Sign in

Jeff

@techbyjeff.net
90 followers 282 following 206 posts

Microsoft's cloud kingdom, their cranky on-prem ancestors, and homelab adventures. Words at www.techbyjeff.net

PostsRepliesMedia
Jeff @techbyjeff.net · 9h
I said PingOne was the last identity provider I'd seed. That held for almost 24 hours. OneLogin made me rethink how a tool proves it created something before it deletes it: www.techbyjeff.net/a-role-with-... #PowerShell #OneLogin
techbyjeff.net
A Role With Nothing but a Name: Seeding OneLogin
What the TestEnvironment OneLogin provider seeds, how it proves it owns a role with no description, and role grants the API accepts and never applies.
010
Jeff @techbyjeff.net · 29/09/2026
I have been working on a new module to help validate and troubleshoot detect,remediate, and install scripts for #Intune -- including a PSScriptAnalyzer wrapper. www.powershellgallery.com/packages/Int... #PowerShell #Pester #MEM #EndpointManagement #Testing #SysAdmin
powershellgallery.com
IntuneScriptLab 0.25.0
Test Intune scripts before Intune does: static analysis, a runtime harness, Pester assertions
350
Jeff @techbyjeff.net · 29/09/2026
My first PingOne seed from Windows PowerShell produced a directory where every accented name was a question mark. From PowerShell 7, same code, same environment, every name stored perfectly. The cause belonged to all six of my providers: www.techbyjeff.net/a-directory-... #PowerShell #PingOne
techbyjeff.net
A Directory Full of Question Marks: Seeding PingOne
What the TestEnvironment PingOne provider seeds, how it proves it owns a user with no free-text field, and why a boolean attribute has to be text.
010
Jeff @techbyjeff.net · 27/09/2026
Akane from oshi no ko is smarter than anyone in death note and I will die on this hill.
000
Jeff @techbyjeff.net · 25/09/2026
000
Jeff @techbyjeff.net · 25/09/2026
A Conditional Access policy is not an HBAC rule. An Entra role is not a sudo rule. Nothing in a cloud tenant answers the question a Linux fleet asks its directory. Seeding a FreeIPA realm with the states a review has to tell apart: www.techbyjeff.net/seeding-free... #PowerShell #FreeIPA #Linux
techbyjeff.net
010
Jeff @techbyjeff.net · 25/09/2026
A policy bound to the wrong UUID is created, returned, listed, and enforces nothing. A provider made through the API issues tokens with no claims. Seeding Authentik with the states an inventory has to tell apart: www.techbyjeff.net/seeding-auth... #PowerShell #Authentik #Homelab #SelfHosted
techbyjeff.net
Seeding Authentik, Where the Directory Is Only the Floor
What the TestEnvironment Authentik provider seeds above the directory: flows, policies, bindings, outposts, and objects that govern nothing.
030
Jeff @techbyjeff.net · 22/09/2026
Never in my life have I wanted alt tab to swap between browser tabs.
000
Jeff @techbyjeff.net · 22/09/2026
I think we have very different ideas on a) what merits an email 2) what is popular
000
Jeff @techbyjeff.net · 17/09/2026
Quick tip: How to hide your name and profile picture from the Windows 11 Start menu www.neowin.net/guides/quick...
neowin.net
Quick tip: How to hide your name and profile picture from the Windows 11 Start menu
If you want to hide your identity from Windows 11's Start menu, Microsoft has introduced a change that lets you do just that.
000
Jeff @techbyjeff.net · 16/09/2026
I went back to write about my Okta provider again with better numbers and found the eight users unchanged and nearly everything around them replaced. What that means for a test lab living under a ten-user licence cap: www.techbyjeff.net/eight-okta-u... #PowerShell #Okta #IdentityManagement
techbyjeff.net
Eight Okta Users, and Everything That Changed Around Them
What a year and a six-provider merge did to TestEnvironment's Okta provider: verification, repair and cross-directory comparison under a ten-user cap.
