Entra accounts to sync?&lt;BR /&gt;&lt;BR /&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2026 22:32:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/using-cloud-sync-to-sync-ad-to-existing-entra-accounts/m-p/4535450#M10369</guid>
      <dc:creator>tjcooper2</dc:creator>
      <dc:date>2026-07-09T22:32:31Z</dc:date>
    </item>
    <item>
      <title>Group-Based Licensing (E3 → Business Premium): MutuallyExclusiveViolation – Months Unresolved</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/group-based-licensing-e3-business-premium/m-p/4534721#M10362</link>
      <description>&lt;P&gt;We operate a Microsoft 365 environment with Entra ID, Intune, and Exchange Online. For &lt;STRONG&gt;months&lt;/STRONG&gt;, we have been dealing with a critical issue that remains unresolved to this day — despite an active Microsoft Support ticket.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Technical Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;During the migration of approximately 87 user accounts from Microsoft 365 E3 to Business Premium (SPB) via group-based licensing in Entra ID, all affected accounts receive a MutuallyExclusiveViolation error. Microsoft's backend treats E3 and Business Premium as mutually exclusive, blocking the SPB assignment — despite sufficient licenses being available.&lt;/P&gt;&lt;P&gt;A sequential approach (removing E3 first, then assigning Business Premium) is not an acceptable solution: a test run proved that this causes a complete loss of Exchange Online access. For a rollout across 87 productive user accounts, this is not viable. What is required is a &lt;STRONG&gt;seamless, atomic license swap at the backend level&lt;/STRONG&gt; — exclusively via group-based licensing.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Support Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Two support engineers&lt;/STRONG&gt; assigned — zero technical progress.&lt;/LI&gt;&lt;LI&gt;Instead of a substantive solution, we received &lt;STRONG&gt;standard documentation steps&lt;/STRONG&gt; that do not address the actual problem.&lt;/LI&gt;&lt;LI&gt;A &lt;STRONG&gt;false resolution notice&lt;/STRONG&gt; was issued — the issue had demonstrably not been resolved. Our own PowerShell tests (Get-MgUser, Get-MgSubscribedSku) and CSV exports from the Entra ID portal disproved this conclusively.&lt;/LI&gt;&lt;LI&gt;Committed updates from the Engineering Team were &lt;STRONG&gt;not delivered&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Instead, &lt;STRONG&gt;automatically generated follow-up emails&lt;/STRONG&gt; were sent with no substantive relation to the ongoing case.&lt;/LI&gt;&lt;LI&gt;An additional unexplained behavior: a test user appears in the error report of a license group they were &lt;STRONG&gt;never added to&lt;/STRONG&gt; — a further backend inconsistency that has not been investigated.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Current Status:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The ticket has been open for months. 87 user accounts cannot be migrated to Business Premium. An escalation to the Team Manager has been initiated. No resolution is in sight.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Question to the Community:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced a similar issue with MutuallyExclusiveViolation in group-based licensing (E3 → Business Premium)? Is there a known workaround or an official Microsoft statement on this?&lt;/P&gt;&lt;P&gt;Ticket Reference: &lt;STRONG&gt;#2604241410000669&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 06:32:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/group-based-licensing-e3-business-premium/m-p/4534721#M10362</guid>
      <dc:creator>DanielZieb</dc:creator>
      <dc:date>2026-07-08T06:32:59Z</dc:date>
    </item>
    <item>
      <title>Made a self-hosted Entra ID governance portal for app/identity sprawl (open source)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/made-a-self-hosted-entra-id-governance-portal-for-app-identity/m-p/4533415#M10353</link>
      <description>&lt;P&gt;Our tenant ended up with hundreds of app registrations and enterprise apps, and the native portal makes you dig through a separate blade for every basic question. Who owns this app? Which secrets die next month? What hasn't been signed into in a year? Which ones have scary Graph permissions? There's no single view for any of it, and half the ownership info was missing anyway.&lt;/P&gt;&lt;P&gt;Entra ID Governance, access reviews, PIM all exist, but they felt heavy (and licensed) for what I actually wanted, which was just a fast list I could scan for routine cleanup.