PowerShell & Security MVP who is passionate about helping others succeed w/ Active Directory, Entra, Defender, & Microsoft 365. Always learning! โœ๏ธ๐Ÿ‘จโ€๐Ÿ‘ฉโ€๐Ÿ‘งโ€๐Ÿ‘ฆโ˜•

Charlotte ๐Ÿ‘จโ€๐Ÿ’ป GitHub and โžก๏ธ
Sam Erde retweeted
Replying to @GithubProjects
Shouldnโ€™t the guide just say โ€œstop posting your API keys into every agent?โ€ ๐Ÿคญ๐Ÿ˜‰ I really like the idea, but we MUST secure our tools and credentials first, THEN do the awesome things!
1
1
96
Honestly, how did Gmail not filter this spam immediately?! ๐Ÿ˜จ
1
4
835
Microsoft Scout is now โ€œAutopilot.โ€ Iโ€™m sure that wonโ€™t confuse anyone. ๐Ÿ˜† Maybe they should have called it โ€œSurface Duoโ€ or โ€œZune.โ€ ๐Ÿ˜‹
Microsoft Scout is now Microsoft Autopilot- not to be confused with Microsoft Autopilot for Intune. ๐Ÿคทโ€โ™‚๏ธ
8
1
48
5,718
Sam Erde retweeted
Defender for Identity sensor v3 on ADFS, ADCS, and Entra Connect sync is now in preview! ๐Ÿฅณ Make sure you have at least one, reachable DC running the v3 sensor as well ;)
6
26
122
9,552
Sam Erde retweeted
ISOC in Microsoft Defender is a benefit for M365 E5 and E7 customers, it is not a new product. Those lucky customers will save 44% off 3P security log ingestion. I spent all day reading and broke it down here to bring it to you straight: patriotconsulting.com/blogs/โ€ฆ
XDR and SIEM now in one platform. Meet the new ISOC in Microsoft Defenderโ€”a SOC built for agentic security. Here to help you investigate and respond more efficiently. msft.it/6019ag5T1
7
40
305
626,000
It's a gray, rainy, Astra High on Fast kind of day. ๐Ÿ‘จโ€๐Ÿ’ป
6
303
Iโ€™m getting my em dash back! Being able to read and actually understand the output from Claude models is going to be a nice change as well. ๐Ÿคญ
Replying to @claudeai
Opus 5.5 communicates more naturally, addressing some of the most common feedback we heard on Opus 5. It puts the most important information up front and follows the writing rules you give it, which makes long sessions easier to follow.
3
414
In which we talk about Active Directory and other things you might monitor with Maester. ๐Ÿ•ต๏ธโ€โ™‚๏ธ
Developers wouldn't ship without tests. Identity teams ship changes to a 30-year-old directory every single day with nothing but a change ticket and hope. Maester now tests on-prem Active Directory: 269 checks, read-only, runs from your workstation. Built by Mike Soule, who joins @SamErde and me on this week's Entra.Chat to go through what it covers and how to run it safely. Let's bring Sec DevOps practices to Active Directory! There's no good reason not to have a baseline. Watch the full episode on entra.chat #ActiveDirectory #Maester #PowerShell #IdentitySecurity
2
8
1,082
The focus of our talk centered around the following questions: ๐Ÿ”ฅ What makes your tenant unique in ways that security benchmarks can't help? ๐Ÿ”ฅ How can you monitor for the intent of your security and compliance policies? ๐Ÿ”ฅ What makes the configuration of your policies fragile?
112
Sam Erde retweeted
Today, we announced the 2nd set of finalists for the Golden #Clippy Awards. Yes, this is the trophy below. Of the 10ish awards, no award better personifies our culture and mission than this one. We work very hard, and try to support each other, but we often have people who don't get the recognition they deserve. Many of this year's nominees are people who we're like "how the hell were they not already a MVP?" like @NathanMcNulty last year or @SamErde. Let's welcome these amazing nominees, who I consider to be good friends, and very talented people. Let's also try to not let legacy technology people like @techspence win ok? ๐Ÿ’• Register now: workplaceninjas.us
Happy Monday! Today, we announce the finalists for our 2nd Golden #Clippy and perhaps my favorite: "The Next-Gen #Ninja" which highlights a new Microsoft MVP who has been making a great impact on the community. Let's discuss these 6 amazing people: ๐Ÿ– @MarkHunterOrr, who we met in Dallas last year, and impressed plenty of people at the #hackathon, and overall, throughout the event, is a very impressive guy. Outside of being a great dad, he has been building tools and making a difference every day. ๐Ÿ’ช @bigchrisatx feels like he's been an MVP for 15 years, but he just finally got one. A super smart guy, who has a heart of gold and some major skills in the #AVD and #Windows 365 space. ๐Ÿผ Maxime Guillemin has been making a major impact despite being young in his country of Belgium. The hard work has finally paid off as he's in a new role at one of our sponsors, Splashtop Inc. along with being a new dad. A master of #MSSecurity #Copilot and #MSIntune, we're very proud of him for finally becoming a MVP. ๐Ÿ’ป @techspence , despite