000
Jeff @techbyjeff.net · 16/09/2026
Boomer take of the day: ordered a new phone and wireless charger and neither came with the power supply. Back in my day...
100
Jeff @techbyjeff.net · 16/09/2026
Setting up a new phone and mobile outlook wants a mysterious passkey for my personal ms account that doesn't exist via nfc or usb. Can't choose anything else, despite authenticator connected to the account on that phone. Guess I just don't get email on phone?
120
Jeff @techbyjeff.net · 14/09/2026
I seed about 1,180 objects into an Entra tenant, including eleven Conditional Access policies. Not one of them can ever enforce anything, and that is not a parameter. The design, and the Graph behaviour behind it: www.techbyjeff.net/seeding-entr... #PowerShell #EntraID #Security #Identity
techbyjeff.net
Seeding Entra ID When There Is Nothing to Paste
How TestEnvironment's Entra provider bootstraps its own service app, holds its objects in administrative units, and seeds policies that never enforce.
010
Jeff @techbyjeff.net · 13/09/2026
A year ago I published a module that fills a lab domain with test users, groups and devices. The three commands from that post still work. Besides the underlying rework, added more real users that may break a script. Then and now: www.techbyjeff.net/ad-test-data... #PowerShell #ActiveDirectory
techbyjeff.net
Active Directory Test Data, a Year and Six Providers Later
What the TestEnvironment Active Directory provider seeds, and how it tears a lab domain down, set against the standalone module it replaced.
110
Jeff @techbyjeff.net · 13/09/2026
Non LotR character who could resist the One Ring:
static.klipy.com
Solo Leveling: Sung Jinwoo Commands 'Arise'
ALT: Solo Leveling: Sung Jinwoo Commands 'Arise'
000
Jeff @techbyjeff.net · 12/09/2026
Me in interviews lately.
000
Jeff @techbyjeff.net · 12/09/2026
I've built out a couple different modules that seed various idp's with meaningful test data to run scripts against. On the third provider I was duplicating processes. I made a centralized module that plugs in providers. www.techbyjeff.net/test-data-th... #PowerShell #Identity #AD #Entra #Okta
techbyjeff.net
Test Data That Breaks Scripts on Purpose
Why a hand-built lab agrees with the script under test, and how one PowerShell module seeds five identity providers with data designed to disagree.
000
Jeff @techbyjeff.net · 12/09/2026
Teaser for what the next week or so of blogs will be: www.powershellgallery.com/packages/Tes...
powershellgallery.com
TestEnvironment 1.0.0
Seeds a realistic identity test environment in Entra ID, Active Directory, Okta, Authentik or FreeIPA - users in every lifecycle state, groups, devices and hosts, and the access policy over them - and...
010
Jeff @techbyjeff.net · 10/09/2026
Job application page: under no circumstances should you use AI at all to fill out anything. Also them: Join a video call with an AI interviewer as the first step.
000
Jeff @techbyjeff.net · 10/09/2026
The only spare host in my lab runs Ubuntu, and Ubuntu cannot run the FreeIPA server packages. So the second directory server lives in a container, and systemd in a container has opinions. www.techbyjeff.net/adding-a-fre... #FreeIPA #Linux #Kerberos #389DirectoryServer #Homelab
techbyjeff.net
Adding a FreeIPA Replica When the Only Spare Host Runs Ubuntu
Running a FreeIPA replica in a container on Ubuntu: systemd without privileged mode, macvlan addressing, and proving replication really works.
010
Jeff @techbyjeff.net · 10/09/2026
"We're removing predictive text as that has proven to be disruptive but we're now adding copilot to draft inline" uhhh what www.neowin.net/news/copilot...
neowin.net
Copilot is moving directly into Outlook's email composer
In case opening the Copilot sidebar in Outlook is too much work for you, Microsoft is bringing its AI assistant directly into the text editor.