&lt;/P&gt;&lt;P&gt;So I built one. Lightweight portal that runs entirely in your own subscription:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;One grid for App Registrations, Enterprise Apps, Managed Identities and Privileged Users&lt;/LI&gt;&lt;LI&gt;Risk flags per identity: expiring/expired creds, high-risk permissions, no owner, stale sign-in, no CA coverage&lt;/LI&gt;&lt;LI&gt;Ownership tracking, review and owner-change workflow, CSV export&lt;/LI&gt;&lt;LI&gt;Tenant health score and a consent posture dashboard&lt;/LI&gt;&lt;LI&gt;Optional expiry email notifications (needs a SendGrid key)&lt;/LI&gt;&lt;LI&gt;Reads Graph through a managed identity, so no app secrets for data access and nothing leaves your tenant&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Runs about $26-30/month (one B2 App Service plan). B1 is also supported, but it's noticeably slower.&lt;/P&gt;&lt;P&gt;It's not a replacement for Entra ID Governance or PIM, more of a cheap everyday hygiene thing.&lt;/P&gt;&lt;P&gt;Full disclosure, I used AI building this and writing this up. I designed the architecture and functionality, tested it and ran it against my own tenant. It's open source and deployable with Azure DevOps or an Azure CLI script. Data never leaves your own tenant.&lt;/P&gt;&lt;P&gt;Repo (screenshots + setup): &lt;A class="lia-external-url" href="https://github.com/nicolaibaralmueller/entra-identity-governance-portal" target="_blank"&gt;Github Repository&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Would love feedback, especially what you'd want it to flag that it doesn't, or where the risk scoring feels off. Been building it on and off for a few months with a lot of iteration. Hopefully this could be useful for others as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2026 08:46:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/made-a-self-hosted-entra-id-governance-portal-for-app-identity/m-p/4533415#M10353</guid>
      <dc:creator>AzAutomationEngineer</dc:creator>
      <dc:date>2026-07-03T08:46:42Z</dc:date>
    </item>
    <item>
      <title>EntraID integration with Biostar 2</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/entraid-integration-with-biostar-2/m-p/4531322#M10352</link>
      <description>&lt;P&gt;Hi all, I have issue integrate entra ID with biostar. The sync keep fail, anyone have done the integration before? Need advise on the integration steps. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 12:05:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/entraid-integration-with-biostar-2/m-p/4531322#M10352</guid>
      <dc:creator>SancroNelly</dc:creator>
      <dc:date>2026-06-26T12:05:16Z</dc:date>
    </item>
    <item>
      <title>Best approach to detect multiple user accounts signing in from the same physical device</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/best-approach-to-detect-multiple-user-accounts-signing-in-from/m-p/4532446#M10348</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;Working on environment: D365 Finance &amp;amp; Operations (cloud).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Goal:&lt;BR /&gt;I need to detect when more than one Dynamics user account is being used&lt;BR /&gt;from the same physical device, and ideally count how many distinct users&lt;BR /&gt;are active on that device. The business reason is this is not permissible to login with more than one account in the same device.&lt;BR /&gt;&lt;BR /&gt;For example:&lt;BR /&gt;User X has device D1, User Y has device D2.&lt;BR /&gt;User X logged in with his account using Device D2 (which is user's Y device).&lt;BR /&gt;&lt;BR /&gt;I want to know if this happened, cause it's not permissible behavior in the organization.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For more illustration some users have blank devices id when I see Microsoft Entra.&lt;BR /&gt;&lt;BR /&gt;Or if I could find out when a user logs in and integrate it with D365 F&amp;amp;O to store the device the user logged into in a custom log table or anything that tells me that this user account is opened on more than one device or this device has more than one logged-in user account.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 09:10:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/best-approach-to-detect-multiple-user-accounts-signing-in-from/m-p/4532446#M10348</guid>
      <dc:creator>RaedSalah</dc:creator>
      <dc:date>2026-07-01T09:10:12Z</dc:date>
    </item>
    <item>
      <title>Registering user becomes local admin on Joined Devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/registering-user-becomes-local-admin-on-joined-devices/m-p/4531078#M10346</link>
