Sign in

Stian A. Strysse 🛡️

@learningbydoing.cloud
225 followers 743 following 26 posts

Sr. Identity Architect - #learningbydoing 🛡️ Focused on #cloud, #identity, #cybersecurity, #devops, #automation, #Entra 🆔. Fixing it with code, sharing it in blogs 🚀 Blog: learningbydoing.cloud 💥 LinkedIn: linkedin.com/in/stianstrysse 🗞️

PostsRepliesMedia
Stian A. Strysse 🛡️ @learningbydoing.cloud · 10/05/2025
Yeah, I’m definitely doing \$batch after looking into it, isn’t that bad actually. Just need this script to be super effective when adding/removing a bunch of group members. Thanks! 🙏🏻
010
Stian A. Strysse 🛡️ @learningbydoing.cloud · 10/05/2025
@nathanmcnulty.com - did you ever find a way to remove group members in batches of 20, like we can for adding group members? Looking for the most efficient way to remove members. 😅
110
Stian A. Strysse 🛡️ @learningbydoing.cloud · 29/04/2025
Connect-AzAccount with newest PS module does not redirect to browser sign-in as the older versions did. Now it’s a popup instead, which takes longer to sign-in with. Same with Connect-ExchangeOnline newest module, why this new behavior - anyone knows?
000
Stian A. Strysse 🛡️ @learningbydoing.cloud · 03/02/2025
Helpful to protect against malicious or inadvertent admin actions. Now please bring recycle bin support for security groups too, Microsoft. Come on, it’s years overdue!
020
Stian A. Strysse 🛡️ @learningbydoing.cloud · 03/02/2025
Woah, this feature totally slipped under my #Entra radar - new protected action capability in #ConditionalAccess for hard-deletion of directory objects. Require e.g. compliant device, phishing-resistant MFA and re-auth before allowing permanent deletion of users, M365 groups and apps in Entra ID!
learn.microsoft.com
What are protected actions in Microsoft Entra ID? - Microsoft Entra ID
Learn about protected actions in Microsoft Entra ID.
1144
Stian A. Strysse 🛡️ @learningbydoing.cloud · 24/01/2025
Indeed. I’d love for Microsoft to implement Restricted Admin Units for appregs/SPs, so we could prevent app takeover from a lower privileged admin. Good discussion! 👍🏻
030
Stian A. Strysse 🛡️ @learningbydoing.cloud · 24/01/2025
That we agree on, 💯 CA is a killswitch that can cripple a business in seconds. I’ve heard of several organizations that locked themselves out, one was down for 3 days. A mitigation can be a service principal with CA.ReadWrite.All scope, but then you need to secure and monitor that too…
100
Stian A. Strysse 🛡️ @learningbydoing.cloud · 24/01/2025
That’s the thing - a breakglass account isn’t going to save the day if someone messes up a CA policy. One single policy created by mistake with scoping in all users, excluding no one, with an impossible grant, and everyone is locked out of the tenant.
100
Stian A. Strysse 🛡️ @learningbydoing.cloud · 24/01/2025
There is always a way of messing up CA policies, so I don’t feel that is an excuse :) I would not feel comfortable with a standing GA only a password away from total compromise. Some good pointers here: t.co/0bJ4b9u9Ez
t.co
https://www.cswrld.com/2023/12/how-to-manage-break-glass-accounts-in-microsoft-entra-id/
100
Stian A. Strysse 🛡️ @learningbydoing.cloud · 24/01/2025
Microsoft is enforcing MFA on all accounts accessing admin portals and APIs, so I think that way of managing breakglass accounts are over. Register 2-3 FIDO2 security keys locked up in a safe with only access for trusted individuals, test them yearly, and monitor the accounts for sign-ins. Right?
100
Stian A. Strysse 🛡️ @learningbydoing.cloud · 24/01/2025
I keep hearing recommendations for excluding #Entra breakglass accounts from all CA policies - I don’t agree. They should be included in at least one single, special CA policy requiring phishing-resistant MFA (FIDO2), where only breakglass accs’ are included. Session policy too. Thoughts?
100
Stian A. Strysse 🛡️ @learningbydoing.cloud · 21/12/2024
Not my field of expertise, but four day work week sounds awesome 🥺
130
Reposted by Stian A. Strysse 🛡️
Dirk-jan @dirkjanm.io · 12/12/2024
Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃
34520
Stian A. Strysse 🛡️ @learningbydoing.cloud · 07/12/2024
Funny thing is, 99% of the apps I’ve seen still using Azure AD Graph is Microsoft’s own apps 😬
010
Stian A. Strysse 🛡️ @learningbydoing.cloud · 05/12/2024
I just submitted an idea for this on the MgGraph GitHub repo. Upvote if you agree 🙏🏻 github.com/microsoftgra...
github.com
Add support for Authentication Context in MgGraph · microsoftgraph msgraph-sdk-powershell · Discussion #3047
It doesn't seem that MgGraph supports Conditional Access policies requiring Authentication Context. This is used for requiring specific policies for sensitive actions, like when creating a new Cond...
