Your service principals probably don’t need secrets
Check out this article via web browser: Your service principals probably don’t need secrets
Application policies in Entra have been around for a while now to manage the use of secrets, but I don’t see many folks using them. It’s probably because secrets are still widely used, and an unlimited lifetime for secrets results in less yelling from developers. Everyone’s happy. Yet, attackers love secrets and use them all…
The post Your service principals probably don’t need secrets appeared first on JanBakker.tech.
Published on:
Learn moreRelated posts
How to add granular amr claims to your SAML apps in Entra ID
Check out this article via web browser: How to add granular amr claims to your SAML apps in Entra ID In my last post, I covered how Entra...
Lock or sign-out when Yubikey is removed from the device
Check out this article via web browser: Lock or sign-out when Yubikey is removed from the device I didn’t know there was already a solut...
Writing Maester tests using AI – From idea to Pull Request
Check out this article via web browser: Writing Maester tests using AI – From idea to Pull Request I love Maester. No doubt about that. ...
Admin control for SSO prompts in Windows; finally, an off switch!
Check out this article via web browser: Admin control for SSO prompts in Windows; finally, an off switch! If you’ve been paying attentio...
Passkeys by default and retirement of Microsoft-provided SMS and voice authentication – A guide to stay calm
Check out this article via web browser: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication – A guide ...
KB – employeeLeaveDateTime show empty (null)
Check out this article via web browser: KB – employeeLeaveDateTime show empty (null) This is a knowledge base item. I hope it will help ...
Why Windows is the hardest passkey surface in 2026 and what Entra admins should expect
Check out this article via web browser: Why Windows is the hardest passkey surface in 2026 and what Entra admins should expect Written by: Cor...
Entra ID SAML authnmethodsreferences (AMR) now supports phishing-resistant MFA
Check out this article via web browser: Entra ID SAML authnmethodsreferences (AMR) now supports phishing-resistant MFA If you’ve been fo...
Domainless SAML federation in Microsoft Entra External ID
Check out this article via web browser: Domainless SAML federation in Microsoft Entra External ID If you’ve ever set up direct federatio...
Use Device Code Flow to register a passkey in Microsoft Authenticator App
Check out this article via web browser: Use Device Code Flow to register a passkey in Microsoft Authenticator App The other day, I was doing s...