      <description>&lt;P&gt;This setting works exactly as named, but the confusion is understandable because the privilege is invisible in the places people normally look.&lt;/P&gt;&lt;P&gt;Per Microsoft's official docs (assign-local-admin): at the moment of Microsoft Entra join, &lt;STRONG&gt;two&lt;/STRONG&gt; principals get added to the local administrators group — the &lt;STRONG&gt;Microsoft Entra Joined Device Local Administrator role&lt;/STRONG&gt; and the &lt;STRONG&gt;user performing the join&lt;/STRONG&gt;. This happens &lt;EM&gt;only during the join operation itself&lt;/EM&gt;. It's not a directory role assignment, so it won't show up in role assignments, audit logs, or under "Device Administrators" — that's by design.&lt;/P&gt;&lt;P&gt;Critically: &lt;STRONG&gt;users aren't directly listed in the local admin group; the privilege is delivered through the Primary Refresh Token (PRT)&lt;/STRONG&gt; at sign-in. So:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;To validate on the device itself, sign in as the user and run whoami /groups — you should see the device-local Administrators SID.&lt;/LI&gt;&lt;LI&gt;If you just changed the setting and want to force re-evaluation, run dsregcmd /refreshprt, then &lt;STRONG&gt;sign out and back in&lt;/STRONG&gt; (lock/unlock won't trigger it — you need a fresh PRT, which can take up to ~4 hours to propagate otherwise).&lt;/LI&gt;&lt;LI&gt;This setting only applies to &lt;STRONG&gt;joined&lt;/STRONG&gt; devices, not registered (workplace-joined) ones — so your distinction there is correct.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The "Manage Additional local administrators on all Microsoft Entra joined devices" link is a &lt;EM&gt;separate, tenant-wide&lt;/EM&gt; mechanism (the same Device Administrator role) — it can't be scoped to specific devices, which is also worth knowing if you're trying to limit blast radius.&lt;/P&gt;&lt;P&gt;If you want to stop this going forward for new joins without ripping out existing admins, set "Registering user is added as local administrator" to &lt;STRONG&gt;None&lt;/STRONG&gt;, and consider a Windows Autopilot profile or Intune &lt;STRONG&gt;Local Users and Groups&lt;/STRONG&gt; policy to manage membership going forward — existing devices won't be retroactively changed.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 20:16:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/registering-user-becomes-local-admin-on-joined-devices/m-p/4531078#M10346</guid>
      <dc:creator>gokhantatar</dc:creator>
      <dc:date>2026-06-25T20:16:24Z</dc:date>
    </item>
    <item>
      <title>PHS staged rollout works for existing users but not new synced users</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/phs-staged-rollout-works-for-existing-users-but-not-new-synced/m-p/4530759#M10345</link>
      <description>&lt;P&gt;We are troubleshooting an Entra ID PHS staged rollout issue with a federated domain using a third-party WS-Fed IdP.&lt;/P&gt;&lt;P&gt;The intended behavior is that normal federated users redirect to the IdP, while users in the PHS staged rollout group receive the Microsoft/Entra password prompt instead.&lt;/P&gt;&lt;P&gt;Existing users in the staged rollout group continue to work correctly. They enter their UPN and receive the Microsoft password prompt. One known-good test user is not provisioned in the third-party IdP and still signs in successfully through the Entra password prompt, so the working path does not require the user to exist in the IdP.&lt;/P&gt;&lt;P&gt;The issue is only with newly created AD-synced users. Newly synced users in the same staged rollout group are still being routed to the federated IdP at HRD instead of receiving the Entra password prompt.&lt;/P&gt;&lt;P&gt;We’ve verified the staged rollout policy and group membership from Graph, confirmed the affected users are properly AD-synced with clean immutableID/sourceAnchor, and confirmed PHS is working. Federation metadata and HRD policies also look clean. Seamless SSO/AZUREADSSOACC was checked and remediated, but the behavior did not change.&lt;/P&gt;&lt;P&gt;For failed attempts, there is no Entra sign-in log entry, including tenant-wide interactive and non-interactive logs. However, the federated IdP logs show a WS-Fed inbound request from login.microsoftonline.com for the affected user. That makes it look like Entra HRD is routing the user to federation before sign-in logging or token issuance.&lt;/P&gt;&lt;P&gt;The issue started around an Entra Connect AD connector/DC-path change. We have since reverted the connector to the previous known-good configuration. After reverting, we created a clean-room test user with the correct UPN set before first sync, confirmed sync/PHS/sourceAnchor, added the user directly to the staged rollout group, and waited 60+ minutes. The clean-room user still redirected to the federated IdP instead of getting the Entra password prompt.&lt;/P&gt;&lt;P&gt;So the current behavior is that established staged-rollout users still get the Entra password prompt, but newly created synced staged-rollout users are sent to the federated IdP by HRD.&lt;/P&gt;&lt;P&gt;Has anyone seen staged rollout get into this state, where existing users work but new synced users remain on the federated HRD path despite valid rollout policy, group membership, synced password hash, and clean immutableID/sourceAnchor? Is there any known backend cache/state reset or escalation path for HRD/staged rollout routing?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 00:01:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/phs-staged-rollout-works-for-existing-users-but-not-new-synced/m-p/4530759#M10345</guid>
