<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Another security blog...]]></title><description><![CDATA[The purpose of this blog is to share my knowledge gained from real-life scenarios in practice, which may help others overcome various challenges they encounter.]]></description><link>https://www.matej.guru</link><image><url>https://www.matej.guru/img/substack.png</url><title>Another security blog...</title><link>https://www.matej.guru</link></image><generator>Substack</generator><lastBuildDate>Tue, 05 May 2026 11:42:42 GMT</lastBuildDate><atom:link href="https://www.matej.guru/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Matej.GURU]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[matej@matej.guru]]></webMaster><itunes:owner><itunes:email><![CDATA[matej@matej.guru]]></itunes:email><itunes:name><![CDATA[Matej Klemenčič]]></itunes:name></itunes:owner><itunes:author><![CDATA[Matej Klemenčič]]></itunes:author><googleplay:owner><![CDATA[matej@matej.guru]]></googleplay:owner><googleplay:email><![CDATA[matej@matej.guru]]></googleplay:email><googleplay:author><![CDATA[Matej Klemenčič]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[When OAuth Redirects Become a Phishing Tool]]></title><description><![CDATA[Attackers can abuse OAuth redirect behavior to deliver phishing and malware.]]></description><link>https://www.matej.guru/p/when-oauth-redirects-become-a-phishing</link><guid isPermaLink="false">https://www.matej.guru/p/when-oauth-redirects-become-a-phishing</guid><dc:creator><![CDATA[Matej's Copilot]]></dc:creator><pubDate>Sun, 15 Mar 2026 19:00:51 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5535e342-a69a-47e4-beb1-b5be6b2c6877_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>&#129302; Matej&#8217;s Copilot Brief</h4><p style="text-align: justify;">Microsoft recently documented phishing campaigns abusing <strong>OAuth redirect behavior</strong> in identity platforms such as Microsoft Entra ID.</p><p style="text-align: justify;">The technique does not exploit a vulnerability. Instead, attackers abuse <strong>legitimate OAuth redirection logic</strong> to deliver phishing pages or malware payloads.</p><p style="text-align: justify;">The attack typically begins with a phishing email containing a crafted OAuth authorization URL. The link triggers a login flow against a legitimate identity provider such as Microsoft Entra ID.</p><p style="text-align: justify;">Instead of completing the authentication process, the attacker intentionally manipulates parameters in the request <em>(for example by using invalid scopes or manipulated redirect URIs)</em>. This causes the OAuth flow to redirect the user to a <strong>malicious endpoint controlled by the attacker</strong>.</p><p style="text-align: justify;">Because the flow starts on a <strong>trusted Microsoft login domain</strong>, many email and browser defenses allow the link to pass.</p><p style="text-align: justify;">In observed campaigns, the redirected page delivered malware payloads such as ZIP archives containing LNK loaders and scripts that eventually executed PowerShell commands and connected to attacker-controlled infrastructure.</p><p style="text-align: justify;">Microsoft emphasizes that this technique demonstrates how <strong>legitimate authentication mechanisms can be repurposed for social engineering</strong> rather than exploiting technical vulnerabilities.</p><blockquote><p><a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/">OAuth redirection abuse enables phishing and malware delivery | Microsoft Security Blog</a></p></blockquote><h4>&#129489;&#8205;&#128187; Matej&#8217;s Take</h4><p style="text-align: justify;">Microsoft&#8217;s report describes how OAuth redirection can be abused in phishing campaigns. To better understand the risk, it helps to look at how this can actually work in practice.</p><p style="text-align: justify;">The attacker first registers an application in their own Entra ID tenant.</p><p style="text-align: justify;">The key element is the <strong>redirect URI</strong>, which points to infrastructure controlled by the attacker. This URI will be used later in the OAuth flow to redirect the victim after authentication.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hlWZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hlWZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 424w, https://substackcdn.com/image/fetch/$s_!hlWZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 848w, https://substackcdn.com/image/fetch/$s_!hlWZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 1272w, https://substackcdn.com/image/fetch/$s_!hlWZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hlWZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png" width="1290" height="774" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:774,&quot;width&quot;:1290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:194539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/191039076?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hlWZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 424w, https://substackcdn.com/image/fetch/$s_!hlWZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 848w, https://substackcdn.com/image/fetch/$s_!hlWZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 1272w, https://substackcdn.com/image/fetch/$s_!hlWZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1a9df8-be3e-4b49-bfe6-cf8ef9e767fe_1290x774.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">In this example the application has <strong>no API permissions configured</strong>. This is intentional. Without permissions, the user will <strong>not see a consent prompt</strong>, which removes an important warning signal and makes the login flow appear completely normal.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1c9-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1c9-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 424w, https://substackcdn.com/image/fetch/$s_!1c9-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 848w, https://substackcdn.com/image/fetch/$s_!1c9-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 1272w, https://substackcdn.com/image/fetch/$s_!1c9-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1c9-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png" width="1282" height="779" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:779,&quot;width&quot;:1282,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:223375,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/191039076?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1c9-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 424w, https://substackcdn.com/image/fetch/$s_!1c9-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 848w, https://substackcdn.com/image/fetch/$s_!1c9-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 1272w, https://substackcdn.com/image/fetch/$s_!1c9-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbac4653e-ce0b-4fe5-882d-4cc584a227a7_1282x779.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">The attacker can now generate an OAuth authorization link and deliver it to a target user. </p><p style="text-align: justify;"><em>I will not demonstrate how to construct such links in this article, but I personally use the <strong>Microsoft Entra Sign-in URL Builder</strong> when analyzing authentication flows.</em></p><blockquote><p><a href="https://signin.merill.net/">Entra Sign-in URL Builder - Generate Microsoft Entra OAuth 2.0 Authorization URLs</a></p></blockquote><p style="text-align: justify;">When the victim opens the link, the browser loads a <strong>legitimate Microsoft authentication page</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jkhx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jkhx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 424w, https://substackcdn.com/image/fetch/$s_!Jkhx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 848w, https://substackcdn.com/image/fetch/$s_!Jkhx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 1272w, https://substackcdn.com/image/fetch/$s_!Jkhx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jkhx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png" width="1290" height="774" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:774,&quot;width&quot;:1290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:291918,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/191039076?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Jkhx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 424w, https://substackcdn.com/image/fetch/$s_!Jkhx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 848w, https://substackcdn.com/image/fetch/$s_!Jkhx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 1272w, https://substackcdn.com/image/fetch/$s_!Jkhx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8e34960-d6ef-41c2-b13d-f5c1aed558fb_1290x774.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">The URL points to the real Microsoft login domain, which makes the flow appear trustworthy.</p><p style="text-align: justify;">In this demo the user is asked to select an account because multiple accounts exist in the browser session. In many real environments this step does <strong>not even appear</strong>. If the user already has an active session, <strong>Single Sign-On (SSO)</strong> may authenticate the user automatically, which actually makes the attack even smoother for the attacker.</p><p style="text-align: justify;">Because the redirect URI points to attacker infrastructure, the user is silently forwarded to a <strong>phishing page </strong><em>(in my example the page is part of an AiTM phishing kit).</em> </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FhqZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FhqZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 424w, https://substackcdn.com/image/fetch/$s_!FhqZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 848w, https://substackcdn.com/image/fetch/$s_!FhqZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 1272w, https://substackcdn.com/image/fetch/$s_!FhqZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FhqZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png" width="1252" height="798" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:798,&quot;width&quot;:1252,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65414,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/191039076?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FhqZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 424w, https://substackcdn.com/image/fetch/$s_!FhqZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 848w, https://substackcdn.com/image/fetch/$s_!FhqZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 1272w, https://substackcdn.com/image/fetch/$s_!FhqZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98cf9d50-5013-49fd-9592-c8bef042af6d_1252x798.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">One practical mitigation is restricting authentication to external tenants.</p><p style="text-align: justify;">If users can freely sign in to other Microsoft Entra tenants, attackers can leverage their own tenant as part of the phishing flow. Blocking <strong>outbound B2B collaboration by default</strong> reduces this exposure.</p><p style="text-align: justify;">My recommendation is a <strong>deny-by-default approach</strong>: block external tenant authentication and allow only trusted partner tenants through an allow list.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zcEn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zcEn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 424w, https://substackcdn.com/image/fetch/$s_!zcEn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 848w, https://substackcdn.com/image/fetch/$s_!zcEn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 1272w, https://substackcdn.com/image/fetch/$s_!zcEn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zcEn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png" width="1290" height="774" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:774,&quot;width&quot;:1290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:194374,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/191039076?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zcEn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 424w, https://substackcdn.com/image/fetch/$s_!zcEn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 848w, https://substackcdn.com/image/fetch/$s_!zcEn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 1272w, https://substackcdn.com/image/fetch/$s_!zcEn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fa4cd9-dac5-47e0-b786-54cc31b7cb6e_1290x774.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Before enforcing this, you should review whether users are legitimately signing in to external tenants.</p><p style="text-align: justify;">This can be verified by analyzing Entra Sign-in logs using Defender Advanced Hunting or a SIEM such as Microsoft Sentinel.</p><h4>&#127891; Action for Security Teams</h4><ul><li><p>Review <strong>Sign-in logs</strong> for cross-tenant authentication.</p></li><li><p>Use <strong>Defender Advanced Hunting (KQL)</strong> or <strong>Sentinel</strong> to identify external tenant sign-ins.</p></li><li><p>Implement <strong>deny-by-default outbound B2B collaboration restrictions</strong>.</p></li><li><p>Allow only <strong>trusted partner tenants</strong> through an allow list.</p></li><li><p>Periodically review allowed tenants.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[March 2026 is here! Synced Passkeys and Passkey Profiles rollout?]]></title><description><![CDATA[Microsoft is bringing Passkey Profiles and Synced Passkeys to General Availability in March 2026.]]></description><link>https://www.matej.guru/p/march-2026-is-here-synced-passkeys</link><guid isPermaLink="false">https://www.matej.guru/p/march-2026-is-here-synced-passkeys</guid><dc:creator><![CDATA[Matej's Copilot]]></dc:creator><pubDate>Sun, 01 Mar 2026 18:57:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c696d741-e143-4a96-955e-2a66279afc0a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>&#129302; Matej&#8217;s Copilot Brief</h4><p>Microsoft is bringing <strong>Passkey Profiles</strong> and <strong>Synced Passkeys</strong> to General Availability in March 2026.</p><p>Until now, Microsoft Entra ID supported primarily <strong>device-bound passkeys</strong>. These credentials are stored on a specific device and cannot be synchronized across password managers or ecosystems such as Apple iCloud Keychain, Google Password Manager, 1Password, or Bitwarden.</p><p>Passkey Profiles introduce policy-based control over passkey usage. Administrators can define how passkeys are registered and enforced across users and groups.</p><p>Synced passkeys expand usability. They allow credentials to be securely synchronized across devices using supported password managers, improving cross-device experience and reducing registration friction.</p><p>The change addresses one of the key adoption barriers of passkeys: usability across multiple devices.</p><blockquote><p><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-passkey-profiles">How to Enable Passkey (FIDO2) Profiles in Microsoft Entra ID (Preview) - Microsoft Entra ID | Microsoft Learn</a></p></blockquote><blockquote><p><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-synced-passkeys">How to Enable Synced Passkeys (FIDO2) in Microsoft Entra ID (Preview) - Microsoft Entra ID | Microsoft Learn</a></p></blockquote><div><hr></div><h4>&#129489;&#8205;&#128187; Matej&#8217;s Take</h4><p>This was one of the missing pieces in Entra ID. Device-bound passkeys are technically stronger because the credential never leaves the device. However, adoption has been limited.</p><p>Users change devices. They reinstall operating systems. They expect portability.</p><p>Synced passkeys lower that friction.</p><p>Yes, they are slightly weaker than device-bound passkeys from a pure security standpoint. But they are still phishing-resistant and significantly stronger than traditional MFA methods such as OTP codes or push-based authentication vulnerable to advanced phishing attacks.</p><p>If the choice is between:</p><ul><li><p>Synced passkey</p></li><li><p>SMS / OTP / weak MFA</p></li></ul><p>The answer is clear.</p><p>This change moves Entra ID in the right direction.</p><p>Now the question is <strong>adoption</strong>.</p><div><hr></div><h4>&#127891; Action for Security Teams</h4><ul><li><p>Review the GA timeline and Message Center notification (MC1221452).</p></li><li><p>Understand the difference between device-bound and synced passkeys.</p></li><li><p>Define Passkey Profiles aligned with your risk appetite.</p></li><li><p>Pilot synced passkeys with security-savvy users first.</p></li><li><p>Update authentication strength policies if needed.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Entra ID Guest Accounts: Identify, Analyze, and Clean Up (August 2025 Update)]]></title><description><![CDATA[For a while, I had been manually running cmdlets to export guest account reports from Entra ID.]]