010
Stian A. Strysse 🛡️ @learningbydoing.cloud · 03/12/2024
@merill.net is a machine, I wish I had just half of that energy 😅 Excellent work mate! 👏🏻
110
Reposted by Stian A. Strysse 🛡️
Merill Fernando 💚 @merill.net · 03/12/2024
Today is the day folks. The new and updated Bluesky.ms is now live! Go add yourself. I'll share a detailed step by step...
bluesky.ms
Search the Microsoft community on Bluesky and get verified!
Bluesky account verification for Microsoft staff and MVPs.
3117165
Stian A. Strysse 🛡️ @learningbydoing.cloud · 03/12/2024
Salesforce used with for their Outlook plugin, action required for any customers using it: help.salesforce.com/s/articleVie...
help.salesforce.com
Help And Training Community
000
Stian A. Strysse 🛡️ @learningbydoing.cloud · 03/12/2024
I know at least some SaaS vendors use these EXO legacy tokens still, so good to stay updated on this with the coming deprecation.
100
Stian A. Strysse 🛡️ @learningbydoing.cloud · 02/12/2024
I just read this cool blog post by @smsagent.bsky.social covering how to activate eligible PIM roles using PS MgGraph when CA policies require Auth Context, found in @merill.net’s epic #Entra newsletter. This problem has been bugging me! However, shouldn’t MgGraph add support for Auth Context CAPs?
smsagent.blog
Activating PIM Roles that require MFA or Conditional Access Authentication Context with PowerShell
For some time, I’ve been activating and scheduling activations for Azure roles under Privileged Identity Management (PIM) using the Microsoft Graph PowerShell SDK. However recently we secured…
092
Reposted by Stian A. Strysse 🛡️
Fabian Bader @fabian.bader.cloud · 29/11/2024
Use exposure management data in #XDR to find all domain controllers and check if #MDI is installed.
buff.ly
AzSentinelQueries/Defender XDR/DefenderForIdentityInventory.md at master · f-bader/AzSentinelQueries
Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources. - f-bader/AzSentinelQueries
2286
Stian A. Strysse 🛡️ @learningbydoing.cloud · 29/11/2024
That would totally rock!
020
Reposted by Stian A. Strysse 🛡️
Merill Fernando 💚 @merill.net · 26/11/2024
So who wants a verified 'Microsoft' and 'Microsoft MVP' label on their profile and all the posts? I just finished setting up @bluesky.ms as a labelling service. Go subscribe to the label to start seeing labels on verified MVPs and Microsofties. 🧵👇
102466162
Reposted by Stian A. Strysse 🛡️
Merill Fernando 💚 @merill.net · 24/11/2024
This week's Entra newsletter just went out. Get all the Entra related Ignite announcements in one place 👇 entra.news/p/entra-n...
24710
Stian A. Strysse 🛡️ @learningbydoing.cloud · 19/11/2024
All days I’m working from my beloved home office, except for special circumstances or team events. I love it.
010
Stian A. Strysse 🛡️ @learningbydoing.cloud · 18/11/2024
Nothing to see there I guess… 😅
010
Reposted by Stian A. Strysse 🛡️
Merill Fernando 💚 @merill.net · 18/11/2024
Quick reminder to check out the #Microsoft community starter packs. We have new starter packs + starter packs updated with new folks. So hit up the page and update your follows so you can connect with more folks. Please add if I've missed any. bluesky.ms/starterpacks/
bluesky.ms
🚀 Starter packs | Bluesky.ms
Starter packs in Bluesky are curated collections of folks to follow. These packs are created by the community and are a great way to get started with Bluesky. You can bulk follow the folks in the pack...
34815
Reposted by Stian A. Strysse 🛡️
Imran Rashid @imranrashid.bsky.social · 12/11/2024
New to Bluesky? Looking for people to follow who post content about Microsoft Azure, Microsoft 365 and/or Security? Click the below starter pack and click follow all. Let me know if you want to be added to the list. go.bsky.app/2nmrHcS
273918
Reposted by Stian A. Strysse 🛡️
Stacey Holleran @staceyholleran.bsky.social · 17/11/2024
I just created my first starter pack. This one is for women in infosec. Please follow and share, and lmk if you’d like to be added! go.bsky.app/HAGHpCr
113217
Reposted by Stian A. Strysse 🛡️
Scott Piper @scottpiper.bsky.social · 18/11/2024
I created a list of Cloud Security folks on here. bsky.app/profile/scot...