      <dc:creator>mdoraz</dc:creator>
      <dc:date>2026-06-25T00:01:42Z</dc:date>
    </item>
    <item>
      <title>TAP requires step-up MFA when user already has a passkey registered — expected behavior?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/tap-requires-step-up-mfa-when-user-already-has-a-passkey/m-p/4528814#M10334</link>
      <description>&lt;P&gt;Environment&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Microsoft 365 Business Premium (Entra ID P1)&lt;/LI&gt;&lt;LI&gt;Cloud-only tenant&lt;/LI&gt;&lt;LI&gt;Authentication methods enabled: FIDO2/Passkey only + TAP&lt;/LI&gt;&lt;LI&gt;All other methods disabled (no Authenticator push, no TOTP, no SMS)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;CA Policy configuration&lt;/P&gt;&lt;P&gt;CA001 — Protect Security Info Registration&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Target: User action — Register security information&lt;/LI&gt;&lt;LI&gt;Grant: Custom authentication strength "Bootstrap and Recovery" (TAP one-time + TAP multi-use + Passkey/FIDO2 + WHfB/Platform credential)&lt;/LI&gt;&lt;LI&gt;Status: On&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;CA002 — Require Phishing-Resistant Authentication&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Target: All cloud apps (excluding Azure Credential Configuration Endpoint and tested also excluding Microsoft App Access Panel)&lt;/LI&gt;&lt;LI&gt;Grant: Built-in Phishing-resistant MFA&lt;/LI&gt;&lt;LI&gt;Status: On&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What was tested&lt;/P&gt;&lt;P&gt;Scenario 1 — User with no registered methods (only with Platform credential):&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Admin issues TAP (multi-use, 4 hours)&lt;/LI&gt;&lt;LI&gt;User navigates to aka.ms/mysecurityinfo&lt;/LI&gt;&lt;LI&gt;User authenticates with TAP&lt;/LI&gt;&lt;LI&gt;Result: Access granted — user can register passkey without any step-up, even in a flow authenticating directly to a resource (such as Microsoft Teams in browser)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Scenario 2 — User with an existing portable passkey already registered (in MS Authenticator):&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Admin issues TAP (multi-use, 4 hours)&lt;/LI&gt;&lt;LI&gt;User navigates to aka.ms/mysecurityinfo&lt;/LI&gt;&lt;LI&gt;User authenticates with TAP&lt;/LI&gt;&lt;LI&gt;Result: Entra requests a second factor — specifically the existing passkey — before allowing access to My Security Info. Seems the system enforces CA002 or a platform-level step-up requirement.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The TAP is accepted as a first factor, but the platform then requires the existing passkey as a second factor before proceeding.&lt;/P&gt;&lt;P&gt;Sign-in log analysis: The behavior does not appear in the Conditional Access tab of the sign-in logs as a CA policy failure — it appears to be enforced at the platform level, not by any configured CA policy.&lt;/P&gt;&lt;P&gt;Questions&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is it by design that when a user already has a registered MFA-capable method (passkey), the platform enforces step-up authentication before allowing access to My Security Info — even when the user authenticates with a valid TAP?&lt;/LI&gt;&lt;LI&gt;If so, does the correct recovery procedure require the admin to first remove all existing authentication methods before issuing a TAP — so the user has no registered methods and the TAP is accepted without step-up?&lt;/LI&gt;&lt;LI&gt;Is there any way to allow TAP to bypass this step-up requirement for recovery scenarios, without removing existing methods first?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any pointers to official documentation or confirmed behavior would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 10:24:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/tap-requires-step-up-mfa-when-user-already-has-a-passkey/m-p/4528814#M10334</guid>
      <dc:creator>ivofernandes</dc:creator>
      <dc:date>2026-06-17T10:24:00Z</dc:date>
    </item>
    <item>