000
Jeff @techbyjeff.net · 09/09/2026
I used a rufus install to remove some of the windows nags on personal and some of it set my default to en_uk and some things like date display and spell check are defaulting to it still despite setting en_us as default on the system later on. Annoying.
000
Jeff @techbyjeff.net · 09/09/2026
A fresh FreeIPA install ships an access rule that lets any user reach any service on any host, and it arrives enabled. Which is why I hardened the server before a single client joined. www.techbyjeff.net/hardening-fr... #FreeIPA #Linux #Identity #Homelab
techbyjeff.net
Hardening FreeIPA Before the First Client Joins
Hardening FreeIPA before enrollment, then the sudo provider, sudo-rs and NFS group-resolution traps that break directory logins on Linux clients.
000
Jeff @techbyjeff.net · 08/09/2026
Everyone reaches for Active Directory on premises. I wanted to try something different with no Windows in the fleet, without one Windows Server box to keep alive on an evaluation clock. I ran FreeIPA instead. www.techbyjeff.net/standing-up-... #FreeIPA #Linux #Homelab
techbyjeff.net
Standing Up FreeIPA When Everything in the Lab Is Linux
Installing FreeIPA on Rocky as an Active Directory alternative, its integrated DNS, and the traps in migrating a zone off Pi-hole and Cloudflare.
011
Jeff @techbyjeff.net · 07/09/2026
Six posts of proxying applications that cannot do single sign-on. Proxmox speaks OpenID Connect in the shipping product, so the work was getting out of the way. No proxy, no outpost, nothing in the path but the identity provider. www.techbyjeff.net/proxmox-nati... #Homelab #authentik #Proxmox
techbyjeff.net
Proxmox Can Do This Itself
Wiring Proxmox VE to authentik with a native OIDC realm, using no proxy and no outpost, plus the four mismatched values that broke the login.
000
Jeff @techbyjeff.net · 06/09/2026
My NAS listens on seven ports. Forward auth covers one of them. File protocols do not speak HTTP, so no proxy that makes an auth subrequest will ever sit in front of a file share. The identity layer guards the console. www.techbyjeff.net/openmediavau... #Homelab #SelfHosted #Identity #NAS
techbyjeff.net
Why OpenMediaVault Keeps Its Own Login
Forward auth in front of a NAS that serves its own web interface, and the firewall rule that turns the proxy from a convention into a boundary.
010
Jeff @techbyjeff.net · 05/09/2026
My fifth post of my homelab identity series, I try my hardest to not remove an app's built-in login and explore ways that I end up reverting. Sometimes it's all about acknowledging the risk. www.techbyjeff.net/turning-off-... #Homelab #SelfHosted #Identity #Security #authentik #nginx #tautulli
techbyjeff.net
Turning Off Tautulli's Login on Purpose
Removing an application login so a forward auth proxy becomes the single gate, and the network conditions that decide whether doing so is safe.
120
Jeff @techbyjeff.net · 04/09/2026
I put my identity provider on the internet on purpose, then went looking for where to put an access policy in front of it. Almost nowhere, as it turns out, and the reason is the protocols themselves. www.techbyjeff.net/access-in-fr... #Homelab #Security #Identity #Cloudflare #authentik
techbyjeff.net
An Identity Provider Is Supposed to Be Reachable
Exposing authentik through a Cloudflare tunnel, and why an access policy can cover only the admin console and never the whole hostname it sits on.
000
Jeff @techbyjeff.net · 04/09/2026
If only lol
000
Jeff @techbyjeff.net · 04/09/2026
Replaying FF16 and the subtitles have so many em dashes, funny how it's something that AI made you hyper aware. I'm sure if SquareEnix published it today they'd be criticized of AI subtitles.