us giving him a hard time, is an absolute rockstar. Someone who is doing nearly 100 penetration tests per year on #ActiveDirectory, it's hard to believe he's a new MVP. ๐Ÿ‘‘ @WelkasWorld , the "Queen of #Purview", has continued to have a meteoric rise in the community. She's not only one of the most brilliant Purview people in the world, but she's been rising the ranks at Threatscape, and challenging herself with more dynamic sessions and content around the world. This is a very competitive category this year with 5 very deserving people. It is ANYONE's game to win, but who WILL win? Debate in the comments, who do you got? #MVPBuzz Don't forget to register and join us to crown one of these brilliant people!! workplaceninjas.us
1
4
14
3,044
๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—”๐˜‚๐˜๐—ผ๐—บ๐—ฎ๐˜๐—ถ๐—ฐ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฟ ๐—ณ๐—ผ๐—ฟ ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ป๐—ผ๐˜„ ๐—ด๐—ผ๐—ฒ๐˜€ ๐—ฏ๐—ฒ๐˜†๐—ผ๐—ป๐—ฑ ๐—ฑ๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐—น๐—ฒ๐—ฟ๐˜€ You can now enable Windows event auditing on ๐—”๐—— ๐—–๐—ฆ, ๐—”๐—— ๐—™๐—ฆ and ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—˜๐—ป๐˜๐—ฟ๐—ฎ ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜ servers automatically. The servers have to run the ๐˜€๐—ฒ๐—ป๐˜€๐—ผ๐—ฟ ๐˜ƒ๐Ÿฏ.๐˜… to get the audit configuration automatically. ๐Ÿ› ๏ธ ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐˜๐—ผ ๐˜๐˜‚๐—ฟ๐—ป ๐—ถ๐˜ ๐—ผ๐—ป: Microsoft Defender portal โ†’ Settings โ†’ Identities โ†’ General โ†’ Advanced features โ†’ ๐—”๐˜‚๐˜๐—ผ๐—บ๐—ฎ๐˜๐—ถ๐—ฐ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ช๐—ต๐—ฎ๐˜ ๐˜๐—ต๐—ฒ ๐˜€๐—ฒ๐—ป๐˜€๐—ผ๐—ฟ ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ๐˜€: - Directory services advanced auditing: audit entries in the SACL of the domain root object - NTLM auditing: the required registry values - Domain object auditing: the SACL on the Configuration partition - AD FS: object-level auditing on the AD FS configuration container, plus the Audit Application Generated policy (Success and Failure) - AD CS: the required value in the CA audit filter in the CA registry configuration - Entra Connect: the Audit Logon policy (Success and Failure) - The local Windows audit policies The sensor writes the settings to the local system policy of the server and repeats the check once every 24 hours. โš ๏ธ ๐—•๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฒ ๐˜†๐—ผ๐˜‚ ๐˜๐˜‚๐—ฟ๐—ป ๐—ถ๐˜ ๐—ผ๐—ป: - AD FS: event auditing in AD FS Management and verbose logging stay manual (Set-AdfsProperties -AuditLevel Verbose) - If Sensor v2.x is still in use, you have to do it manually - GPO settings can conflict with the local settings that the sensor applies ๐Ÿ“„ ๐—–๐—ต๐—ฒ๐—ฐ๐—ธ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฐ๐˜‚๐—ฟ๐—ฟ๐—ฒ๐—ป๐˜ ๐˜€๐˜๐—ฎ๐˜๐—ฒ ๐—ณ๐—ถ๐—ฟ๐˜€๐˜: New-MDIConfigurationReport -Path "C:\Reports" -Mode Domain -OpenHtmlReport (DefenderForIdentity PowerShell module) Do your AD FS, AD CS and Entra Connect servers already run the v3.x sensor? Author: Martin Strnad #DefenderForIdentity #ActiveDirectory #ADCS #ADFS #EntraConnect #SecureBits #HorizonSecured
1
13
57
2,751
Sam Erde retweeted
A guided migration that includes "includes configuration assessment, provisioning agent setup, staged activation, and validation." It's almost like the Entra team asked "How can we make this easier for our customers?" and then did it ๐Ÿ’ก Big kudos to the Entra team for this ๐Ÿฅณ
Microsoft releases Entra Connect v2.6.91.0 with security fixes and recommends upgrading to this version as soon as possible! โ€‹ This release also includes a guided migration workflow from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync. โ€‹ The workflow includes configuration assessment, provisioning agent setup, staged activation, and validation. โ€‹ To download the Microsoft Entra Connect Sync tool: โ€‹ 1. Sign in to Microsoft Entra admin center. 2. Navigate to Entra ID > Entra Connect > Get Started > Manage. 3. Select the "Download Connect Sync agent". 4. Select the "Accept terms & download" button. 5. Run the tool on the Entra Connect server and follow the wizard. โ€‹ Note: The release is only available for download via the Microsoft Entra admin center, and auto-upgrade is not available. โ€‹ Learn more: - learn.microsoft.com/en-us/enโ€ฆ - alitajran.com/upgrade-microsโ€ฆ โ€‹ #Microsoft365 #EntraID #EntraConnect
1
15
92
8,873
Microsoft just announced that they are dropping support for Windows PowerShell 5.1 in future releases of the Microsoft Graph PowerShell module. ๐Ÿ‘€ This is a GOOD thing for PowerShell and for the Microsoft.Graph module--and for us!!!๐Ÿ”ฅ devblogs.microsoft.com/microโ€ฆ