      <title>Entra ID Governance vs Saviynt for SAP IGA Use Cases</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/entra-id-governance-vs-saviynt-for-sap-iga-use-cases/m-p/4523348#M10330</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We are currently evaluating Microsoft Entra ID Governance as a potential replacement for Saviynt for SAP-focused IGA requirements across a mixed SAP landscape, including:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SAP SuccessFactors&lt;/LI&gt;&lt;LI&gt;SAP Concur&lt;/LI&gt;&lt;LI&gt;SAP S/4HANA Private Cloud&lt;/LI&gt;&lt;LI&gt;Other SAP SaaS and enterprise applications&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I wanted to get insights from anyone who has implemented or worked extensively with Entra Governance in SAP-centric environments, specifically around the following areas:&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;1. Birthright RBAC Provisioning&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Can Entra Governance provision a single composite/business role (similar to Saviynt Enterprise Roles) through HR-driven JML events?&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HR event triggers provisioning&lt;/LI&gt;&lt;LI&gt;User automatically receives bundled SAP access/business roles&lt;/LI&gt;&lt;LI&gt;Role assignment follows birthright/access package logic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;How mature/scalable is this approach in Entra compared to Saviynt?&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;2. SoD (Segregation of Duties) Capabilities&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Saviynt supports preventative SoD checks directly during request submission, including SAP-specific SoD analysis.&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Does Entra Governance support preventative SoD evaluation at request time?&lt;/LI&gt;&lt;LI&gt;Can conflicts be surfaced before approval/provisioning?&lt;/LI&gt;&lt;LI&gt;Is there native SAP SoD support or dependency on external tooling (for example SAP GRC/IAG)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Additionally, Saviynt supports granular SAP authorization object analysis down to field-level min/max values within SAP Private Cloud environments.&lt;/P&gt;&lt;P&gt;Does Entra provide similar depth for SAP authorization analysis?&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;3. SAP Integrations / Connectors&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;While Entra provides OOTB Enterprise Applications and provisioning connectors for SAP applications:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What differences or limitations have you observed compared to Saviynt’s SAP connectors?&lt;/LI&gt;&lt;LI&gt;How well does Entra handle SAP role imports, entitlement hierarchy, and provisioning workflows?&lt;/LI&gt;&lt;LI&gt;Any known gaps for SAP Private Cloud integrations?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Would appreciate any implementation experiences, architecture guidance, lessons learned, or recommendations from teams who have evaluated or deployed Entra Governance in SAP-heavy environments.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 17:28:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/entra-id-governance-vs-saviynt-for-sap-iga-use-cases/m-p/4523348#M10330</guid>
      <dc:creator>carltonflewis</dc:creator>
      <dc:date>2026-05-27T17:28:07Z</dc:date>
    </item>
    <item>
      <title>ssoSilent() not working across Next.js apps — timed_out or account picker on localhost</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/ssosilent-not-working-across-next-js-apps-timed-out-or-account/m-p/4521758#M10329</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been stuck on this for a few days and would really appreciate some guidance from anyone who has dealt with cross-app silent SSO using MSAL.js v5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the setup. We have 3 separate Next.js applications all belonging to the same organisation, all registered under a single Azure Entra ID App Registration with the same clientId and tenantId. In production they all live under the same parent domain — app1.contoso.com, app2.contoso.com, app3.contoso.com — so localStorage is shared between them. On localhost we run them on ports 3000, 3001, and 3002.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is simple: if a user is already signed into App 1, opening App 2 in a new tab should silently authenticate them without any popup, redirect, or account picker. Just seamless SSO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is how I've set up the msalConfig:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;export const msalConfig: Configuration = {&lt;/P&gt;&lt;P&gt;auth: {&lt;/P&gt;&lt;P&gt;clientId: 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx',&lt;/P&gt;&lt;P&gt;authority: 'https://login.microsoftonline.com/yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy',&lt;/P&gt;&lt;P&gt;redirectUri: 'http://localhost:3001/',&lt;/P&gt;&lt;P&gt;postLogoutRedirectUri: '/login',&lt;/P&gt;&lt;P&gt;},&lt;/P&gt;&lt;P&gt;cache: {&lt;/P&gt;&lt;P&gt;cacheLocation: 'localStorage',&lt;/P&gt;&lt;P&gt;storeAuthStateInCookie: true,&lt;/P&gt;&lt;P&gt;},&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;export const loginRequest = {&lt;/P&gt;&lt;P&gt;scopes: ['openid', 'profile', 'email', 'User.Read'],&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inside a component called SsoInitializer that sits inside MsalProvider, I scan localStorage for a sibling app's MSAL account on mount. I check both msal.2.account.keys (MSAL v5 format) and msal.account.keys (older format), extract the username/email as a loginHint, and then call ssoSilent(). If no loginHint is found — which is always the case on localhost since different ports are different origins — I still call ssoSilent() without a hint, expecting it to fall back to the Entra session cookie that was set when the user logged into port 3000.