Microsoft adds user actions to the Security Administrator role
Microsoft expands Entra ID Security Administrator role with identity containment actions, enabling incident-response tasks like disabling users and resetting passwords.
Daniel is a UK-based technical architect and Microsoft Security MVP specializing in Microsoft Entra, Intune, and Microsoft Graph, sharing real-world automation and identity management insights from hands-on experience.
50 articles from this blog
Microsoft expands Entra ID Security Administrator role with identity containment actions, enabling incident-response tasks like disabling users and resetting passwords.
Something that may catch you out today, is that your “All Staff” dynamic group which has likely always works, may no longer contain only staff. Micros
Microsoft retires memberOf dynamic group operator; article warns against using preview features in production due to risks.
Microsoft Entra ID shows licensing overage warnings for Conditional Access, signaling potential enforcement of license compliance.
Microsoft Entra simplifies passwordless MFA registration, allowing passwordless credentials as first MFA and recognizing Windows Hello/macOS SSO as standalone MFA factors.
Microsoft is ending the memberOf rule operator for dynamic groups in Entra, affecting group membership processing. Learn how to audit and replace affected rules.
Learn how to prevent users from registering applications in Microsoft Entra to mitigate security risks.
Learn how to disable group nesting in Microsoft Entra ID using PowerShell and Microsoft Graph API to improve access control clarity.
Microsoft silently updated four Entra ID built-in roles, affecting permissions for backup, AI, and governance administrators.
Microsoft Entra will allow passwordless users to change passwords without knowing the current one, reducing support calls.
Microsoft retires custom CSS positioning in Entra ID company branding by Oct 2026 to boost phishing resistance.
Microsoft announces retirement of SMS and voice authentication by 2027, pushing passkeys as the default MFA method.
Microsoft's new Entra SOC Identity Responder role allows granular identity threat response with least privilege.
Microsoft retires Custom Controls in Conditional Access, replacing them with External MFA for third-party MFA integration.
Explains why bypassing MFA for office IP addresses creates security risks, especially with guest networks and SNAT.
Microsoft Purview adds native time limits for role group assignments, enabling temporary access from 1 day to 2 years without PIM workarounds.
Clarifies Microsoft Entra's 'One Person, One License' philosophy with new FAQs, explaining that employees with multiple identities need only one license.
Guide to enabling baseline scope settings in Conditional Access for Microsoft Entra ID.
Learn how to automate PIM approvals using custom extensions with REST APIs to improve efficiency.
Guide to restricting guest invitation permissions in Microsoft Entra ID for better security and zero trust compliance.