ALT It's happening

2
4
26
1,727
Sam Erde retweeted
Even better news - Server 2016 reaches end of support in January 2027!

ALT Lets Go Hurry GIF

5
5
32
4,002
Sam Erde retweeted
๐Ÿ” Microsoft Entra Connect (Azure AD Connect) version 2.6.91.0 is now available Everything you need to know is in the images below. ๐Ÿ”’ This release includes security fixes. Microsoft recommends upgrading as soon as possible. โš ๏ธ Before you upgrade: 2.6.91.0 adds Microsoft Graph permissions. If you have app-scoped Conditional Access policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service, review them first or the sync may be blocked. Microsoft Entra Connect Sync is no longer available from the Microsoft Download Center. The .msi must be downloaded from the Microsoft Entra admin center: entra[.]microsoft[.]com > Identity > Hybrid Management > Microsoft Entra Connect > Connect Sync > Get started > Manage tab ๐Ÿšจ Reminder: on September 30, 2026, every server below 2.5.79.0 stops synchronizing until it is upgraded. Two weeks left. ๐Ÿ”— Official release notes: learn.microsoft.com/en-us/enโ€ฆ ๐Ÿ”— Previous versions list, you can download older versions there: l.itpro.tips/entraconnectsynโ€ฆ
2
10
77
7,862
Sam Erde retweeted
#Azure and #MicrosoftGraph #PowerShell tokens can be persisted in the #macOS Keychain and exfiltrated by other scripts. In my blog, I unpack research about: ๐ŸŽฏ Same-user-context risk ๐Ÿ›ก๏ธ Process-scoped mitigations & detections ๐Ÿ› ๏ธ A defensive audit script ๐Ÿ”— cloud-architekt.net/macos-caโ€ฆ
12
32
2,059
๐Ÿš€PSPreworkout v2.2.0 is live on the PowerShell Gallery! New features, fixes, and polish to help you set up and tune your PowerShell environment faster. ๐Ÿ‘‰Update-AllTheThings now updates GH CLI extensions and GitHub Copilot. github.com/SamErde/PSPreworkโ€ฆ #PowerShell #DevTools
2
6
801