></description><link>https://www.matej.guru/p/entra-id-guest-accounts-identify</link><guid isPermaLink="false">https://www.matej.guru/p/entra-id-guest-accounts-identify</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Fri, 15 Aug 2025 19:18:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5c8bf163-c0bc-4bed-bc82-66933668454d_1024x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="pullquote"><p><strong>August 2025 Update: </strong>The script for exporting <strong>Entra ID Enterprise Applications</strong>, which I covered in <a href="https://www.matej.guru/p/stop-flying-blind-get-visibility">this post</a>, has proven to be extremely useful, mainly because of the HTML export which makes data analysis much easier. Based on that success, I decided to update the existing script for reviewing Entra ID guest accounts. The new version now supports export both to HTML and CSV, allowing for a quicker visual overview as well as easy further data processing</p></div><p>For a while, I had been manually running cmdlets to export guest account reports from Entra ID. These reports were crucial for analyzing and cleaning up inactive accounts, but I often found myself retyping or searching for the right commands. To simplify the process, I created a straightforward PowerShell script to generate a report of guest accounts.</p><p>Regularly reviewing guest accounts is important, especially if you&#8217;re not using advanced features like <a href="https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-overview">Entitlement Management</a> in Entra ID. Identifying and removing inactive accounts helps keep your environment clean and secure.</p><p>The goal was to make the task easier:</p><ul><li><p>Quickly export guest accounts to a CSV and HTLM for further analysis.</p></li><li><p>Use <a href="https://learn.microsoft.com/en-us/entra/identity/users/users-bulk-delete">bulk delete actions</a> in Entra ID to remove stale accounts.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sSNH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sSNH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 424w, https://substackcdn.com/image/fetch/$s_!sSNH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 848w, https://substackcdn.com/image/fetch/$s_!sSNH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 1272w, https://substackcdn.com/image/fetch/$s_!sSNH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sSNH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png" width="1277" height="810" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:810,&quot;width&quot;:1277,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:55834,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/157832181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sSNH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 424w, https://substackcdn.com/image/fetch/$s_!sSNH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 848w, https://substackcdn.com/image/fetch/$s_!sSNH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 1272w, https://substackcdn.com/image/fetch/$s_!sSNH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79108fb6-c1a6-4a56-aa25-35998c4d76ab_1277x810.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I primarily focus on analyzing environments and providing recommendations, so I didn&#8217;t include any code for deleting guest accounts. I don&#8217;t have or need deletion rights, and I wanted to keep the script safe and read-only. However, it&#8217;s flexible enough for others to modify if needed.</p><h2>The Script</h2><p>You can find the complete script in my GitHub repository. Feel free to download, review, or contribute improvements:</p><p><a href="https://github.com/matejklemencic/MyHub/blob/main/Export-EntraGuestReport.ps1">Export-EntraGuestReport.ps1</a></p><blockquote><p>Before you run the script, you must install the <a href="https://learn.microsoft.com/en-us/powershell/entra-powershell/installation?view=entra-powershell&amp;tabs=powershell%2Cv1&amp;pivots=windows">Microsoft Entra PowerShell module</a></p></blockquote><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4>Rich HTML Report Generation</h4><p>Beyond simple CSV export, the script generates a comprehensive HTML report with interactive features, summary statistics, and visual categorization:</p><ul><li><p><strong>Summary Dashboard</strong>: Key metrics displayed in an easy-to-read card layout</p></li><li><p><strong>Interactive Filtering</strong>: Search by email, filter by status, account state, and more</p></li><li><p><strong>Visual Status Indicators</strong>: Color-coded rows for different user states</p></li><li><p><strong>Sortable Columns</strong>: Click column headers to sort data</p></li><li><p><strong>Responsive Design</strong>: Professional appearance with modern styling</p></li></ul><h2>How to Use the Script</h2><h4><strong>Save and Prepare the Script</strong></h4><p>Save the complete script as <code>Export-EntraGuestReport.ps1</code> in your preferred location and ensure you have the Microsoft Entra PowerShell module installed:</p><pre><code>Install-Module -Name Microsoft.Entra -Repository PSGallery -Scope CurrentUser -Force -AllowClobber</code></pre><h4>Basic Usage Examples</h4><p>Generate both HTML and CSV reports with default settings:</p><pre><code><code>.\Export-EntraGuestReport.ps1</code></code></pre><p>Generate only CSV report for pending guests:</p><pre><code>.\Export-EntraGuestReport.ps1 -PendingAcceptanceOnly -CSVOnly</code></pre><p>Custom inactive threshold with HTML report only:</p><pre><code>.\Export-EntraGuestReport.ps1 -InactiveDays 180 -HTMLOnly</code></pre><p>Custom path and filename for comprehensive reporting:</p><pre><code>.\Export-EntraGuestReport.ps1 -ExportPath "D:\Reports" -FileName "MonthlyGuestAudit"</code></pre><p>Target specific tenant:</p><pre><code>.\Export-EntraGuestReport.ps1 -TenantId "your-tenant-id" -InactiveDays 120</code></pre><h4>Available Parameters</h4><ul><li><p><strong>TenantId:</strong> Optional. Specify a particular tenant to analyze</p></li><li><p><strong>PendingAcceptanceOnly:</strong> Switch to filter only pending guest invitations</p></li><li><p><strong>InactiveDays:</strong> Customize the inactive threshold (default: 90 days)</p></li><li><p><strong>ExportPath:</strong> Specify custom export directory</p></li><li><p><strong>FileName:</strong> Custom filename (without extension)</p></li><li><p><strong>CSVOnly:</strong> Generate only CSV report</p></li><li><p><strong>HTMLOnly:</strong> Generate only HTML report</p></li></ul><h4>Review the Report</h4><p>The script will create comprehensive reports with:</p><ul><li><p><strong>HTML Report:</strong> Interactive dashboard that opens automatically in your browser, featuring summary statistics, filtering capabilities, and visual status indicators</p></li><li><p><strong>CSV Report:</strong> Detailed data export perfect for further analysis in Excel or other tools</p></li><li><p><strong>Summary File:</strong> Text-based summary of key findings for quick reference</p></li></ul><h2>Conclusion</h2><p>This script makes it easy to generate a report on guest accounts from Entra ID. It simplifies data extraction for analysis and cleanup, and its flexible design lets you adapt or expand it as needed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Stop Flying Blind: Get Visibility into Your Entra ID Enterprise Applications]]></title><description><![CDATA[The topic of Enterprise Applications in Entra ID is something that, not long ago, made me feel uncertain.]]></description><link>https://www.matej.guru/p/stop-flying-blind-get-visibility</link><guid isPermaLink="false">https://www.matej.guru/p/stop-flying-blind-get-visibility</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Sun, 03 Aug 2025 16:38:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6VRh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The topic of Enterprise Applications in Entra ID is something that, not long ago, made me feel uncertain. The reason was simple. I honestly did not fully understand how to approach it from a security perspective.</p><p>It was clear to me that controlling app registration and consent was crucial. In most environments, I managed to enforce that new applications require admin approval before being added. Every time I achieved that, my next comment was always the same.</p><p><em>&#8220;Great, but do not forget to check the existing applications because there might already be something risky in there.&#8221;</em></p><p>And without fail, the next question I received was: <em>"Okay, but how do we even do that? Do I have to open every single app manually?"</em></p><p>In such cases, I usually pointed people to various scripts or tools that could export data about enterprise apps, helping them make informed decisions about what is safe to keep. </p><p>But recently, I started wondering if I could create something like this myself using AI to speed up the process. Since I am not a coder, building a custom tool from scratch was never realistic, so turning to AI felt like the logical way forward.</p><h4>First, Understand the Basics</h4><p>Before I could even think about building a reliable report, I realized that I did not fully understand how Enterprise Applications, Service Principals, and App Registrations really work. If I could not explain them clearly to myself, there was no way I could ask AI to help me build a meaningful tool.</p><p>At this point, I have to give credit where it is due. <a href="https://heusser.pro/p/understanding-entra-id-app-registrations-enterprise-applications-and-service-principals-part-2-os8rb48knqez/">Martin Heusser&#8217;s blog posts</a> on the topic were a game-changer for me. I read both of his articles multiple times until I felt like I truly understood the concepts. If you are in the same boat, I highly recommend his content because it really helps connect the dots.</p><h4>What I Wanted to Achieve</h4><p>Armed with new knowledge, I went back to my script with a clear goal. I wanted a full report of all Enterprise Applications, not just App Registrations.</p><p>The reason is simple. I needed visibility over everything tied to my tenant, not only apps registered locally but also external ones, including third-party integrations that can access Exchange Online, OneDrive, and other sensitive Microsoft 365 services. To make the report more relevant, I also added exceptions to filter out certain built-in applications that are not important for my analysis and do not need to show up in the results.</p><p>The HTML report includes:</p><ul><li><p><strong>App Ownership</strong> to quickly identify what kind of application it is.</p></li><li><p><strong>Has App Registration</strong> to show if the app is registered in your tenant and holds active credentials.</p></li><li><p><strong>Owners </strong>because you need to know who to contact about a specific app.</p></li><li><p><strong>Assignment Required</strong> an often-overlooked parameter that defines whether users can access the app freely or only when explicitly assigned. For example, by default any signed-in user can query Microsoft Graph for basic directory information unless you restrict it.</p></li><li><p><strong>Permissions Overview</strong> probably the most critical part, listing what rights the enterprise app or service principal holds.</p></li></ul><h4>Adding a Risk Factor</h4><p>Without some kind of risk score, every app looks equally important, which makes cleanup nearly impossible. So I built a simple logic into the script that analyzes permissions and assigns a Risk Score and Risk Level to each app. These factors are customizable. You can tweak them to match your own risk appetite.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vZdw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vZdw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 424w, https://substackcdn.com/image/fetch/$s_!vZdw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 848w, https://substackcdn.com/image/fetch/$s_!vZdw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 1272w, https://substackcdn.com/image/fetch/$s_!vZdw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vZdw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png" width="1456" height="674" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97422da7-5172-498c-80eb-0251e0600032_1457x674.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:674,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:90378,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/170005952?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vZdw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 424w, https://substackcdn.com/image/fetch/$s_!vZdw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 848w, https://substackcdn.com/image/fetch/$s_!vZdw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 1272w, https://substackcdn.com/image/fetch/$s_!vZdw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97422da7-5172-498c-80eb-0251e0600032_1457x674.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>The Result</strong></h4><p>After a few weeks of trial and error, many iterations with AI, testing, and fixing mistakes, I finally ended up with a script that I felt was worth sharing. I have already used it to analyze several tenants, and let me tell you, the first report will probably hurt. But at least you will have a starting point for cleaning up potentially dangerous apps in your environment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6VRh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6VRh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 424w, https://substackcdn.com/image/fetch/$s_!6VRh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 848w, https://substackcdn.com/image/fetch/$s_!6VRh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 1272w, https://substackcdn.com/image/fetch/$s_!6VRh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6VRh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png" width="1426" height="576" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:576,&quot;width&quot;:1426,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65589,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/170005952?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6VRh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 424w, https://substackcdn.com/image/fetch/$s_!6VRh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 848w, https://substackcdn.com/image/fetch/$s_!6VRh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 1272w, https://substackcdn.com/image/fetch/$s_!6VRh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F566dfc8a-4eca-414f-be35-fcc9f7214e08_1426x576.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One thing is certain. Right now, most environments are flying blind when it comes to Enterprise Applications in Entra ID. And that needs to change.</p><h4>Where to Get the Script</h4><p>If you want to try this out in your own environment, the script is publicly available on my GitHub.</p><p>You can find it here: <a href="https://github.com/matejklemencic/MyHub/blob/main/Get-EntraIDServicePrincipalReport.ps1">Get-EntraIDServicePrincipalReport.ps1</a></p><p>Use the script, change it if you want, adapt it to your needs, it is up to you. I will keep improving it and may even incorporate feedback from the community.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.matej.guru/subscribe?"><span>Subscribe now</span></a></p><h4>Prerequisites and Installation</h4><p>Before running the script, ensure you have the required Microsoft Graph PowerShell modules installed:</p><ul><li><p><em>Install only necessary modules</em></p></li></ul><pre><code><em>Install-Module -Name Microsoft.Graph.Authentication,Microsoft.Graph.Applications,Microsoft.Graph.Identity.SignIns,Microsoft.Graph.Identity.DirectoryManagement,Microsoft.Graph.Reports -Scope CurrentUser -AllowClobber</em></code></pre><ul><li><p><em>Or install the full umbrella module</em></p></li></ul><pre><code>Install-Module -Name Microsoft.Graph -Scope CurrentUser -AllowClobber</code></pre><p>The script automatically requests the minimal required permissions:</p><ul><li><p><code>Application.Read.All</code></p></li><li><p><code>Directory.Read.All</code></p></li><li><p><code>DelegatedPermissionGrant.Read.All</code></p></li><li><p><code>RoleManagement.Read.Directory</code></p></li></ul><h4>Available Parameters</h4><p>The script offers several filtering options to optimize performance and focus analysis:</p><pre><code><em># Basic usage - analyze all Enterprise Applications 
<strong>.\Get-EntraIDServicePrincipalReport.ps1</strong>

# Filter for apps with permissions only 
<strong>.\Get-EntraIDServicePrincipalReport.ps1 -OnlyWithPermissions</strong>

# Minimum permission threshold 
<strong>.\Get-EntraIDServicePrincipalReport.ps1 -MinimumPermissions 5</strong>

# Focus on internal applications with registrations 
<strong>.\Get-EntraIDServicePrincipalReport.ps1 -OnlyWithAppRegistrations</strong>

# Analyze only service principals without registrations 
<strong>.\Get-EntraIDServicePrincipalReport.ps1 -OnlyServicePrincipals</strong>

# Custom output location 
<strong>.\Get-EntraIDServicePrincipalReport.ps1 -OutputPath "C:\Reports\MyReport.html"</strong>