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;instance.ssoSilent({&lt;/P&gt;&lt;P&gt;...loginRequest,&lt;/P&gt;&lt;P&gt;...(loginHint ? { loginHint } : {}),&lt;/P&gt;&lt;P&gt;redirectUri: `${window.location.origin}/silent-callback.html`,&lt;/P&gt;&lt;P&gt;})&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The silent-callback.html in /public is just a blank HTML page with no scripts, which I believe is the correct approach based on the docs since MSAL v5 uses postMessage to communicate with the iframe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Azure app registration has the SPA platform selected, all redirect URIs including the /silent-callback.html variants are registered for all three localhost ports, ID tokens are enabled, and User.Read has admin consent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now here is the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When App 1 is logged in on localhost:3000 and I open App 2 on localhost:3001, ssoSilent() fires but one of two things happens:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first failure is a timed_out error — BrowserAuthError: timed_out from BrowserUtils.ts. The server-telemetry key in localStorage shows redirect_bridge_timeout repeated multiple times with cacheHits of 0. This started happening when I had a CDN import of MSAL inside silent-callback.html trying to call handleRedirectPromise(). The CDN download was too slow for the iframe timeout window, so I removed it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second failure happens after switching to the blank HTML silent-callback page. The timed_out goes away but now ssoSilent() seems to fall through entirely and the Microsoft "Pick an account" full-page redirect opens — which completely defeats the purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also tried passing prompt: 'none' explicitly in the ssoSilent request. No change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One important observation from DevTools: the Entra session cookie IS present in the browser. The user is fully signed in on port 3000. Based on my understanding of the docs, ssoSilent() without a loginHint should detect this session cookie and authenticate silently. But it's either timing out or showing the account picker.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a few specific questions I'm hoping someone can help with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, is ssoSilent() actually supposed to work without a loginHint using only the Entra session cookie? Or does it require a hint and will always show the account picker if multiple accounts are signed in to the browser?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, what is the correct content of silent-callback.html for MSAL v5 specifically? The blank page causes redirect_bridge_timeout, but adding MSAL scripts causes a different timeout because they load too slowly. Has the iframe handshake mechanism changed between v1/v2 and v5?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third, is there an officially recommended pattern for cross-app silent SSO when developing on localhost with different ports? In production the same-domain setup handles localStorage sharing fine, but on localhost the browser's same-origin policy makes each port completely isolated, so the sibling token scan always returns null.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fourth, does the redirectUri passed to ssoSilent() need to point to a page that actively runs MSAL code, or is a blank page genuinely sufficient for the iframe to complete its handshake in v5?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="73893" data-lia-user-login="azure" class="lia-mention lia-mention-user"&gt;azure&lt;/a&gt;/msal-browser 5.6.1, &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="73893" data-lia-user-login="azure" class="lia-mention lia-mention-user"&gt;azure&lt;/a&gt;/msal-react 3.0.20, Next.js 14 App Router, Chrome on Windows 11, single tenant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or a working example from someone who has done this in MSAL v5 would be hugely appreciated. Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 07:08:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/ssosilent-not-working-across-next-js-apps-timed-out-or-account/m-p/4521758#M10329</guid>
      <dc:creator>CilansSystem</dc:creator>
      <dc:date>2026-05-21T07:08:45Z</dc:date>
    </item>
    <item>