010
Jeff @techbyjeff.net · 03/09/2026
My third post on my homelab Authentik series, with emphasis on Caddy. Three silent failures in my auth path, found by writing the walkthrough rather than running a scanner. www.techbyjeff.net/forward-auth... #Homelab #Security #Identity #Caddy #SelfHosted #authentik
techbyjeff.net
Forward Auth in One Snippet, and the Hop I Had Wrong
Wiring authentik forward auth through Caddy with one reusable snippet, and securing the cross-host subrequest that carries the session cookie.
020
Jeff @techbyjeff.net · 03/09/2026
This dude is really showcasing his AI pwsh module by showing it can read a directory contents. 🙄
100
Jeff @techbyjeff.net · 02/09/2026
Everyone recommends Caddy for homelab. Reverse Proxy + Certs in one sidecar. Nobody mentions the official image is missing the one module you need for internal hostnames. Here is the build, plus two other things that caught me out: www.techbyjeff.net/letting-cadd... #Homelab #SelfHosted
techbyjeff.net
Letting Caddy Own the Certificates
Moving a reverse proxy to Caddy for built in ACME renewal, compiling in the Cloudflare DNS module, and why the bundled self-signed cert falls short.
010
Jeff @techbyjeff.net · 02/09/2026
I stood up an identity provider on a thin client to find out whether I understand identity or just understand the enterprise scaffolding around it. Then I found it listening on every interface, behind a firewall that never had a chance. www.techbyjeff.net/standing-up-... #Homelab #Identity
techbyjeff.net
Standing Up authentik on a Thin Client
Deploying authentik 2026.8.0 with Docker Compose: the compose stack, the docker.sock line to delete, and why ufw does not filter a published port.
000
Jeff @techbyjeff.net · 02/09/2026
It brings me joy that the person I beef with most is a Jets fan. Make it extremely easy to trigger. Did you know that it's been 5 generations since they've made it to the Super Bowl?
000
Jeff @techbyjeff.net · 31/08/2026
Moved my KrbEtypeInsight module from the blog repo to its own and submitted my first gallery item! That was a fun learning process, check it out. www.powershellgallery.com/packages/Krb... #PowerShell #ActiveDirectory #Kerberos #Audit
powershellgallery.com
KrbEtypeInsight 1.0.0
Predicts which accounts, services and clients a Kerberos encryption type hardening change will break, before the change is made. Collects events 4768, 4769 and 4771 from domain controllers or archived...
000
Jeff @techbyjeff.net · 30/08/2026
Ghost(Pro) wanted $300/yr to host 40 posts. I moved the blog to Hugo on Azure Static Web Apps for the price of a DNS zone, and not one post URL changed. The writeup includes every place my first plan was wrong. www.techbyjeff.net/ghost-to-hug... #Hugo #Azure #Ghost #BlogMigration
techbyjeff.net
Moving This Blog From Ghost to Hugo Without Changing a Single Post URL
Moving off Ghost(Pro) to Hugo on Azure Static Web Apps with no post URL changed: permalink config, the tag slug trap, and the og:image mistake.
000
Jeff @techbyjeff.net · 30/08/2026
Wild that attackers no longer want your info but your tokens www.bleepingcomputer.com/news/artific...
bleepingcomputer.com
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.
000
Jeff @techbyjeff.net · 29/08/2026
I updated my github.com/fadwen/Power... repo to use the platyps module for help doc generation to keep in line with MS does itself. When looking at existing modules it will incorporate the existing comments before doing its thing. Let me know if you find this useful! #PowerShell #AI #Copilot
github.com
GitHub - fadwen/Powershell-Copilot-Standards: Enterprise-grade PowerShell development standards and GitHub Copilot instructions for consistent, secure, and high-quality PowerShell code across teams an...
Enterprise-grade PowerShell development standards and GitHub Copilot instructions for consistent, secure, and high-quality PowerShell code across teams and projects. - fadwen/Powershell-Copilot-Sta...