# Use external risk configuration 
<strong>.\Get-EntraIDServicePrincipalReport.ps1 -RiskConfigPath "risk-rules.json"</strong></em></code></pre><p>The script includes intelligent pre-filtering that applies quick filters first, skipping detailed analysis for applications that don't meet criteria. This significantly improves performance when analyzing large tenants with hundreds of applications.</p><h4>Report Output</h4><p>The generated HTML report provides:</p><ul><li><p><strong>Executive-style dashboard </strong>with key metrics and risk statistics</p></li><li><p><strong>Interactive filtering</strong> directly in the HTML report by risk level, ownership, assignment requirements, and permission types</p></li><li><p><strong>Sortable columns</strong> for risk score, permission counts, and other attributes</p></li><li><p><strong>Detailed permission breakdowns</strong> with expandable sections</p></li><li><p><strong>Ownership analysis</strong> including gap detection for governance</p></li><li><p><strong>Credential status</strong> tracking for active secrets and certificates</p></li><li><p><strong>Risk factor explanations</strong> for each application's security posture</p></li></ul><p>The report automatically opens in your default browser and includes comprehensive legends explaining all indicators and classifications.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4></h4><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Assume Breach: Securing MFA Registration in Entra ID]]></title><description><![CDATA[Thanks for reading Another security blog...!]]></description><link>https://www.matej.guru/p/assume-breach-securing-mfa-registration</link><guid isPermaLink="false">https://www.matej.guru/p/assume-breach-securing-mfa-registration</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Thu, 15 May 2025 19:29:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/35da80c0-1440-4b29-af00-edfb3a0896cf_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>One of the most crucial security controls in Microsoft Entra ID, alongside the implementation of Multi-Factor Authentication (MFA), is managing the conditions under which users can initially register or modify their MFA methods. Why is this important? Primarily because it's not realistic to assume that all users will proactively complete their MFA registration especially when organizations introduce various exceptions or conditions that only selectively require MFA (unfortunately a common scenario).</p><p>A highly effective approach to deploying MFA within Microsoft 365 environments is through Conditional Access policies, which allow granular control over MFA enforcement under specific conditions. However, a challenge arises when users never encounter conditions that trigger their initial MFA registration due to such policy exceptions. For instance, many companies implement policies requiring MFA only when users access resources from untrusted locations. Practically, this means users who always work from trusted or known locations may never be prompted to register for MFA if additional policies enforcing MFA registration are not implemented.</p><p>This situation creates a vulnerability where an attacker who manages to compromise user credentials could potentially register MFA methods on behalf of the legitimate user. Therefore, it's crucial to strictly control MFA registration. One option is creating a Conditional Access policy that requires MFA specifically when accessing the Security Info Registration page. </p><blockquote><p><a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-security-info-registration">Control security information registration with Conditional Access | Microsoft Learn</a></p></blockquote><p>However, this introduces a chicken-and-egg problem: how can a user perform MFA registration if MFA itself is required to access the registration process? A practical solution to this scenario involves the Temporary Access Pass (TAP). TAP provides a temporary password that allows users to bypass MFA requirements temporarily, enabling them to register their MFA method securely even from untrusted locations or devices.</p><blockquote><p><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass#create-a-temporary-access-pass">Create a Temporary Access Pass | Microsoft Learn</a></p></blockquote><p>However, the primary focus of this blog is not the initial registration process itself, but rather the potential exploitation of MFA registration policies. Adopting a Zero Trust mindset means embracing the <strong>"Assume Breach"</strong> principle. With this perspective, let's consider a scenario where an attacker employs an Adversary-in-the-Middle (AiTM) attack to steal session cookies containing MFA tokens.</p><p>How does this look in practice? Here's a demonstration showing login attempts through a phishing page. <strong>Hint</strong>: One login attempt is legitimate, while the other is fraudulent. Can you spot the difference?</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;4f9a2953-9563-471b-84f6-291595b08507&quot;,&quot;duration&quot;:null}"></div><p>The URLs are deliberately obscured to make it impossible to identify which page is legitimate and which is phishing. While there are several methods to stop such attacks, our focus here is on the Assume Breach strategy and specifically on preventing attackers from maintaining persistent access after an initial breach. Typically, after successfully stealing session tokens, attackers aim to secure persistent access. As previously mentioned, the policy designed to protect users in this scenario is a Conditional Access policy requiring MFA for security changes. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jRF1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jRF1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 424w, https://substackcdn.com/image/fetch/$s_!jRF1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 848w, https://substackcdn.com/image/fetch/$s_!jRF1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 1272w, https://substackcdn.com/image/fetch/$s_!jRF1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jRF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png" width="1057" height="897" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:897,&quot;width&quot;:1057,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/163573404?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jRF1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 424w, https://substackcdn.com/image/fetch/$s_!jRF1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 848w, https://substackcdn.com/image/fetch/$s_!jRF1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 1272w, https://substackcdn.com/image/fetch/$s_!jRF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6847ca83-dfbd-4454-8255-246780c806d3_1057x897.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But does this policy truly protect us in the described scenario? </p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;4087b47d-dcbc-438e-8359-23c1a939c024&quot;,&quot;duration&quot;:null}"></div><p>As demonstrated, even with this Conditional Access policy in place, the attacker successfully added an additional MFA method. Why? Because the attacker already possessed a session token previously authenticated through MFA. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sqvG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sqvG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 424w, https://substackcdn.com/image/fetch/$s_!sqvG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 848w, https://substackcdn.com/image/fetch/$s_!sqvG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 1272w, https://substackcdn.com/image/fetch/$s_!sqvG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sqvG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png" width="563" height="817.7883211678832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:995,&quot;width&quot;:685,&quot;resizeWidth&quot;:563,&quot;bytes&quot;:46544,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/163573404?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sqvG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 424w, https://substackcdn.com/image/fetch/$s_!sqvG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 848w, https://substackcdn.com/image/fetch/$s_!sqvG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 1272w, https://substackcdn.com/image/fetch/$s_!sqvG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63b65834-d082-49f4-b46e-29758cbf95b1_685x995.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Personally, I prefer a Conditional Access policy that blocks access to Security Info Registration unless specific conditions, such as trusted devices or trusted locations, are met. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sM9K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sM9K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 424w, https://substackcdn.com/image/fetch/$s_!sM9K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 848w, https://substackcdn.com/image/fetch/$s_!sM9K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 1272w, https://substackcdn.com/image/fetch/$s_!sM9K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sM9K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png" width="1456" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecd38402-415c-401e-959d-83f0aa006712_1603x863.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:102087,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.matej.guru/i/163573404?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sM9K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 424w, https://substackcdn.com/image/fetch/$s_!sM9K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 848w, https://substackcdn.com/image/fetch/$s_!sM9K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 1272w, https://substackcdn.com/image/fetch/$s_!sM9K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd38402-415c-401e-959d-83f0aa006712_1603x863.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The challenge with this policy is that it does not allow the use of TAP as a bypass option, as mentioned earlier. Whether this limitation is a showstopper is up to you to decide.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;c9cd9147-09c2-439f-ba64-95bceda235bb&quot;,&quot;duration&quot;:null}"></div><p>Of course, this represents just one potential exploitation scenario among many, and it should never serve as the sole control measure. The goal of this blog was primarily to highlight the importance of adopting an Assume Breach approach, prompting us to consider scenarios from the perspective of <strong>what</strong> an attacker could potentially achieve in our environment and how we can proactively prevent it.</p><div class="pullquote"><p><em>The phishing demonstration shown in the blog was conducted in a controlled environment using <a href="https://github.com/kgretzky/evilginx2">Evilginx</a>, an open-source tool created by Kuba Gretzky.</em></p></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Protecting on-premises from Microsoft 365 attacks]]></title><description><![CDATA[A few years ago, I came across a blog post titled Protecting Microsoft 365 from on-premises attacks, which resonated deeply with me.]]></description><link>https://www.matej.guru/p/protecting-on-premises-from-microsoft</link><guid isPermaLink="false">https://www.matej.guru/p/protecting-on-premises-from-microsoft</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Tue, 18 Feb 2025 20:30:41 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5718734e-bdda-4ecd-9e4e-ec4488cb37cf_1024x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A few years ago, I came across a blog post titled <em><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/protecting-microsoft-365-from-on-premises-attacks/1751754/replies/2233428">Protecting Microsoft 365 from on-premises attacks</a></em>, which resonated deeply with me. So much so that I saved it among my favorites, and today, it is even part of official <a href="https://learn.microsoft.com/en-us/entra/architecture/protect-m365-from-on-premises-attacks">Microsoft Learn</a> documentation. This blog challenged my perspective on hybrid security, highlighting various security risks in hybrid environments, including the potential dangers of on-premises administrator accounts having administrative control over Microsoft 365 environments. This realization led me to advocate for better security postures in organizations.</p><p>Now, after revisiting that post, I conducted a personal assessment to see how well these principles have been adopted. The results? While we've made progress by limiting cloud access for synchronized accounts, enforcing Conditional Access policies for corporate-compliant devices, and even adopting phishing-resistant MFA for admins, significant security gaps remain. Many organizations still struggle with fundamental security hygiene, even when robust security measures don&#8217;t necessarily require high-end licensing like Microsoft 365 E5.</p><p>Reflecting on that original blog post title, <em>Protecting Microsoft 365 from on-premises attacks</em>, I now ask: Is this the only risk we should be concerned about? Given today&#8217;s hybrid environments, where more organizations integrate on-premises services with cloud infrastructure, the reverse concern <em>protecting on-premises infrastructure from Microsoft 365 attacks</em> is just as pressing.</p><h4><strong>Microsoft Intune and Device Management Risks</strong></h4><p>Microsoft Intune adoption is growing, and more organizations are using it to manage privileged workstations. The key question is: Who manages these high-privilege devices? Observations vary from internal service desks to external partners many of whom authenticate using only basic MFA, which we know can be bypassed. Worse still, there are cases where MFA isn&#8217;t enforced due to misconfigurations or oversight. Although Microsoft has committed to requiring MFA for Intune portal access, these security changes are rolling out slower than expected.</p><blockquote><p><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication">Planning for mandatory multifactor authentication for Azure and other admin portals</a></p></blockquote><p>From an attacker&#8217;s perspective, Intune provides a powerful method for deploying malware to compromise an organization&#8217;s infrastructure.</p><h4>Defender for Endpoint: A Potential Backdoor?</h4><p>Defender for Endpoint&#8217;s <em>Live Response</em> functionality enables remote command execution. If an attacker gains admin access, they can leverage this tool to execute malicious scripts, even placing a device in <em>troubleshooting mode</em> to disable Defender components. Now, imagine if this compromised device is a domain controller. The consequences would be catastrophic.</p><div class="pullquote"><p>Would we even notice if an attacker deployed malware through Intune? Would we be alerted if they ran a PowerShell script via <em>Live Response</em>? While logs capture these activities, will we realistically detect them in time?</p></div><h4>Mitigating the Risks: Revisiting Zero Trust Principles</h4><p>The foundational principles from the <em>Protecting Microsoft 365 from on-premises attacks</em> blog still hold today. The key to defense is adopting a Zero Trust mindset. This means incorporating more signals, enforcing stricter controls, and maintaining proactive monitoring.</p><p><strong>Enforce Phishing-Resistant MFA for Administrative Accounts</strong></p><p>Given the rise of <a href="https://www.microsoft.com/en-us/security/blog/2023/06/08/detecting-and-mitigating-a-multi-stage-aitm-phishing-and-bec-campaign/">AiTM (Adversary-in-the-Middle)</a> attacks, conventional MFA is no longer sufficient. We must require phishing-resistant MFA methods such as:</p><ul><li><p>Certificate-Based Authentication (CBA)</p></li><li><p>Windows Hello for Business</p></li><li><p>Passkeys</p></li></ul><blockquote><p><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-authenticator-passkey">Enable passkeys in Authenticator for Microsoft Entra ID</a></p></blockquote><p>However, simply registering a phishing-resistant method is not enough. Conditional Access policies must enforce these methods via <em><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-strengths">Authentication Strengths</a></em>, ensuring weaker MFA options aren&#8217;t available in case of a compromise.</p><p><strong>Secure Administrative Access with Privileged Access Workstations (PAWs)</strong></p><p>Organizations should mandate that administrative roles only authenticate from <em>Privileged Access Workstations (PAWs)</em>. Traditionally used for on-premises environments, PAW principles can and should be extended to Microsoft 365. Some implementation approaches may include:</p><ul><li><p>Dedicated physical or Azure Virtual Desktop (AVD) based PAWs for cloud-centric admin tasks.</p></li><li><p>Conditional Access enforcement ensuring that privileged accounts can only sign in from approved, compliant PAW devices.</p></li></ul><p><strong>Privileged Identity Management (PIM): Beyond Just Approval Workflows</strong></p><p>While many view Privileged Identity Management (PIM) as merely requiring <em>approval workflows</em>, its core value lies in enforcing <strong>Just-In-Time (JIT) access</strong>.</p><p>When admins request access, additional security checks are conducted:</p><ul><li><p>They must prove their identity <em>again</em> (e.g., through phishing-resistant MFA).</p></li><li><p>They must use a compliant corporate device.</p></li><li><p>They receive email notifications when their role is activated and potentially alerting them to unauthorized access attempts.