      <title>"Access package assignment manager" role with "Restricted access to Microsoft Entra admin center"</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/quot-access-package-assignment-manager-quot-role-with-quot/m-p/4519739#M10325</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How can I allow a user with the &lt;STRONG&gt;"Access package assignment manager"&lt;/STRONG&gt; role assigned only to a single catalog to manage access package assignments when &lt;STRONG&gt;"Restricted access to Microsoft Entra admin center"&lt;/STRONG&gt; is set to &lt;STRONG&gt;Yes&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;I do not see any option to manage assignments through the &lt;STRONG&gt;MyAccess&lt;/STRONG&gt; portal, so it seems this must be done through the &lt;STRONG&gt;Entra Admin Center&lt;/STRONG&gt;. However, the user cannot access the Entra Admin Center because they do not have any Entra administrative roles.&lt;/P&gt;&lt;P&gt;I do not have an &lt;STRONG&gt;Entra ID Governance&lt;/STRONG&gt; license, so the option to use &lt;STRONG&gt;on-behalf-of access package assignment requests&lt;/STRONG&gt; is not available.&lt;/P&gt;&lt;P&gt;How can this scenario be solved?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2026 11:49:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/quot-access-package-assignment-manager-quot-role-with-quot/m-p/4519739#M10325</guid>
      <dc:creator>PawelKowalczyk</dc:creator>
      <dc:date>2026-05-14T11:49:27Z</dc:date>
    </item>
    <item>
      <title>'Registering user becomes local admin on Joined Devices' - WHAT</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/registering-user-becomes-local-admin-on-joined-devices-what/m-p/4513794#M10317</link>
      <description>&lt;P&gt;Stumbled on a tenant with 'JOIN' available for all users. Haven't worked with this much - most tenants I see only have registration. But then I noticed the horrifying 'Registering user is added as local administrator on the device during Microsoft Entra join' option was ALSO set to ALL.&lt;/P&gt;&lt;img /&gt;&lt;P&gt;This is a tenant we just took on, but I've never seen that control before. This is terrifying, considering AFAIK, there is no real way for a registering user to know if they're registering or joining. Beneath it is an option to 'Manage Additional local administrators on all Microsoft Entra joined devices', which leads to the Role page for Device Administrators, which is empty.&lt;/P&gt;&lt;img /&gt;&lt;P&gt;Under Description, this describes what APPEARS to be to be the same thing mentioned in the previous control - 'Users with this role become local machine administrators on all Windows 10 devices that are joined to Microsoft Entra'. But no one is assigned this.&lt;/P&gt;&lt;img /&gt;&lt;P&gt;Conveniently, on my own tenant, I happened to let someone JOIN yesterday. We have this limited to 2 (now 3) people - most just register... But this user Joined, and the 'Joining user becomes local admin' option was on ALL. But I can't validate that the user ever become local admin. They don't have the role, their device shows as joined, but there's no additional roles. The audit logs don't look weird. They're not in that 'Device Administrators' group, which describes itself as 'Users with this role become local machine administrators on all Windows 10 devices that are joined to Microsoft Entra'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts? Freaking out, honestly. We have a mix of DC and Cloud users. I've inherited them all, and had the understanding that Join was essentially registration but with Org ownership. I've tried to get some input from Copilot, but he has basically waffled between 'No, this setting is just badly named' and 'no, actually it's this other setting' and 'no, you know what, it all makes sense somehow'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Does that option actually set the joining user as global admin? Is that really the default setting?&lt;/P&gt;&lt;P&gt;2. can you validate this ANYWHERE in Entra? Or does it just disappear?&lt;/P&gt;&lt;P&gt;3. what is that Device Admin group? A separate group, independent of these two settings, that gives local admin?&lt;/P&gt;&lt;P&gt;4. Is there a graph endpoint that can be used to set this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 20:22:52 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/registering-user-becomes-local-admin-on-joined-devices-what/m-p/4513794#M10317</guid>
      <dc:creator>underQualifried</dc:creator>
      <dc:date>2026-04-22T20:22:52Z</dc:date>
    </item>
    <item>
      <title>MFA Options for Employees without Phones</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/mfa-options-for-employees-without-phones/m-p/4511579#M10310</link>