020
Reposted by Jeff
Wade Bachelder @wadebach.bsky.social · 28/08/2026
45 PowerShell Commands. One Goal. I built a PowerShell module specifically around endpoint security. The result? 45 commands designed to address endpoint issues identified through Microsoft Secure Score and other Windows security products. Deets: wadebach.blackcatwhitehatsecurity.com/code.cfm
131
Jeff @techbyjeff.net · 28/08/2026
Can we have the cushion backdrop for live human races too?
010
Jeff @techbyjeff.net · 28/08/2026
Went through the app looking for some #PowerShell people to follow and made it a collection. bsky.app/profile/did:...
021
Jeff @techbyjeff.net · 27/08/2026
I migrated my firewall, and the next morning a machine was still talking to NICs from a server I pulled months ago. Get-NetNeighbor found it in one command. The layer 2 cmdlet nobody runs, and nine ways to troubleshoot with it: www.techbyjeff.net/get-netneigh... #PowerShell #Networking
techbyjeff.net
Get-NetNeighbor: Layer 2 Troubleshooting on Windows
Two firewall changes in one maintenance window. By morning one box pings the gateway, cannot reach the Plex VM, and looks perfectly healthy in UniFi. Routing is fine. It is working from a cache writt...
000
Jeff @techbyjeff.net · 26/08/2026
I love when a recruiter cold calls, text, emails and dm's in the space of 3 minutes.
100
Jeff @techbyjeff.net · 24/08/2026
Microsoft's RC4 removal hit permanent enforcement in July 2026. The rollback lever is gone. KrbEtypeInsight is a read-only PowerShell module that names the exact client machines an RC4 withdrawal will break, before you change anything. www.techbyjeff.net/knowing-what... #ActiveDirectory #Kerberos
techbyjeff.net
Audit Kerberos RC4 Dependencies Before Disabling
Flipping msDS-SupportedEncryptionTypes is one line. I have never once been nervous about the line. I am nervous about the call two days later: a nightly job stopped, and nobody can say why. The attri...
100
Jeff @techbyjeff.net · 20/08/2026
The WMIC escape hatch closed this month. I grepped my repos and scoped the migration off the count. The count was measuring the wrong thing, and the hit that mattered most was the one that would not have failed. www.techbyjeff.net/wmic-is-gone... #PowerShell #SysAdmin #Windows
techbyjeff.net
WMIC Removed in Windows 11: PowerShell Migration
A utility script died on a fresh Windows 11 box. wmic bios get serialnumber, gone, and the DISM command that puts it back stops working this month. The one-liners map onto Get-CimInstance cleanly. Th...
100
Jeff @techbyjeff.net · 19/08/2026
Nothing more depressing than making a resume, having to fill in fields on application because they don't want to look at the resume, then the first interview is an "AI interview" who again asks things the resume answers. Why is there so much resistance on a human reading a resume? Cmon.
020
Jeff @techbyjeff.net · 18/08/2026
A report-only CA policy, and one question: if I enable it, who stops being able to work? What If gave me thirteen rows and no answer. So I wrote a PowerShell module that folds them into one. www.techbyjeff.net/conditional-... #EntraID #PowerShell #Maester #ConditionalAccess #Microsoft365
techbyjeff.net
Conditional Access: Outcomes, Not Verdicts
A report-only CA policy, and one question: if I enable it, who stops being able to work? What If gave me thirteen rows and no answer. So I wrote a PowerShell module that folds them into one.
122
Jeff @techbyjeff.net · 16/08/2026
A service's cert I don't use much had expired. Turns out certbot had been failing twice a day for months and nothing said a word. Port 80 is blocked on my home line. Wrote up the fix, and hand rolled some alerting. www.techbyjeff.net/renewing-a-w... #homelab #selfhosted #ssl #automation
techbyjeff.net
Renewing a Cert From Behind a Residential ISP
A service's cert I don't use much had expired. Turns out certbot had been failing twice a day for months and nothing said a word. Port 80 is blocked on my home line, so HTTP-01 was never an option. W...
110