</p></li></ul><h4><strong>Final Thoughts</strong></h4><p>Security isn&#8217;t just about implementing advanced tools. it&#8217;s about ensuring fundamental hygiene. While we have made progress, organizations continue to struggle with basic security principles that don&#8217;t necessarily require high-end licensing. By enforcing Zero Trust, requiring phishing-resistant MFA, securing administrative access through PAWs, and leveraging Just-In-Time access with PIM, we can significantly reduce the attack surface in both cloud and hybrid environments. However, these are just a few examples of necessary security measures, and organizations must continuously evaluate and implement additional controls to stay ahead of evolving threats.</p><p>Ultimately, the real question is not only how to protect Microsoft 365 from on-premises attacks, but also how to safeguard on-premises infrastructure from Microsoft 365 compromises.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Tenant Restrictions Made Easy with Global Secure Access]]></title><description><![CDATA[In certain scenarios, organizations may want to restrict access to other tenants to prevent potential data leakage or for other security reasons.]]></description><link>https://www.matej.guru/p/tenant-restrictions-made-easy-with</link><guid isPermaLink="false">https://www.matej.guru/p/tenant-restrictions-made-easy-with</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Sun, 21 Jul 2024 06:01:42 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/430b4c32-4c00-4899-b21e-ca72145d666e_1024x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In certain scenarios, organizations may want to restrict access to other tenants to prevent potential data leakage or for other security reasons. Often, there is also a need to block access to Microsoft personal accounts, such as Outlook.com or personal OneDrive. Historically, implementing such restrictions on Windows workstations was somewhat challenging. Now that Global Secure Access is generally available, this process has become significantly more straightforward by leveraging Microsoft Traffic Profiles. </p><blockquote><p><em>Microsoft traffic profile is included with the Secure Access Essentials license, which will soon be included in the Microsoft 365 E3 license.&#8239;</em></p></blockquote><p>Let's consider a scenario where an employee attempts to sign in to their personal Microsoft account from a corporate device. With Tenant restrictions V2 and client-side tagging with Global Secure Access, this access attempt will be blocked, ensuring that corporate data is not inadvertently shared with personal accounts.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TMd0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TMd0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 424w, https://substackcdn.com/image/fetch/$s_!TMd0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 848w, https://substackcdn.com/image/fetch/$s_!TMd0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 1272w, https://substackcdn.com/image/fetch/$s_!TMd0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TMd0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png" width="857" height="861" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:861,&quot;width&quot;:857,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:96993,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TMd0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 424w, https://substackcdn.com/image/fetch/$s_!TMd0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 848w, https://substackcdn.com/image/fetch/$s_!TMd0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 1272w, https://substackcdn.com/image/fetch/$s_!TMd0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff233a4bf-8262-4dc5-8112-5dd81e6283e7_857x861.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So, what are the necessary steps to implement this?</p><p>First, we need to configure Tenant Restriction in the Microsoft Entra admin center by navigating to <em>External Identities &gt; <strong>Cross-tenant access settings</strong></em>. In the Default settings tab, you will find the <em><strong>Tenant Restrictions</strong></em> option. Set access status to block access.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CBO1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CBO1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 424w, https://substackcdn.com/image/fetch/$s_!CBO1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 848w, https://substackcdn.com/image/fetch/$s_!CBO1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!CBO1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CBO1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png" width="1456" height="1084" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1084,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:194476,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CBO1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 424w, https://substackcdn.com/image/fetch/$s_!CBO1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 848w, https://substackcdn.com/image/fetch/$s_!CBO1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 1272w, https://substackcdn.com/image/fetch/$s_!CBO1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62b6c644-2067-4e3d-b6d3-be0885f7f77d_1681x1251.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Next, we need to navigate to Global Secure Access and activate <em><strong>Microsoft traffic profile.</strong></em></p><blockquote><p><em>If you want to test all the features of Global Secure Access, including Microsoft Entra Internet Access and Private Access, there is a 90-day trial available for the Microsoft Entra Suite license.</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kW8P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kW8P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 424w, https://substackcdn.com/image/fetch/$s_!kW8P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 848w, https://substackcdn.com/image/fetch/$s_!kW8P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 1272w, https://substackcdn.com/image/fetch/$s_!kW8P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kW8P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png" width="1456" height="989" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:989,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:235140,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kW8P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 424w, https://substackcdn.com/image/fetch/$s_!kW8P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 848w, https://substackcdn.com/image/fetch/$s_!kW8P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 1272w, https://substackcdn.com/image/fetch/$s_!kW8P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F243f809c-3e9f-4e92-84e2-acdf37ea93d2_1867x1268.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After enabling the profile, we need to assign it to a group of users.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WDJE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WDJE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 424w, https://substackcdn.com/image/fetch/$s_!WDJE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 848w, https://substackcdn.com/image/fetch/$s_!WDJE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 1272w, https://substackcdn.com/image/fetch/$s_!WDJE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WDJE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png" width="1400" height="1253" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1253,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:208409,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WDJE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 424w, https://substackcdn.com/image/fetch/$s_!WDJE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 848w, https://substackcdn.com/image/fetch/$s_!WDJE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 1272w, https://substackcdn.com/image/fetch/$s_!WDJE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff067ce4b-25be-4a36-9910-36825657aaea_1400x1253.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><em><strong>NOTE</strong>: Access is granted only to users directly in the group and does not extend to nested groups.</em></p></blockquote><p>We also need to activate Tenant Restriction within the <strong>Session Management</strong> section under Settings.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eCXI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eCXI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 424w, https://substackcdn.com/image/fetch/$s_!eCXI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 848w, https://substackcdn.com/image/fetch/$s_!eCXI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 1272w, https://substackcdn.com/image/fetch/$s_!eCXI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eCXI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png" width="1294" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1294,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:49140,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eCXI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 424w, https://substackcdn.com/image/fetch/$s_!eCXI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 848w, https://substackcdn.com/image/fetch/$s_!eCXI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 1272w, https://substackcdn.com/image/fetch/$s_!eCXI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9790ddfe-11e7-47b7-8e6d-190c1853e476_1294x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The final step is to deploy the client to your Windows devices, which is a requirement to tunnel network traffic to the Global Secure Access service. You can download the client from the <strong>Client Download</strong> section or directly via <a href="https://aka.ms/GlobalSecureAccess-windows">this link</a>.</p><p>If you plan to deploy the client using Microsoft Intune or other device management tool, you can utilize the following commands:</p><pre><code>GlobalSecureAccessClient.exe /install /quiet</code></pre><pre><code>GlobalSecureAccessClient.exe /uninstall</code></pre><p>Once the client is installed on your device you should check the status and make sure that the Microsoft traffic profile was downloaded. In the system tray, right-click the Global Secure Access Client and select <em><strong>Advanced Diagnostics</strong></em>. In the <em><strong>Forwarding profile</strong></em>, you should see <em><strong>Microsoft 365 rules</strong></em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cs6N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cs6N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 424w, https://substackcdn.com/image/fetch/$s_!cs6N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 848w, https://substackcdn.com/image/fetch/$s_!cs6N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 1272w, https://substackcdn.com/image/fetch/$s_!cs6N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cs6N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png" width="1022" height="888" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:888,&quot;width&quot;:1022,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:39423,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cs6N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 424w, https://substackcdn.com/image/fetch/$s_!cs6N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 848w, https://substackcdn.com/image/fetch/$s_!cs6N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 1272w, https://substackcdn.com/image/fetch/$s_!cs6N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a57b485-a127-4920-a8bf-e93c0b61b1c4_1022x888.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If everything was set up correctly, you should no longer be able to log in to Microsoft Personal OneDrive and Mail. The same restriction should apply if you attempt to use a separate account from an unknown tenant.</p><p>Test logging in with a separate account from an unknown tenant:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1WzU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1WzU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 424w, https://substackcdn.com/image/fetch/$s_!1WzU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 848w, https://substackcdn.com/image/fetch/$s_!1WzU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 1272w, https://substackcdn.com/image/fetch/$s_!1WzU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1WzU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png" width="933" height="801" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:801,&quot;width&quot;:933,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:227274,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1WzU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 424w, https://substackcdn.com/image/fetch/$s_!1WzU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 848w, https://substackcdn.com/image/fetch/$s_!1WzU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 1272w, https://substackcdn.com/image/fetch/$s_!1WzU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07fa9c29-fdd7-43d5-84f8-97bf5b9b7113_933x801.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Of course, there are always exceptions. If you want to allow access to a specific tenant, you need to add the organization first by navigating to <em>External Identities &gt; <strong>Cross-tenant access settings</strong></em> and selecting <em><strong>Add organization</strong></em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!buPm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!buPm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 424w, https://substackcdn.com/image/fetch/$s_!buPm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 848w, https://substackcdn.com/image/fetch/$s_!buPm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 1272w, https://substackcdn.com/image/fetch/$s_!buPm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!buPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png" width="1414" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1414,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98318,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!buPm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 424w, https://substackcdn.com/image/fetch/$s_!buPm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 848w, https://substackcdn.com/image/fetch/$s_!buPm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 1272w, https://substackcdn.com/image/fetch/$s_!buPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cff99dd-f32f-4176-8a56-59f6b6fb2b11_1414x795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once the organization is added, you need to configure the tenant restrictions for that specific tenant to allow access.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QcBU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QcBU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 424w, https://substackcdn.com/image/fetch/$s_!QcBU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 848w, https://substackcdn.com/image/fetch/$s_!QcBU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 1272w, https://substackcdn.com/image/fetch/$s_!QcBU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QcBU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png" width="1142" height="848" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:848,&quot;width&quot;:1142,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73500,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QcBU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 424w, https://substackcdn.com/image/fetch/$s_!QcBU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 848w, https://substackcdn.com/image/fetch/$s_!QcBU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 1272w, https://substackcdn.com/image/fetch/$s_!QcBU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4192977a-d6c4-47e2-bd53-0b959e60d6d6_1142x848.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you haven't yet tried Global Secure Access, now is the perfect time to explore its capabilities. As Global Secure Access is a comprehensive product, I plan to dive deeper into its features and functionalities in future blog posts. Stay tuned for more insights and tips on maximizing the benefits of this essential security solution.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Switching Off Self-Service Password Reset for Administrators in Microsoft Entra]]></title><description><![CDATA[Recently, I assisted a client in implementing the Microsoft Entra self-service password reset (SSPR) feature. Their requirement was that this service be enabled only for non-privileged accounts.]]></description><link>https://www.matej.guru/p/switching-off-self-service-password</link><guid isPermaLink="false">https://www.matej.guru/p/switching-off-self-service-password</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Mon, 22 Apr 2024 06:01:18 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c996af7e-f578-46ad-80a9-23067db0dff2_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Recently, I assisted a client in implementing the <a href="https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr">Microsoft Entra self-service password reset (SSPR)</a> feature. Their requirement was that this service be enabled only for non-privileged accounts. The policy was tied to a user group which did not include administrative accounts; however, SSPR was still operational for administrative accounts. This experience is expected as it is by default permitted to reset passwords for administrative roles such as Global Administrator, Exchange Administrator, Intune Administrator, Security Administrator, etc.</p><blockquote><p><strong><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-policy#administrator-reset-policy-differences">Microsoft Learn:</a></strong><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-policy#administrator-reset-policy-differences"> Administrator reset policy differences</a>.</p></blockquote><p>A two-gate policy is enabled which mandates two forms of authentication evidence (e.g., entering a code from the Microsoft Authenticator app plus an SMS code). While the two-gate policy offers significant protection, it is still possible to disable the default policy to prevent administrators from changing their own passwords using the <strong>Update-MgPolicyAuthorizationPolicy</strong> PowerShell cmdlet.</p><p>First, the Microsoft.Graph.Identity.SignIns Module must be installed. Use the following command to install this package via PowerShellGet:</p><pre><code>Install-Module -Name Microsoft.Graph.Identity.SignIns</code></pre><p>Once the module is installed, it should be imported, and the Connect-MgGraph cmdlet must be invoked before executing any commands that interact with Microsoft Graph. This cmdlet retrieves the access token through the Microsoft Authentication Library.</p><pre><code>Import-Module Microsoft.Graph.Identity.SignIns
