Father Engineer Learner Lurker | Microsoft MVP | AD, Entra & enterprise security specialist. Senior Security Consultant @trustedsec. Fellow Human Being.

Wow. I'm super mixed on this. Seems that orgs with good intentions may have users pushed into unintended methods. On the other hand, I'm a huge supporter of "synced passkeys are better than no passkeys". Join me for more passkey chaos:
Folks, you might have been caught out by this but it's what Microsoft said they would do, according to the docs. Since Sept 1, tenants with an attestation-enforced or AAGUID-restricted passkey policy are suddenly seeing users register synced and browser passkeys. Admins are asking "why isn't Microsoft respecting my FIDO2 policy?" Here's what's going on. The "Passkeys by default" retirement page on Learn (published July 14) says this in its Important box: "Users enabled for SMS or Voice ... will be auto-enabled for passkeys in AMP. These in scope users will be put into a passkey profile allowing ALL types of passkeys. Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys." Two important notes: 1. Passkey profiles are a union. If a user is in more than one profile, a passkey only has to satisfy ONE of them. So your attestation-enforced profile is still there. Microsoft just added a second, unrestricted profile next to it for every SMS/voice user, and that one wins for registration. 2. Your registration campaign state doesn't protect you. Disabled, Enabled, doesn't matter. The doc says it gets set to Microsoft Managed regardless, which is why some of you saw your campaign config wiped with Microsoft in the audit log. Even with the campaign off, the new profile lets users self-register a non-attested passkey from My Security Info. The ONLY way to avoid this was the opt-out flag on the authentication methods policy: PATCH graph.microsoft.com/beta/pol… { "optOutSettings": { "passkeyDynamicMigration": true } } Or moving users out of SMS and voice before Sept 1. Where Microsoft dropped the ball: the Message Center post (MC1426371) only says "passkeys will be automatically enabled for users currently enabled for SMS or voice." It never mentions a new unrestricted profile or that your attestation/AAGUID restrictions would be bypassed. And MC1469555 says the campaign "does not override configured passkey policies", which is technically true and practically misleading. The passkey profile part is only on Learn. So: not a bug, but a really important detail buried in one paragraph on a docs page. What to do now: - Look at your passkey profiles for a Microsoft-created one with both passkey types and no restrictions, and check who's targeted. - Set the opt-out flag if you need attestation to hold, then clean up that profile. Note the doc says the flag stops working Feb 1, 2027. - If you already had the flag set and it still changed, that IS a bug. Open a case. Docs: learn.microsoft.com/entra/id…
2
9
1,142
Flying home from a successful client engagement. Excited to see my family and slightly less excited to meet my brand new Mac Studio.
6
277
I wanted to get out a quick blog this afternoon, not because of urgency, but because this is a 3+yr old problem that I keep seeing. I should have named it F*ck Teams. techbrandon.github.io/entra/…
1
4
5
1,213
Tech Brandon retweeted
👀
7
33
336
15,100
Anything you want to know or think should specifically be covered? Looking forward to sharing some real world advice on how to make Passkeys possible.
Passkeys are changing the game—and the timeline for adoption got expedited. Join @paulsems, @TechBrandon, and Jason Crawford on Wed, October 7 for "AMA: Passkeys and Preventing Credential Theft" and get answers to your #passkey questions. Register now! hubs.la/Q04y2N1w0
2
5
619
Every time I use super glue, I almost end up with a finger permanently attached to something.
1
4
254
I'll be speaking at 2026 CornCon Cybersecurity Conference on Oct 01 - 03, 2026. I would love to see you there! Register here: whova.com/portal/registratio… #CornCon
1
9
315
Not much has changed with passkeys but despite your current role, it's time to get familiar with Entra's implementation
UPDATE 📣 Organizations used to ask themselves "if" they'd adopt passkeys; #Microsoft decided the "when" for us, as of Sept 1, 2026. Our updated blog by @TechBrandon covers how Entra is implementing passkeys and what every role needs to know. Read it now! hubs.la/Q04xyjR40
1
12
1,974
Agents in AD are going to be indistinguishable from user based service accounts, or even user accounts themselves. But TBH, Entra is also already behind a similar curve. Governance is only covering who colors inside the lines. And if anyone likes coloring outside the lines its AI
Do you know the BIGGEST fear for a Microsoft VP? Its not whether they will make more money. It's whether the org they are leading is working on a Zune while the rest of the world is building the iPhone. Every feature PM is asked 'are you building where the puck is going to be in five years?' Work on the wrong thing, your org might still make money but you and your leadership team are shown the door (ask Steve Ballmer). Side note: I see all these posts on X whenever I talk about AD vs Entra. 'Oh it's all for the money' - You have no idea the thin ice you are on. Guess what Microsoft needs to do to make more money on prem? Hello Windows Server CALs 💰 Coming back to our main thread. Here are some of the moonshot features the Entra ID team started working on more than half a decade ago. - Decentralised ID (now Verified ID) - Entra Global Secure Access - Passwordless and Passkeys Today, most teams are working on Agents and Agent Identities. Do you think they are adding support for Agent ID to Active Directory? Please...