      <description>&lt;P&gt;Hello everbody,&lt;/P&gt;&lt;P&gt;we're currently trying to implement MFA in our company, but approximately 1/10 of our employees have a workphone and are not allowed to use their personal phone.&lt;/P&gt;&lt;P&gt;Since we also recently introduced Intune, the idea was to just use&amp;nbsp;&lt;STRONG&gt;Windows Hello for Business,&amp;nbsp;&lt;/STRONG&gt;but when trying to provision it, we realized that you need to have MFA active for an account to be able to even activate it? Which kinda defeats the purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question is, is there some way to circumvent the MFA requirement for WHfB? Or what other options do we realistically have?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 12:00:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/mfa-options-for-employees-without-phones/m-p/4511579#M10310</guid>
      <dc:creator>FabianUni</dc:creator>
      <dc:date>2026-04-15T12:00:35Z</dc:date>
    </item>
    <item>
      <title>Advice required for temp / agency staff</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/advice-required-for-temp-agency-staff/m-p/4510876#M10307</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;Anyway, I'm hoping someone can point me in the right direction.&lt;/P&gt;&lt;P&gt;We have Android devices in Entra Shared Device Mode (Multi App) which any of our employees with a valid UPN can logon to.&lt;/P&gt;&lt;P&gt;All good there.&lt;/P&gt;&lt;P&gt;What we need is a solution for temporary or agency staff. This would be staff that could be called on at very short notice and may not stay around for long.&lt;/P&gt;&lt;P&gt;For security and audit reasons, we'd rather not create "userless" accounts.&lt;/P&gt;&lt;P&gt;Is there anything in Entra / Entra Shared Device Mode that can achieve this?&lt;/P&gt;&lt;P&gt;Info greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 15:05:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/advice-required-for-temp-agency-staff/m-p/4510876#M10307</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-04-13T15:05:38Z</dc:date>
    </item>
    <item>
      <title>Understand Why a Service Principal Was Created in Your Entra Tenant</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/understand-why-a-service-principal-was-created-in-your-entra/m-p/4509863#M10305</link>
      <description>&lt;P&gt;Are you a tenant admin or member of a security team in your organization and find yourself asking “Why was this service principal created in our tenant?”&lt;/P&gt;
&lt;P&gt;Historically, answering this required correlating audit logs with Microsoft Graph queries or going through long investigations. Microsoft Entra now introduces enhanced audit log properties that make it significantly easier to understand the origin and intent behind newly created service principals directly from tenant audit logs. These new improvements surface additional insights within the&amp;nbsp;&lt;STRONG&gt;Add service principal&lt;/STRONG&gt; activity under the &lt;STRONG&gt;ApplicationManagement&lt;/STRONG&gt; category—helping administrators determine whether a service principal was provisioned automatically by Microsoft services, triggered by a purchased subscription, or explicitly created by user or application activity.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What’s in it for me as an Admins or member of the Security Team&lt;BR /&gt;&lt;/STRONG&gt;When a service principal is created, new metadata is now captured within Microsoft Entra audit logs that enables faster root‑cause analysis. These properties help distinguish between Microsoft‑driven provisioning processes and tenant‑initiated actions, allowing teams to quickly assess whether an event is expected platform behavior or something requiring deeper investigation.&lt;/P&gt;
&lt;P&gt;For example, administrators can now:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify provisioning initiated by Microsoft services versus internal users or automation.&lt;/LI&gt;
&lt;LI&gt;Determine which tenant subscription or service plan enabled just‑in‑time provisioning.&lt;/LI&gt;
&lt;LI&gt;Recognize provisioning linked to Azure resource onboarding or managed identities.&lt;/LI&gt;
&lt;LI&gt;Investigate service principal creation without relying on additional Graph lookups.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By leveraging these enriched audit logs, security teams can streamline investigations into newly created enterprise applications and reduce manual dependency on downstream data sources. This ultimately improves visibility into application onboarding events and supports faster decision‑making when assessing potential risk or unexpected provisioning activity within the tenant.&lt;/P&gt;
&lt;P&gt;Learn more here- &lt;A href="https://learn.microsoft.com/en-us/entra/identity/monitoring-health/understand-service-principal-creation-with-new-audit-log-properties" target="_blank"&gt;Understand why a service principal was created in your tenant - Microsoft Entra ID | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 08:22:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/understand-why-a-service-principal-was-created-in-your-entra/m-p/4509863#M10305</guid>
      <dc:creator>milgo</dc:creator>
      <dc:date>2026-04-09T08:22:36Z</dc:date>
    </item>
  </channel>
</rss>