Connect-MgGraph -Scopes Policy.ReadWrite.Authorization</code></pre><p>If you haven't already, you will need to provide consent for Microsoft Graph.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nspr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nspr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 424w, https://substackcdn.com/image/fetch/$s_!nspr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 848w, https://substackcdn.com/image/fetch/$s_!nspr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 1272w, https://substackcdn.com/image/fetch/$s_!nspr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nspr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png" width="852" height="1161" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1161,&quot;width&quot;:852,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:239239,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nspr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 424w, https://substackcdn.com/image/fetch/$s_!nspr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 848w, https://substackcdn.com/image/fetch/$s_!nspr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 1272w, https://substackcdn.com/image/fetch/$s_!nspr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86162c1-7a30-499a-b4d3-7010835b9a67_852x1161.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once connected, we can check the current setting for AllowedToUseSspr, which shows whether administrators of the tenant are permitted to use the SSPR.</p><pre><code>Get-MgPolicyAuthorizationPolicy | select AllowedToUseSspr</code></pre><p>To disable SSPR for administrators, we need to set the value to FALSE.</p><pre><code>$params = @{
allowedToUseSSPR = $false
}
Update-MgPolicyAuthorizationPolicy -BodyParameter $params</code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tyEk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tyEk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 424w, https://substackcdn.com/image/fetch/$s_!tyEk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 848w, https://substackcdn.com/image/fetch/$s_!tyEk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 1272w, https://substackcdn.com/image/fetch/$s_!tyEk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tyEk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png" width="1456" height="633" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:633,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30319,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tyEk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 424w, https://substackcdn.com/image/fetch/$s_!tyEk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 848w, https://substackcdn.com/image/fetch/$s_!tyEk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 1272w, https://substackcdn.com/image/fetch/$s_!tyEk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F067253f2-e6a8-4743-8481-edcef9502b7a_1618x703.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The policy takes effect within 60 minutes. Our test confirms that the administrator indeed cannot use the SSPR service anymore.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ARWb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ARWb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 424w, https://substackcdn.com/image/fetch/$s_!ARWb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 848w, https://substackcdn.com/image/fetch/$s_!ARWb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 1272w, https://substackcdn.com/image/fetch/$s_!ARWb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ARWb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png" width="1456" height="974" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:974,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:147698,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ARWb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 424w, https://substackcdn.com/image/fetch/$s_!ARWb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 848w, https://substackcdn.com/image/fetch/$s_!ARWb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 1272w, https://substackcdn.com/image/fetch/$s_!ARWb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594e4d38-facb-4dc8-9670-26919cc0bacd_1577x1055.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I hope you find this information useful for improving your administrator&#8217;s security.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Plus Addressing in Exchange Online: Solution for Admin Accounts Without a Mailbox?]]></title><description><![CDATA[One of the cornerstone principles in maintaining a secure Microsoft 365 environment is the segregation of administrative and everyday user accounts. This means categorically avoiding the use of the same accounts for administrative tasks and daily activities, such as browsing the internet or managing emails. Moreover, a key security practice is to ensure that administrative accounts are not equipped with mailboxes to mitigate the risk of phishing attacks. Adhering to these guidelines is not just recommended; it's a critical step towards securing your digital infrastructure. If you haven't segregated your accounts yet, it's imperative to take action without delay.]]></description><link>https://www.matej.guru/p/plus-addressing-in-exchange-online</link><guid isPermaLink="false">https://www.matej.guru/p/plus-addressing-in-exchange-online</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Sun, 11 Feb 2024 16:46:55 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/83dae4a7-db9a-4f73-95bb-94c8dd1165a1_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>One of the cornerstone principles in maintaining a secure Microsoft 365 environment is the segregation of administrative and everyday user accounts. This means categorically avoiding the use of the same accounts for administrative tasks and daily activities, such as browsing the internet or managing emails. Moreover, a key security practice is to ensure that administrative accounts are not equipped with mailboxes to mitigate the risk of phishing attacks. Adhering to these guidelines is not just recommended; it's a critical step towards securing your digital infrastructure. If you haven't segregated your accounts yet, it's imperative to take action without delay.</p><p>Upon implementing these security measures, you'll likely encounter a practical challenge: how can admin accounts, now devoid of mailboxes, receive essential notifications for Microsoft 365 environment management? This question becomes particularly pressing in scenarios such as when a user requests admin consent for an app that requires permissions to access organizational data, or when using Entra Privileged Identity Management (PIM), where it's necessary for an admin to be informed about assigned rights directly in their main inbox.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XiVU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XiVU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 424w, https://substackcdn.com/image/fetch/$s_!XiVU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 848w, https://substackcdn.com/image/fetch/$s_!XiVU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 1272w, https://substackcdn.com/image/fetch/$s_!XiVU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XiVU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png" width="1456" height="599" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/208107f1-467b-463d-9da1-7849c0614654_2028x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:599,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107075,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XiVU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 424w, https://substackcdn.com/image/fetch/$s_!XiVU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 848w, https://substackcdn.com/image/fetch/$s_!XiVU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 1272w, https://substackcdn.com/image/fetch/$s_!XiVU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208107f1-467b-463d-9da1-7849c0614654_2028x834.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>To mitigate the threat of malicious apps misleading users into providing access, user consent should only proceed with admin approval.</p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wYLf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wYLf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 424w, https://substackcdn.com/image/fetch/$s_!wYLf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 848w, https://substackcdn.com/image/fetch/$s_!wYLf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 1272w, https://substackcdn.com/image/fetch/$s_!wYLf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wYLf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png" width="1456" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:151955,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wYLf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 424w, https://substackcdn.com/image/fetch/$s_!wYLf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 848w, https://substackcdn.com/image/fetch/$s_!wYLf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 1272w, https://substackcdn.com/image/fetch/$s_!wYLf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3125744f-2ae9-476d-8a6e-bcbb92f92091_1679x1003.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Fortunately, this dilemma has a straightforward solution: the Plus Addressing feature in Exchange Online. This functionality elegantly bridges the gap, ensuring that admin accounts can receive critical notifications without compromising on security protocols.</p><blockquote><p><strong><a href="https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/plus-addressing-in-exchange-online">Microsoft Learn</a></strong><a href="https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/plus-addressing-in-exchange-online">: Plus Addressing in Exchange Online</a></p></blockquote><p>Plus Addressing in Exchange Online allows us to create unique email addresses for mailbox by adding a plus sign ('+') and a keyword to a standard email address.</p><div class="pullquote"><p>Starting from May 2022, plus addressing, is activated by default in Exchange Online.</p></div><p>How does it work? We simply need to add the address using the format &lt;local-part&gt;+&lt;tag&gt;@&lt;domain&gt; as follows:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ubDI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ubDI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 424w, https://substackcdn.com/image/fetch/$s_!ubDI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 848w, https://substackcdn.com/image/fetch/$s_!ubDI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 1272w, https://substackcdn.com/image/fetch/$s_!ubDI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ubDI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png" width="1456" height="660" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:660,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:179883,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ubDI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 424w, https://substackcdn.com/image/fetch/$s_!ubDI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 848w, https://substackcdn.com/image/fetch/$s_!ubDI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 1272w, https://substackcdn.com/image/fetch/$s_!ubDI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2ba2779-1c0e-4630-8957-fe9573220599_1873x849.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In my example, the email address for my administrative account is configured as <em><strong>AdeleV+365.adm</strong>@mydomain.com</em>, ensuring that emails are routed directly to my main mailbox at <em><strong>AdeleV</strong>@mydomain.com</em>.</p><p>A simple test of both scenarios confirms that the mail is delivered to the main mailbox of the user <em>AdeleV@mydomain.com</em>:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z03P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z03P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 424w, https://substackcdn.com/image/fetch/$s_!Z03P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 848w, https://substackcdn.com/image/fetch/$s_!Z03P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 1272w, https://substackcdn.com/image/fetch/$s_!Z03P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z03P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png" width="1456" height="857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:857,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:395243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z03P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 424w, https://substackcdn.com/image/fetch/$s_!Z03P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 848w, https://substackcdn.com/image/fetch/$s_!Z03P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 1272w, https://substackcdn.com/image/fetch/$s_!Z03P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc045e73a-4232-481d-b18a-ff49ea46d7a5_2466x1451.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kSOO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kSOO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 424w, https://substackcdn.com/image/fetch/$s_!kSOO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 848w, https://substackcdn.com/image/fetch/$s_!kSOO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 1272w, https://substackcdn.com/image/fetch/$s_!kSOO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kSOO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png" width="1456" height="712" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:712,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:336373,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kSOO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 424w, https://substackcdn.com/image/fetch/$s_!kSOO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 848w, https://substackcdn.com/image/fetch/$s_!kSOO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 1272w, https://substackcdn.com/image/fetch/$s_!kSOO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba70ef70-7c68-4caf-b875-06c74d1e6c5e_2470x1208.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This wraps up the key insight I aimed to share through this post: a seemingly minor yet profoundly impactful tip for the efficient management of Microsoft 365 environments. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Password-less: use FIDO2 as smart card]]></title><description><![CDATA[In today's digital age, where security and privacy are extremely important, we are facing the task of making sure that our devices and services have secure logins. One of the most exciting areas in this context is the transition to password-less authentication, enabling users to access their systems easily and securely. Despite the challenges, we must embark on this journey and explore new technologies that help us achieve this goal.]]></description><link>https://www.matej.guru/p/password-less-use-fido2-as-smart</link><guid isPermaLink="false">https://www.matej.guru/p/password-less-use-fido2-as-smart</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Tue, 24 Oct 2023 20:43:06 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5a229d5d-a65d-4a62-8b01-3742d2eb3909_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In today's digital age, where security and privacy are extremely important, we are facing the task of making sure that our devices and services have secure logins. One of the most exciting areas in this context is the transition to password-less authentication, enabling users to access their systems easily and securely. Despite the challenges, we must embark on this journey and explore new technologies that help us achieve this goal.</p><p>An intriguing challenge for me was figuring out how to implement a modern login method for Windows devices using a dedicated hardware authentication technique.  While smart cards have long been a traditional method of authentication, the question arises: have they become obsolete and unusable in the era of FIDO2 keys? I believe they have not, as they can still effectively cover certain user scenarios. