Privileged Identity Management (PIM), done right
Standing admin access is the risk. PIM makes privilege eligible, time-bound, and approved. Eligibility, activation controls, access reviews, and why to keep very few Global Admins.
Short, honest write-ups of the ideas that come up in interviews and on the job. Each one teaches the concept properly, cites the Microsoft documentation, and points back to the class that drills it until it sticks.
Standing admin access is the risk. PIM makes privilege eligible, time-bound, and approved. Eligibility, activation controls, access reviews, and why to keep very few Global Admins.
Entra ID now lets eligible password-only users enrol straight into a phishing-resistant passkey — skipping the weak SMS/voice step. The new flow, the supported credentials, the retirement timeline, and a 4-step checklist.
The portal where tenant identity lives — users, groups, roles, enterprise-app SSO, Conditional Access. Step-by-step least-privilege access and SSO setup.
P1 for everyone, P2 for admins — and what is already free. The Free/P1/P2 feature ladder, and how not to overbuy.
MFA is the what; Conditional Access is the when. Why you use both, Security Defaults versus CA, and the P1 licensing line.
One blueprint, one instance per tenant, one portal view. The mental model that finally makes Entra app identities click.
Same product, new name (July 2023) — nothing breaks. Why the rename, what stayed identical, and the old-to-new cheat sheet.
Active Directory works in Azure in three distinct, commonly confused ways. Untangle on-prem AD, Entra ID (formerly Azure AD), and Entra Domain Services in one sitting, plus where a cloud engineer meets each daily.
The if-then engine, how it resolves several policies at once, the MFA decisions that actually change your risk, the break-glass-first rollout order, and the legacy-auth policy that Microsoft's own numbers say stops 99% of password spray.
Both are the same object underneath — the difference is who holds the password. Plus the keyless options ranked: managed identity inside Azure, workload identity federation outside it, a certificate only when neither fits, and how to migrate off a secret with no downtime.
One short, honest Azure note at a time — plus the occasional hiring signal. No spam, no card, unsubscribe in one click.