4439
Reposted by Stian A. Strysse 🛡️
Dave Carroll @thedavecarroll.com · 17/11/2024
Sharing my #PowerShell Starter Pack again. I realized I must have accidentally dropped @robsewell.com's PowerShell feed, so I added it back. I also added @psconf.eu #PSConfEU feed. go.bsky.app/9ozmoAY
76016
Reposted by Stian A. Strysse 🛡️
soul nate @mnateshyamalan.bsky.social · 17/11/2024
“bluesky is an echo chamber” everywhere’s an echo chamber i’m going with the one without cybertruck guys
1097933109806
Reposted by Stian A. Strysse 🛡️
Jef Kazimer 😶‍🌫️ 🆔 @jeftek.com · 15/11/2024
If you are new to #Entraid Conditional Access Policies, or you have been working with them for years, this video from the product group on the #425show is worth your time to watch. #identity #security #microsoft #entra www.youtube.com/live/HylR3JL...
youtube.com
YouTube
Share your videos with friends, family, and the world
0298
Reposted by Stian A. Strysse 🛡️
Rudy Ooms | MVP @call4cloud.nl · 17/11/2024
Want to know how to setup/configure and use Fiddler to intercept Intune Traffic? Well, this is how! #Intune #MsIntune #Windows call4cloud.nl/fiddler-decr...
call4cloud.nl
Fiddler | Capture and Decrypt Intune Traffic | Troubleshoot
Fiddler | Intune | MDM | Entra | Capture and Decrypt Traffic | Autopilot | ClientCertificate.cer | Troubleshooting | customize rules | Troubleshooting
46517
Reposted by Stian A. Strysse 🛡️
Merill Fernando 💚 @merill.net · 17/11/2024
This week's Entra newsletter just went out → entra.news/p/entra-news... Featuring posts from @call4cloud.nl @danielbradley.bsky.social @olastrom.bsky.social @peter.inthecloud247.com @pvanderwoude.bsky.social @sapirxfed.bsky.social @savilltech.com @sreejith-r.bsky.social @tonyredmond.bsky.social
entra.news
Entra 🆔 News #71 → This week in Microsoft Entra
Watch the BlueHat 🧢 Entra recordings, learn about Entra sessions at Ignite this week ✨, mandatory MFA for the Microsoft 365 admin center 🔐, protecting AI with conditional access 🤖, and more! 🚀
25715
Reposted by Stian A. Strysse 🛡️
Merill Fernando 💚 @merill.net · 17/11/2024
Want to follow the Entra community on Bluesky? Check out the bluesky.entra.news starter pack👇 Please repost, like, bookmark to spread the word. To add yourself to the starter pack → github.com/merill/en...
bluesky.entra.news
Entra.News Authors #microsoft
Join the conversation
34216
Reposted by Stian A. Strysse 🛡️
Dave Carroll @thedavecarroll.com · 11/11/2024
Do you remember the first big task you tackled with #PowerShell? How about the moment it all just clicked, that system administration shouldn't be about clicks? What drew you to #automation?
31218
Stian A. Strysse 🛡️ @learningbydoing.cloud · 17/11/2024
Pre-2010 I was responsible at Helpdesk to disable and offboard AD accounts once a termination date in HR passed. I ended up learning Powershell specifically to do it quicker and with minimum manual work. Many years later I’m still working with automating identity lifecycle (amongst other stuff) 😅
020
Reposted by Stian A. Strysse 🛡️
Jef Kazimer 😶‍🌫️ 🆔 @jeftek.com · 16/11/2024
With #Microsoft Ignite 2024 taking place this week in Chicago, US, I created an automated feed you can subscribe to, to join those sharing from people around the world attending and posting! Please Like>Share>Post, and Pin to your feeds! #msignite #microsoftignite #entra bsky.app/profile/did:...
04618
Stian A. Strysse 🛡️ @learningbydoing.cloud · 09/11/2024
I have no opinion on this specifically. But please, please sync back the SID to the group object in Entra ID for any groups written back to AD - so that the cloud groups can be used for Cloud Kerberos-integrated Azure Fileshares.
040
Stian A. Strysse 🛡️ @learningbydoing.cloud · 08/11/2024
This is such a refreshing place!
020
Reposted by Stian A. Strysse 🛡️
Merill Fernando 💚 @merill.net · 08/11/2024
🦋 Introducing bluesky.ms 👏 = A crowdsourced database of anyone and everyone in the Microsoft community on Bluesky. 👉 Add yourself and anyone you know today 👈 🫂 All are welcome. This is my v1, I'll add options to directly follow from the site itself but first 👇 LET'S FILL IT UP! 🙏
bluesky.ms
Search bluesky.ms
Use this page to search for the Microsoft community on bluesky.ms.
58606266
Stian A. Strysse 🛡️ @learningbydoing.cloud · 08/11/2024
Hell yes, this is how you connect up with the MS community again from the «other platform». Thanks @merill.net 👏🏻 bluesky.ms
bluesky.ms
Search bluesky.ms
Use this page to search for the Microsoft community on bluesky.ms.
1132
Stian A. Strysse 🛡️ @learningbydoing.cloud · 06/11/2024
The hardest part of moving from «there» to Bluesky is that it’s hard to find all the interesting people I’m following on the other platform 😵‍💫 Where you at?
240