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Using YubiKey and PIV</h3><p>One of the features of FIDO2 keys is their ability to also function as a "smart card" allowing you to store your own digital certificate on them. This opens up new possibilities and enhances security for Windows device logins.</p><p>I personally use the YubiKey 5 NFC, which offers Personal Identity Verification (PIV) functionality.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!REhq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!REhq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 424w, https://substackcdn.com/image/fetch/$s_!REhq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 848w, https://substackcdn.com/image/fetch/$s_!REhq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 1272w, https://substackcdn.com/image/fetch/$s_!REhq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!REhq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png" width="1185" height="493" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:493,&quot;width&quot;:1185,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74433,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!REhq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 424w, https://substackcdn.com/image/fetch/$s_!REhq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 848w, https://substackcdn.com/image/fetch/$s_!REhq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 1272w, https://substackcdn.com/image/fetch/$s_!REhq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc3509f-224f-4a90-903f-eb44698c1e18_1185x493.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>Personal Identity Verification (PIV) is a set of standards and specifications for smart card-based authentication of individuals in a government or enterprise environment.</p></div><p>Before you can store a certificate on the FIDO2 key, several prerequisites need to be met. Among them is the installation of the YubiKey Smart Card Minidriver for Windows which is available <a href="https://www.yubico.com/support/download/smart-card-drivers-tools/">here</a>. Additionally, setting a PIN, PUK, and Management Key on the FIDO2 key with YubiKey Manager is necessary to securely store the certificate.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uuSs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uuSs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 424w, https://substackcdn.com/image/fetch/$s_!uuSs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 848w, https://substackcdn.com/image/fetch/$s_!uuSs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 1272w, https://substackcdn.com/image/fetch/$s_!uuSs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uuSs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png" width="1195" height="351" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:351,&quot;width&quot;:1195,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34698,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uuSs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 424w, https://substackcdn.com/image/fetch/$s_!uuSs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 848w, https://substackcdn.com/image/fetch/$s_!uuSs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 1272w, https://substackcdn.com/image/fetch/$s_!uuSs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6357546-f0f2-4b11-b47e-4d39ec382bb2_1195x351.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p><strong>Note:</strong> I had to set the Management Key back to the default value because of <a href="https://support.yubico.com/hc/en-us/articles/360013790519-Troubleshooting-SCARD-W-SECURITY-VIOLATION">SCARD_W_SECURITY_VIOLATION (0x8010006A)</a> error while issuing the certificate. </p></div><p>Now that we have our FIDO2 key ready, we need to prepare Certificate Authority templates. Those of you who have used or are still using traditional smart cards are likely familiar with the "Enroll On Behalf Of..." process. The idea is that an administrator can issue a certificate on behalf of a user. For this purpose, we first need to prepare an Enrollment Agent certificate.</p><h3>Preparing the Enrollment Agent Templates</h3><p>An Enrollment Agent certificate is used to grant a highly privileged right to issue certificates on behalf of other individuals, including administrative accounts. This certificate must be protected very securely since it grants the high privilege of issuing certificates for others. Enrollment rights should be restricted as much as possible. Additionally, you might want to store the Enrollment Agent certificate in the TPM (Trusted Platform Module) to reduce the risk of theft, or even storing it on a FIDO2 key.</p><p>Duplicate the <strong>Enrollment Agent</strong> template on your Windows Certificate Authority Server and name it accordingly:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vK0g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK0g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 424w, https://substackcdn.com/image/fetch/$s_!vK0g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 848w, https://substackcdn.com/image/fetch/$s_!vK0g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 1272w, https://substackcdn.com/image/fetch/$s_!vK0g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK0g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png" width="417" height="587.1753794266442" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:593,&quot;resizeWidth&quot;:417,&quot;bytes&quot;:96749,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vK0g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 424w, https://substackcdn.com/image/fetch/$s_!vK0g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 848w, https://substackcdn.com/image/fetch/$s_!vK0g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 1272w, https://substackcdn.com/image/fetch/$s_!vK0g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd33b5b1d-4dec-47d0-accc-64b62e68dea1_593x835.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Change the <strong>Compatibility Settings</strong> to the highest operating system version: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XZ9b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XZ9b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 424w, https://substackcdn.com/image/fetch/$s_!XZ9b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 848w, https://substackcdn.com/image/fetch/$s_!XZ9b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 1272w, https://substackcdn.com/image/fetch/$s_!XZ9b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XZ9b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png" width="424" height="594.738255033557" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:836,&quot;width&quot;:596,&quot;resizeWidth&quot;:424,&quot;bytes&quot;:87442,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XZ9b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 424w, https://substackcdn.com/image/fetch/$s_!XZ9b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 848w, https://substackcdn.com/image/fetch/$s_!XZ9b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 1272w, https://substackcdn.com/image/fetch/$s_!XZ9b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db9e65c-d4f5-4592-a1c1-6605e27cf02a_596x836.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Configure <strong>Request Handling:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OFl8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OFl8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 424w, https://substackcdn.com/image/fetch/$s_!OFl8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 848w, https://substackcdn.com/image/fetch/$s_!OFl8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 1272w, https://substackcdn.com/image/fetch/$s_!OFl8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OFl8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png" width="422" height="591.9328859060403" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:836,&quot;width&quot;:596,&quot;resizeWidth&quot;:422,&quot;bytes&quot;:139439,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OFl8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 424w, https://substackcdn.com/image/fetch/$s_!OFl8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 848w, https://substackcdn.com/image/fetch/$s_!OFl8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 1272w, https://substackcdn.com/image/fetch/$s_!OFl8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9b9a4c6-9229-458f-a652-c6aeeb964773_596x836.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Select <strong>Key Storage Provider</strong> as Provider Category and <strong>Microsoft Platform Crypto Provider</strong> to store the certificate in the TPM: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QmLe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QmLe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 424w, https://substackcdn.com/image/fetch/$s_!QmLe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 848w, https://substackcdn.com/image/fetch/$s_!QmLe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 1272w, https://substackcdn.com/image/fetch/$s_!QmLe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QmLe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png" width="423" height="594.3327731092437" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:836,&quot;width&quot;:595,&quot;resizeWidth&quot;:423,&quot;bytes&quot;:123459,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QmLe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 424w, https://substackcdn.com/image/fetch/$s_!QmLe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 848w, https://substackcdn.com/image/fetch/$s_!QmLe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 1272w, https://substackcdn.com/image/fetch/$s_!QmLe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7319d467-18ff-45e6-958b-119c0eaaec5c_595x836.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Configure <strong>Read</strong> and <strong>Enroll</strong> permissions for your privileged accounts:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9FIL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9FIL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 424w, https://substackcdn.com/image/fetch/$s_!9FIL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 848w, https://substackcdn.com/image/fetch/$s_!9FIL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 1272w, https://substackcdn.com/image/fetch/$s_!9FIL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9FIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png" width="415" height="584.3591905564924" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:593,&quot;resizeWidth&quot;:415,&quot;bytes&quot;:127189,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9FIL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 424w, https://substackcdn.com/image/fetch/$s_!9FIL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 848w, https://substackcdn.com/image/fetch/$s_!9FIL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 1272w, https://substackcdn.com/image/fetch/$s_!9FIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4953a530-5897-4992-bb61-a9b014a5ef2b_593x835.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>Certificate must be protected very securely since it grants the high privilege of issuing certificates for others.</p></div><p>Use <em><strong>certutil -store -user My</strong></em> to check if certificate is stored in Microsoft Platform Crypto Provider:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8xVG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8xVG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 424w, https://substackcdn.com/image/fetch/$s_!8xVG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 848w, https://substackcdn.com/image/fetch/$s_!8xVG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 1272w, https://substackcdn.com/image/fetch/$s_!8xVG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8xVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png" width="1456" height="723" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:723,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:295679,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8xVG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 424w, https://substackcdn.com/image/fetch/$s_!8xVG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 848w, https://substackcdn.com/image/fetch/$s_!8xVG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 1272w, https://substackcdn.com/image/fetch/$s_!8xVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7b4904-7c5c-4d7f-94e8-b9fbfb3064da_1756x872.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Preparing the Smart Card Templates for FIDO2 key</h3><p>Now that we have the Enrollment Agent certificate in place, the next step is to issue the Smart Card Template for our FIDO2 key.</p><p>Duplicate the <strong>Smartcard Logon</strong> template on your Windows Certificate Authority Server and name it accordingly:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8wmr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8wmr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 424w, https://substackcdn.com/image/fetch/$s_!8wmr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 848w, https://substackcdn.com/image/fetch/$s_!8wmr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 1272w, https://substackcdn.com/image/fetch/$s_!8wmr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8wmr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png" width="428" height="599.6308724832214" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:596,&quot;resizeWidth&quot;:428,&quot;bytes&quot;:185498,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8wmr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 424w, https://substackcdn.com/image/fetch/$s_!8wmr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 848w, https://substackcdn.com/image/fetch/$s_!8wmr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 1272w, https://substackcdn.com/image/fetch/$s_!8wmr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd461980-fc19-4b6c-b33b-ade40b9cb11a_596x835.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Change the <strong>Compatibility Settings</strong> to the highest operating system version: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fnuM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fnuM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 424w, https://substackcdn.com/image/fetch/$s_!fnuM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 848w, https://substackcdn.com/image/fetch/$s_!fnuM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 1272w, https://substackcdn.com/image/fetch/$s_!fnuM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fnuM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png" width="428" height="603.0909090909091" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d857b5b0-0504-4291-9149-bcf9a668c197_594x837.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:837,&quot;width&quot;:594,&quot;resizeWidth&quot;:428,&quot;bytes&quot;:130094,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fnuM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 424w, https://substackcdn.com/image/fetch/$s_!fnuM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 848w, https://substackcdn.com/image/fetch/$s_!fnuM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 1272w, https://substackcdn.com/image/fetch/$s_!fnuM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd857b5b0-0504-4291-9149-bcf9a668c197_594x837.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Configure <strong>Request Handling:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NTdA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NTdA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 424w, https://substackcdn.com/image/fetch/$s_!NTdA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 848w, https://substackcdn.com/image/fetch/$s_!NTdA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 1272w, https://substackcdn.com/image/fetch/$s_!NTdA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NTdA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png" width="441" height="618.1411764705882" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:595,&quot;resizeWidth&quot;:441,&quot;bytes&quot;:157830,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NTdA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 424w, https://substackcdn.com/image/fetch/$s_!NTdA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 848w, https://substackcdn.com/image/fetch/$s_!NTdA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 1272w, https://substackcdn.com/image/fetch/$s_!NTdA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a0bc228-7c9b-4ef1-9451-9db61a10d29b_595x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Select <strong>Key Storage Provider</strong> as Provider Category and <strong>Microsoft Smart Card Key Storage Provider</strong> to store the certificate on FIDO2 key: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uGZA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uGZA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 424w, https://substackcdn.com/image/fetch/$s_!uGZA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 848w, https://substackcdn.com/image/fetch/$s_!uGZA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 1272w, https://substackcdn.com/image/fetch/$s_!uGZA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uGZA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png" width="445" height="625.1011804384485" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:833,&quot;width&quot;:593,&quot;resizeWidth&quot;:445,&quot;bytes&quot;:149919,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uGZA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 424w, https://substackcdn.com/image/fetch/$s_!uGZA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 848w, https://substackcdn.com/image/fetch/$s_!uGZA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 1272w, https://substackcdn.com/image/fetch/$s_!uGZA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa855b0b-018f-4a38-94a0-c25721b5479d_593x833.