2
1
6
1,722
Tech Brandon retweeted
We’re at @BlueTeamCon! Join #SoberInCyber at 9 PM CT in the alcohol-free board games room & wind down after opening day with games, mocktails, good company, and zero pressure to drink. 🎲 soberincyber.org/events-1/al… (Blue Team Con badge required)
5
8
270
This was some of the best news of the conference.
I can't believe I'm tweeting about new NTLM features coming to Windows Sever 2019 🙀
1
4
264
Tech Brandon retweeted
Tomorrow in Nashville—catch Senior Security Consultant @TechBrandon at the @HIPConf 26 presenting "Abusing the Holes in Conditional Access: Modern Attack Paths and How to Close Them" at 4:15 PM. Add it to your schedule! hubs.la/Q04wXP1R0
1
8
12
2,171
Nathan has a great breakdown of how to use risk policies. I didn't realize sign in frequency played a role in this.
Replying to @NathanMcNulty
And finally, the biggest issue of all - you must use Sign-in Frequency of Every time If you only select Require MFA and the attacker has MFA on their token, it passes the check... Forcing every time ensures the attacker must reauthenticate to get new tokens, locking them out ;)
3
216
That's what I call leg room! Omw to @HIPConf #hipconf
1
1
209
True, but both have glaring misconfigurations (many default) that are years old and still being exploited. Kerberoasting, and device code flow to name a few.
Active directory is roughly twice the age of Entra (formerly Azure Active Directory). Roughly 26.5 years old to almost 13.5 years old. Active Directory has had about 13 years MORE lifetime for researchers and threat actors to find vulnerabilities. Chances are there will be more serious vulnerabilities discovered in Entra & associated cloud components over the coming years. As there likely will with Active Directory. Don't think because some guy on the internet says AD is defensible or Entra is better means that you can rest on your laurels.
1
2
219
Tech Brandon retweeted
As Conditional Access features multiply, so do the misconfigurations. Catch @TechBrandon presenting "Abusing the Holes in Conditional Access: Modern Attack Paths and How to Close Them" at @HIPConf in Nashville on September 9 at 4:15 PM. Don't miss it! hubs.ly/Q04wjn5Q0
13
26
7,738
MapQuest is still a thing? Respect for the "call it whatever you want" take. As if we need something else to argue about.
We're not changing the name of Lake Ontario. Name it whatever you want at your leisure: gulfof.mapquest.com/lakeonta… (tag us so we can see your work 🙂)
1
202
This made me lol. Is the old @Wendys social team running @MerriamWebster now?
2
3,010
I always see trusted locations being used as an exception to a policy instead of being used to provide additional protection on accounts excluded from other policies.
🔔 Stop bypassing MFA by adding your Office IP addresses to Conditional Access exclusions 🔔 Read this now on why you shouldn't do this > ourcloudnetwork.com/why-you-… Modern threats have evolved, and your justification for why you have done this no longer matters. 𝐘𝐨𝐮 𝐦𝐚𝐲 𝐭𝐡𝐢𝐧𝐤 𝐢𝐭 𝐚𝐝𝐝𝐬 𝐭𝐨 𝐦𝐮𝐜𝐡 𝐟𝐫𝐢𝐜𝐭𝐢𝐨𝐧 𝐰𝐡𝐢𝐥𝐞 𝐢𝐧 𝐭𝐡𝐞 𝐨𝐟𝐟𝐢𝐜𝐞? No, misconception. Microsoft invented their own token to solve this, called a PRT (or Primary Refresh Token). It works for AD Joined, Hybrid, or Entra-only devices, so no excuses. 𝐘𝐨𝐮 𝐦𝐚𝐲 𝐭𝐡𝐢𝐧𝐤 𝐮𝐬𝐞𝐫𝐬 𝐝𝐨𝐧'𝐭 𝐡𝐚𝐯𝐞 𝐬𝐮𝐩𝐩𝐨𝐫𝐭𝐞𝐝 𝐝𝐞𝐯𝐢𝐜𝐞𝐬 (𝐨𝐫 𝐢𝐭𝐬 𝐭𝐨𝐨 𝐢𝐦𝐩𝐚𝐜𝐭𝐟𝐮𝐥) No, misconception. Plenty of platforms let you to federate your logins to offer custom authentication options. Like QR code badges, which satisfy MFA through your webcam. 𝐃𝐢𝐝 𝐲𝐨𝐮 𝐟𝐨𝐫𝐠𝐞𝐭 𝐚𝐛𝐨𝐮𝐭 𝐩𝐨𝐰𝐞𝐫𝐟𝐮𝐥 𝐝𝐞𝐯𝐢𝐜𝐞-𝐛𝐚𝐬𝐞𝐝 𝐂𝐨𝐧𝐝𝐢𝐭𝐢𝐨𝐧𝐚𝐥 𝐀𝐜𝐜𝐞𝐬𝐬 𝐟𝐞𝐚𝐭𝐮𝐫𝐞𝐬? Requiring device compliance in Conditional Access is non-interruptive for users, but acts as a highly impactful "second factor". #Entra #Microsoft
1
1
7
1,004
DO: Block service accounts that cannot MFA unless from trusted locations. DONT: Exclude trusted locations in your MFA, Compliance, or Entra Joined enforcement policies
2
77