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Configure <strong>Issuance Requirements</strong>:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f8JS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f8JS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 424w, https://substackcdn.com/image/fetch/$s_!f8JS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 848w, https://substackcdn.com/image/fetch/$s_!f8JS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 1272w, https://substackcdn.com/image/fetch/$s_!f8JS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f8JS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png" width="450" height="631.8181818181819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:594,&quot;resizeWidth&quot;:450,&quot;bytes&quot;:177165,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f8JS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 424w, https://substackcdn.com/image/fetch/$s_!f8JS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 848w, https://substackcdn.com/image/fetch/$s_!f8JS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 1272w, https://substackcdn.com/image/fetch/$s_!f8JS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f2181c-e75c-4742-8c49-b2b7b620a635_594x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Configure <strong>Read</strong> and <strong>Enroll</strong> permissions for your privileged accounts:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_FMD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_FMD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 424w, https://substackcdn.com/image/fetch/$s_!_FMD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 848w, https://substackcdn.com/image/fetch/$s_!_FMD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 1272w, https://substackcdn.com/image/fetch/$s_!_FMD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_FMD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png" width="455" height="637.6138279932546" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/acd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:831,&quot;width&quot;:593,&quot;resizeWidth&quot;:455,&quot;bytes&quot;:131995,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_FMD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 424w, https://substackcdn.com/image/fetch/$s_!_FMD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 848w, https://substackcdn.com/image/fetch/$s_!_FMD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 1272w, https://substackcdn.com/image/fetch/$s_!_FMD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facd14283-a9c5-44bf-aaa2-c50e627f3243_593x831.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Issuing the certificate</h3><p>Here's how the process of issuing a certificate on a FIDO2 key on behalf of another user typically looks like:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wNwX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wNwX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 424w, https://substackcdn.com/image/fetch/$s_!wNwX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 848w, https://substackcdn.com/image/fetch/$s_!wNwX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 1272w, https://substackcdn.com/image/fetch/$s_!wNwX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wNwX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png" width="1456" height="538" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:538,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:209004,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wNwX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 424w, https://substackcdn.com/image/fetch/$s_!wNwX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 848w, https://substackcdn.com/image/fetch/$s_!wNwX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 1272w, https://substackcdn.com/image/fetch/$s_!wNwX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aacd11f-16b2-42be-af3b-8cb74c8b1967_1598x590.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Select the <strong>Enrollment Agent</strong> Certificate installed previously: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zTIn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zTIn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 424w, https://substackcdn.com/image/fetch/$s_!zTIn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 848w, https://substackcdn.com/image/fetch/$s_!zTIn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 1272w, https://substackcdn.com/image/fetch/$s_!zTIn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zTIn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png" width="943" height="692" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:692,&quot;width&quot;:943,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71144,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zTIn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 424w, https://substackcdn.com/image/fetch/$s_!zTIn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 848w, https://substackcdn.com/image/fetch/$s_!zTIn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 1272w, https://substackcdn.com/image/fetch/$s_!zTIn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa923d5d9-fd0b-449d-ae8e-eef85458c848_943x692.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Select the Smart Card Template:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gIep!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gIep!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 424w, https://substackcdn.com/image/fetch/$s_!gIep!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 848w, https://substackcdn.com/image/fetch/$s_!gIep!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 1272w, https://substackcdn.com/image/fetch/$s_!gIep!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gIep!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png" width="938" height="684" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:684,&quot;width&quot;:938,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:81818,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gIep!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 424w, https://substackcdn.com/image/fetch/$s_!gIep!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 848w, https://substackcdn.com/image/fetch/$s_!gIep!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 1272w, https://substackcdn.com/image/fetch/$s_!gIep!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F725b5ee4-bec9-4eda-b650-12281976ed4d_938x684.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Select a user to whom you want to issue the certificate:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ERm7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ERm7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 424w, https://substackcdn.com/image/fetch/$s_!ERm7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 848w, https://substackcdn.com/image/fetch/$s_!ERm7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 1272w, https://substackcdn.com/image/fetch/$s_!ERm7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ERm7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png" width="943" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:691,&quot;width&quot;:943,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:84285,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ERm7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 424w, https://substackcdn.com/image/fetch/$s_!ERm7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 848w, https://substackcdn.com/image/fetch/$s_!ERm7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 1272w, https://substackcdn.com/image/fetch/$s_!ERm7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63c0d9a7-56ef-4660-b0cf-38c724a26cbe_943x691.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Enter FIDO2 PIN code:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6Sj7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6Sj7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 424w, https://substackcdn.com/image/fetch/$s_!6Sj7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 848w, https://substackcdn.com/image/fetch/$s_!6Sj7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 1272w, https://substackcdn.com/image/fetch/$s_!6Sj7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6Sj7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png" width="935" height="682" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:682,&quot;width&quot;:935,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65485,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6Sj7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 424w, https://substackcdn.com/image/fetch/$s_!6Sj7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 848w, https://substackcdn.com/image/fetch/$s_!6Sj7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 1272w, https://substackcdn.com/image/fetch/$s_!6Sj7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a34a3c-c786-462c-b293-23cac3bd05a9_935x682.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VC2B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VC2B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 424w, https://substackcdn.com/image/fetch/$s_!VC2B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 848w, https://substackcdn.com/image/fetch/$s_!VC2B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 1272w, https://substackcdn.com/image/fetch/$s_!VC2B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VC2B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png" width="938" height="685" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:685,&quot;width&quot;:938,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51208,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VC2B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 424w, https://substackcdn.com/image/fetch/$s_!VC2B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 848w, https://substackcdn.com/image/fetch/$s_!VC2B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 1272w, https://substackcdn.com/image/fetch/$s_!VC2B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5eb0a0a4-9544-4910-890a-d178ee7ae61d_938x685.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Congratulations! If everything has been set up correctly, you should now be able to successfully log in using a FIDO2 key in a Windows environment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e4Eb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e4Eb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 424w, https://substackcdn.com/image/fetch/$s_!e4Eb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 848w, https://substackcdn.com/image/fetch/$s_!e4Eb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 1272w, https://substackcdn.com/image/fetch/$s_!e4Eb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e4Eb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png" width="1456" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1220291,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e4Eb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 424w, https://substackcdn.com/image/fetch/$s_!e4Eb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 848w, https://substackcdn.com/image/fetch/$s_!e4Eb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 1272w, https://substackcdn.com/image/fetch/$s_!e4Eb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d272712-6a62-44ba-ae42-40b253829ad0_1523x1136.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Smart Card Removal Behavior</h3><p>One last important setting you may want to configure is the Smart Card Removal Behavior to automatically lock the workstation. To achieve this, you'll need to do two things:</p><ol><li><p><strong>Group Policy Setting:</strong> Set the GPO (Group Policy Object) policy "Interactive logon: Smart card removal behavior" to the value "Lock Workstation." This policy determines what happens when the smart card is removed from the reader during an active session. Locking the workstation ensures that unauthorized access is prevented when the FIDO2 key is removed.</p></li><li><p><strong>Service Startup:</strong> Set the startup type for the Windows service "Smart Card Removal Policy" to automatic. This service is responsible for enforcing the Smart Card Removal Behavior policy.</p></li></ol><p>By implementing these settings, you enhance the security of your authentication process. When a user removes the FIDO2 key, the workstation will automatically lock, safeguarding sensitive data and ensuring that only authorized users can access the system.</p><h3>Final thoughts</h3><p>With these final configurations in place, your Windows environment is now equipped with a robust and modern authentication system that combines the benefits of FIDO2 keys with the security features of smart card technology.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.matej.guru/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Another security blog...! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Windows LAPS: Create local administrator account via Microsoft Intune]]></title><description><![CDATA[When deploying LAPS in your environment you might want to disable the build in local administrator account and create a custom one. Previously with legacy LAPS this was possible during installation with CUSTOMADMINNAME parameter, for example: msiexec /q /i LAPS.x64.msi CUSTOMADMINNAME=Hulk]]></description><link>https://www.matej.guru/p/windows-laps-create-local-administrator</link><guid isPermaLink="false">https://www.matej.guru/p/windows-laps-create-local-administrator</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Tue, 22 Aug 2023 20:22:58 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8feda170-7fee-4a0c-a900-879976db2e78_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When deploying LAPS in your environment you might want to disable the build in local administrator account and create a custom one. Previously with legacy LAPS this was possible during installation with <strong>CUSTOMADMINNAME</strong> parameter, for example:</p><pre><code>msiexec /q /i LAPS.x64.msi CUSTOMADMINNAME=Hulk</code></pre><blockquote><p><a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/windows-local-administrator-password-solution-with-microsoft/ba-p/3911999">Windows LAPS with Microsoft Entra ID now Generally Available!</a></p></blockquote><p>As Windows LAPS is now build-in directly to supported editions, there is no need for installation, resulting in the absence of the local administrator creation feature.</p><blockquote><p><strong><a href="https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview">Microsoft Learn</a></strong><a href="https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview">: What is Windows LAPS?</a></p></blockquote><p>However, this doesn't mean you can't achieve similar functionality through other means. I personally prefer utilizing the Microsoft Intune Remediations feature as it allows managing local accounts effectively with PowerShell Scripts. </p><blockquote><p><strong><a href="https://learn.microsoft.com/en-us/mem/intune/fundamentals/remediations#about-remediations">Microsoft Learn</a></strong><a href="https://learn.microsoft.com/en-us/mem/intune/fundamentals/remediations#about-remediations">: About Remediations</a></p></blockquote><p>The first step in process involves detecting the presence of a specific user on the target machine. In this example, I&#8217;m focusing on detecting the existence of the user "Hulk." This can be achieved using PowerShell, and here's how the detection script might look:</p><pre><code>$targetUser = "Hulk"
$existingUser = Get-LocalUser -Name $targetUser -ErrorAction SilentlyContinue
if ($existingUser) {
    Write-Host "User '$targetUser' exists."
    exit 0  # Exit with code 0 to indicate success
} else {
    Write-Host "User '$targetUser' does not exist."
    exit 1  # Exit with code 1 to indicate failure
}</code></pre><p>In this script, I&#8217;m using the <code>Get-LocalUser</code> cmdlet to check if the specified user exists on the machine. If the user is found, the script exits with a success code (0); otherwise, it exits with a failure code (1).</p><p>Now, let's move on to the remediation script. If the user doesn't exist, we want to create and enable the user account. The script below accomplishes this by generating a random password, creating the user account, and setting up appropriate account settings:</p><pre><code>function Generate-RandomPassword {
    param (
        [int]$length
    )
    $validChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&amp;*()_+-=[]{}|;:,.&lt;&gt;?'
    $password = ''
    1..$length | ForEach-Object {
        $randomChar = Get-Random -Minimum 0 -Maximum $validChars.Length
        $password += $validChars[$randomChar]
    }
       return $password
}
$targetUser = "Hulk"
# Check if the user already exists
$existingUser = Get-LocalUser -Name $targetUser -ErrorAction SilentlyContinue
if (!$existingUser) {
    # Create the user account with temporary password and enable it
    $password = Generate-RandomPassword 14  # Generate a random password
    $securePassword = ConvertTo-SecureString $password -AsPlainText -Force
    New-LocalUser -Name $targetUser -Password $securePassword -AccountNeverExpires -UserMayNotChangePassword -PasswordNeverExpires
    Enable-LocalUser -Name $targetUser
    Write-Host "User '$targetUser' created and enabled with a temporary password."
    exit 0  # Exit with code 0 to indicate success
} else {
    Write-Host "User '$targetUser' already exists. No remediation needed."
    exit 1  # Exit with code 1 to indicate failure
}</code></pre><p>This script generates a strong, temporary password using the <code>Generate-RandomPassword</code> function. Then, if the user doesn't already exist, it creates the user account with the generated password and enables the account. If the user already exists, the script indicates that no remediation is needed.</p><p>Create a script package in <em>Microsoft Intune &gt; Devices &gt; <strong>Remediations</strong></em>.</p><blockquote><p><strong><a href="https://learn.microsoft.com/en-us/mem/intune/fundamentals/remediations#deploy-the-script-packages">Microsoft Learn</a></strong><a href="https://learn.microsoft.com/en-us/mem/intune/fundamentals/remediations#deploy-the-script-packages">: Deploy the scripts packages</a></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xn4A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xn4A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Xn4A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Xn4A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Xn4A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xn4A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg" width="1162" height="1108" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1108,&quot;width&quot;:1162,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:150381,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Xn4A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Xn4A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Xn4A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Xn4A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bb6bb6-b12d-4103-803a-967505ff1044_1162x1108.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Make sure to select <strong>Run script in 64-bit PowerShell.</strong></em></p><blockquote><p><strong>NOTE: </strong>Created user is <strong>NOT</strong> added to local administrators group automatically.</p></blockquote><p>The final step is to add the created user to local administrators group. I&#8217;m doing that with Custom OMA-URI Setting:</p><p><strong>./Vendor/MSFT/Policy/Config/LocalUsersAndGroups/Configure</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G1PP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G1PP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!G1PP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!G1PP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!G1PP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G1PP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg" width="1456" height="861" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:861,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142788,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!G1PP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!G1PP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!G1PP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!G1PP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdabef6-1cf1-4d95-a51e-c29587979562_1522x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><pre><code>&lt;GroupConfiguration&gt;
&nbsp; &nbsp; &lt;accessgroup desc = "Administrators"&gt;
&nbsp; &nbsp; &nbsp; &nbsp; &lt;group action = "R" /&gt;
&nbsp; &nbsp; &nbsp; &nbsp; &lt;add member = "AzureAD\pcadmin@contoso.com"/&gt;
&nbsp; &nbsp; &nbsp; &nbsp; &lt;add member = "hulk"/&gt;
&nbsp; &nbsp; &lt;/accessgroup&gt;
&lt;/GroupConfiguration&gt;</code></pre><blockquote><p><strong><a href="https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups">Microsoft Learn:</a></strong><a href="https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups"> Policy CSP - LocalUsersAndGroups</a></p></blockquote><p>By combining these two scripts and deploying them through Microsoft Intune's remediation feature, you can effectively manage local user accounts across your environment. This approach not only provides the flexibility to create custom accounts but also allows for automation and consistency in user account management.</p><p>Now we can configure Windows LAPS with <a href="https://learn.microsoft.com/en-us/windows/client-management/mdm/laps-csp?WT.mc_id=Portal-fx#policiesadministratoraccountname">custom managed local administrator account</a>.</p>]]></content:encoded></item><item><title><![CDATA[Microsoft Defender Updates: Managing Rollouts with Precision]]></title><description><![CDATA[Regular antivirus client components updates are crucial for maintaining a strong security posture, but it's equally important to have control over which update channels are deployed to specific devices. Allowing Microsoft to automatically decide which devices become pilots can lead to potential issues, such as the installation of a beta channel with performance problems (e.g., increased processor usage).]]></description><link>https://www.matej.guru/p/microsoft-defender-updates-managing</link><guid isPermaLink="false">https://www.matej.guru/p/microsoft-defender-updates-managing</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Tue, 22 Aug 2023 19:29:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/48e6b2dd-4dfb-4b3c-8148-3169ba095e0e_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Regular antivirus client components updates are crucial for maintaining a strong security posture, but it's equally important to have control over which update channels are deployed to specific devices. Allowing Microsoft to automatically decide which devices become pilots can lead to potential issues, such as the installation of a beta channel with performance problems (e.g., increased processor usage).<br><br>Microsoft Defender offers multiple platform update channels. Here's an overview of the available channels:</p><ul><li><p><strong>Beta Channel</strong>: Devices set to this channel will be the first to receive new updates. For use in (manual) test environments only and a limited number of devices.</p></li><li><p><strong>Current Channel (Preview)</strong>: Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.</p></li><li><p><strong>Current Channel (Staged)</strong>: Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).</p></li><li><p><strong>Current Channel (Broad)</strong>: Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).</p></li><li><p><strong>Critical - Time delay</strong>: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.</p></li></ul><blockquote><p><em>I recommend using the <strong>Current Channel (Staged) </strong>for pilot and <strong>Current Channel (Broad) </strong>for production devices.</em></p></blockquote><p>Here's an example of how to configure update channel via Microsoft Intune:</p><p>Create a custom setting for Windows devices:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CdAq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CdAq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CdAq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CdAq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CdAq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CdAq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg" width="728" height="621.9052132701422" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:721,&quot;width&quot;:844,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:88991,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CdAq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CdAq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CdAq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CdAq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70d43227-005e-44cd-b591-87c6c6b9d495_844x721.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Name the policy and enter description:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NJvr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NJvr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NJvr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NJvr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NJvr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NJvr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg" width="1288" height="636" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:636,&quot;width&quot;:1288,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78532,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NJvr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NJvr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NJvr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NJvr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F371626a6-db82-48db-92bc-1ced39d82dbc_1288x636.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Add a new OMA-URI Setting, enter name, OMA-URI: <strong>./Device/Vendor/MSFT/Defender/Configuration/PlatformUpdatesChannel</strong> and Integer value for update channel:</p><ul><li><p>Beta Channel = <strong>2</strong></p></li><li><p>Current Channel (Preview) = <strong>3</strong></p></li><li><p>Current Channel (Staged) = <strong>4</strong></p></li><li><p>Current Channel (Broad) = <strong>5</strong></p></li><li><p>Critical - Time delay = <strong>6</strong></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZYZ2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg" width="1456" height="388" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:388,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:103186,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZYZ2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4df56fb-1fc7-412c-8d66-6d62a2bd1702_2131x568.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Assign the policy to a group of devices.</p><blockquote><p><strong>UPDATE</strong>: You can now configure update channels with Microsoft Defender Antivirus policy via Microsoft Intune</p></blockquote><p>Use PowerShell cmdlet <strong>"Get-MpPreference | select PlatformUpdatesChannel"</strong> to check Platform Update Channel value on a device:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O-XL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O-XL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 424w, https://substackcdn.com/image/fetch/$s_!O-XL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 848w, https://substackcdn.com/image/fetch/$s_!O-XL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!O-XL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O-XL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg" width="1291" height="223" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:223,&quot;width&quot;:1291,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28946,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O-XL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 424w, https://substackcdn.com/image/fetch/$s_!O-XL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 848w, https://substackcdn.com/image/fetch/$s_!O-XL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!O-XL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5239218-2000-4811-bf36-169d9d453c9a_1291x223.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>By taking control of Microsoft Defender updates through a well-structured rollout process using Microsoft Intune, organizations can mitigate risks, ensure stability, and maintain a secure environment. Hopefully this article has demonstrated the importance of controlled rollouts and provided a step-by-step guide for implementing a successful update management policy. With the right approach, organizations can stay ahead of potential issues while keeping their devices protected and optimized.</p><blockquote><p><strong><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-gradual-rollout?view=o365-worldwide">Microsoft Learn:</a></strong><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-gradual-rollout?view=o365-worldwide"> Manage the gradual rollout process for Microsoft Defender updates</a></p></blockquote>]]></content:encoded></item><item><title><![CDATA[Microsoft Defender for Endpoint script onboarding with TAGs]]></title><description><![CDATA[Onboarding devices in Microsoft Defender for Endpoint (MDE) can be done through various methods, each suited for different scenarios. However, when dealing with workgroup-joined devices that are not part of an AD domain or Intune, manual onboarding using a local script]]></description><link>https://www.matej.guru/p/microsoft-defender-for-endpoint-script</link><guid isPermaLink="false">https://www.matej.guru/p/microsoft-defender-for-endpoint-script</guid><dc:creator><![CDATA[Matej Klemenčič]]></dc:creator><pubDate>Tue, 18 Jul 2023 19:10:21 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6a23fb28-9e05-45bb-a4ed-c30cb9286043_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Onboarding devices in Microsoft Defender for Endpoint (MDE) can be done through various methods, each suited for different scenarios. However, when dealing with workgroup-joined devices that are not part of an AD domain or Intune, manual <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints-script?view=o365-worldwide">onboarding using a local script</a> becomes necessary. While this approach enables us to onboard these devices, it poses a challenge when it comes to applying TAGs for device categorization.</p><p>TAGs are an essential feature in MDE that allow us to organize and manage devices based on specific criteria such as location, department, or device type. Typically, TAGs are added through the MDE portal after the devices are onboarded or with <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/machine-tags?view=o365-worldwide">Group Policy</a> if devices are domain joined. Manual process can be time-consuming, especially when dealing with a large number of devices.<br><br>To streamline the onboarding process and automatically apply TAGs to workgroup-joined devices, we can incorporate a simple command into the onboarding script itself. By including this command, the devices will be automatically tagged during the onboarding process, eliminating the need for manual intervention later on.<br><br>Here's an example of how to add a TAG to devices using the onboarding script:</p><ol><li><p>Open the onboarding script file in a text editor</p></li><li><p>Locate the <strong>:SCRIPT_START</strong> section</p></li><li><p>Add a command to assign a TAG to the device. For instance, if we want to assign a TAG "<strong>Workgroup</strong>", we can use the following command:</p></li></ol><pre><code>REG add "HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection\DeviceTagging" /v Group /t REG_SZ /f /d "Workgroup" &gt;NUL 2&gt;&amp;1</code></pre><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k9l2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k9l2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k9l2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k9l2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k9l2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k9l2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg" width="1456" height="362" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:362,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68661,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k9l2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k9l2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k9l2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k9l2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd94d0c-c556-45b8-a0de-13e7d4af59b2_1621x403.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Save the modified onboarding script.</p><p>By including the command to assign a TAG within the onboarding script, the devices will be automatically tagged during the onboarding process. This saves time and effort since we don't have to manually assign TAGs through the MDE portal afterward.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o2IU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o2IU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o2IU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o2IU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o2IU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o2IU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg" width="1456" height="297" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:297,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:110425,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o2IU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o2IU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o2IU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o2IU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d67e2fc-af81-473c-b185-776e28611b12_1980x404.jpeg 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>Remember to customize the TAG based on your organization's requirements. You can create a TAG that align with your device categorization needs, such as geographical location, department, or device role. By leveraging TAGs, you can effectively manage and organize your devices within Microsoft Defender for Endpoint.<br><br>In conclusion, onboarding workgroup-joined devices in Microsoft Defender for Endpoint requires manual intervention through a local script. By incorporating a command to assign TAGs within the onboarding script, we can streamline the process and automatically categorize the devices during onboarding. This ensures efficient device management and eliminates the need for manual TAG assignment through the MDE portal.</p>]]></content:encoded></item></channel></rss>